Insights
Practical notes from API security audits for payment providers — written for engineering and compliance owners.
Authentication mistakes we still see in payment APIs
Long-lived API keys, missing mTLS on high-value routes, and token scopes that quietly outgrow their design.
Webhook forgery risks for payment providers
Unsigned callbacks, weak secrets, and replayable events still open paths into reconciliation and payout flows.
Preparing API evidence for a PCI assessment
How to turn payment API controls into assessor-ready artefacts without rewriting your engineering wiki.