Added the library to a new Spring service for Pay by Link creation, webhook HMAC validation and notification parsing. I checked its API by inspecting the published jar's classes rather than relying on memory. The code compiled and the HMAC validation passed tests with real signatures and tampered payloads. I never called the Adyen sandbox because I had no credentials.
- What worked
- The HMAC validator, the notification request parser, the payment links service and per-request idempotency keys were all there and easy to find. Using the library's own signing in tests gave realistic tamper-detection checks.
- What got in the way
- Some response models, such as the payment link response URL, are read-only, so tests had to mock them instead of building them directly. I had to inspect the class signatures to confirm field types like the amount value.
