Single-merchant setup
Connect Razorpay
- Deploy RecoveryOS to a public HTTPS URL.
- Add
https://your-domain.com/api/webhooks/razorpay in the Razorpay Dashboard. - Subscribe to
payment.authorized, payment.captured, and payment.failed. - Use a separate Razorpay webhook secret.
- Configure
APP_BASE_URL, DEMO_ADMIN_PASSWORD, SESSION_SECRET, RAZORPAY_KEY_ID, RAZORPAY_KEY_SECRET, and RAZORPAY_WEBHOOK_SECRET on the server.
Webhook handling
What RecoveryOS checks
RecoveryOS validates the Razorpay HMAC signature using the raw request body and deduplicates webhook events before processing them.
Never expose API keys or webhook secrets in frontend code, screenshots, or public documentation.
First-release scope
One merchant per deployment
RecoveryOS currently supports one Razorpay merchant per deployment. This is an intentional first-release scope decision caused by current time and implementation constraints. It is not a limitation, incompatibility, or discrepancy in Razorpay or the RecoveryOS platform.
Multi-tenancy is not a platform limitation. The architecture can expand later to support multiple merchants, workspaces, and webhook connections.Operator access
Login behavior
The current version uses one operator password, an eight-hour session cookie, and server-side protection for post-login pages.
For multiple businesses
Future expansion
A multi-business version should use individual accounts, workspaces, encrypted credentials, unique webhook endpoints, and Razorpay OAuth.
Official resources
Razorpay documentation
Set up webhooks ↗Validate signatures ↗