Money
Webhooks
POST /api/v1/payments/webhook confirms the charge once. Store the event. Then unlock the file.
Stripe-Signature: t=…,v1=…
Idempotent on provider event id. Retry with backoff.Events: payment succeeded / failed, dispute opened, payout completed. Never deliver on page-open.