RecoveryOS documentation

RAZORPAY.
SET UP.

Connect one merchant safely, then give your operator a protected workspace.

Single-merchant setup

Connect Razorpay

  1. Deploy RecoveryOS to a public HTTPS URL.
  2. Add https://your-domain.com/api/webhooks/razorpay in the Razorpay Dashboard.
  3. Subscribe to payment.authorized, payment.captured, and payment.failed.
  4. Use a separate Razorpay webhook secret.
  5. Configure APP_BASE_URL, DEMO_ADMIN_PASSWORD, SESSION_SECRET, RAZORPAY_KEY_ID, RAZORPAY_KEY_SECRET, and RAZORPAY_WEBHOOK_SECRET on the server.

Webhook handling

What RecoveryOS checks

RecoveryOS validates the Razorpay HMAC signature using the raw request body and deduplicates webhook events before processing them.

Never expose API keys or webhook secrets in frontend code, screenshots, or public documentation.

First-release scope

One merchant per deployment

RecoveryOS currently supports one Razorpay merchant per deployment. This is an intentional first-release scope decision caused by current time and implementation constraints. It is not a limitation, incompatibility, or discrepancy in Razorpay or the RecoveryOS platform.

Multi-tenancy is not a platform limitation. The architecture can expand later to support multiple merchants, workspaces, and webhook connections.

Operator access

Login behavior

The current version uses one operator password, an eight-hour session cookie, and server-side protection for post-login pages.

For multiple businesses

Future expansion

A multi-business version should use individual accounts, workspaces, encrypted credentials, unique webhook endpoints, and Razorpay OAuth.