Flow overview
Session fields
Session statuses
Security
Theby-token endpoints used by the hosted page are public and require no API key — they are scoped to the session token embedded in the session_url. Your API key is never exposed to the payer’s browser.
Webhooks
Subscribe tocheckout.session.completed and checkout.session.failed to receive real-time status updates without polling.