Architecture and flow
1. Customer confirms an order on the merchant's site
2. Merchant server --POST /payments--> ROKI (with the secret key)
3. ROKI returns a payment in "pending" state with a checkout_url
4. Merchant stores the payment id locally and redirects the customer to checkout_url
5. Customer pays on ROKI's page (this is where card details are entered)
6. ROKI --signed webhook--> merchant server (authoritative confirmation)
7. Merchant marks the order as paid
8. Customer is redirected to success_url (NOT payment confirmation, see 9.3)
Steps 6 and 8 are independent and can arrive in any order - or step 8 may never happen at all if the customer closes the browser. The truth about the charge lives in step 6 (or in a direct lookup), never in step 8.
