Payment webhooks
Configure Stripe and PayPal callbacks so ONHOST CMS confirms payments on the server before delivering an entitlement.
## Why webhooks matter
A browser return page is not proof of payment. ONHOST CMS waits for the configured payment provider to confirm the final state server-side before marking an order paid, creating download entitlement or issuing a licence.
## Configure the endpoint
Register the public HTTPS endpoint for the provider you use:
```
POST /api/webhooks/stripe
POST /api/webhooks/paypal
```
Save the matching webhook secret or identifier in **Admin → Settings**. Use the provider's test mode first, make a real test payment, then verify the order, invoice and entitlement records in ONHOST.
## Troubleshooting
If a payment is captured but the order is not delivered, check the provider event log, configured webhook secret, public DNS and PHP error log. Do not create duplicate fulfilment manually until you have confirmed whether the payment event was already processed.