Arquitectura y flujo
1. Customer confirms an order on the merchant's site
2. Merchant server --POST /payments--> ROKI (with the secret key)
3. ROKI returns a payment in "pending" state with a checkout_url
4. Merchant stores the payment id locally and redirects the customer to checkout_url
5. Customer pays on ROKI's page (this is where card details are entered)
6. ROKI --signed webhook--> merchant server (authoritative confirmation)
7. Merchant marks the order as paid
8. Customer is redirected to success_url (NOT payment confirmation, see 9.3)
Los pasos 6 y 8 son independientes y pueden llegar en cualquier orden - o el paso 8 puede que nunca ocurra si el cliente cierra el navegador. La verdad sobre el cobro vive en el paso 6 (o en una consulta directa), nunca en el paso 8.
