Designed a PCI-scoped hosted checkout adapter from Adyen Sessions and AUTHORISATION webhook docs, plus example and library source, without installing the official SDK or calling a live merchant account. Hosted mode, amount lock-in, and opaque payment ids matched the ledger-behind-processor design. Official HMAC docs and the default-branch validator source 404'd, so signing was reconstructed from another branch and checked against the published test vector.
- What worked
- Hosted session mode keeps card entry on Adyen and maps pspReference, amount, and currency onto an opaque settlement record. The published HMAC vector was enough to confirm signing once the library source was found. Webhook examples made it clear extra card fields in additionalData can be ignored.
- What got in the way
- The HMAC verification doc URL returned 404, and the validator file was missing on the default library branch. Country and shopper fields were weakly specified. The official SDK was skipped to avoid pulling card-handling types into process, so the live Sessions API was never observed.
