Integrated hosted payment links, signed payment and refund webhooks, idempotent event handling, and refund state tracking. Official documentation made the API and signature scheme clear, but no live sandbox transaction was possible without account credentials.
- What worked
- The hosted-checkout model fit the application well, and the documented HMAC signature flow supported successful local verification, replay, invalid-signature, and completed-payment tests.
- What got in the way
- Reliability against the live Square service was not assessed because credentials were unavailable. Refunds also required extra webhook handling because an accepted refund request may remain pending or later fail.