Aplauso manages provider callbacks as part of its authorized product and payment workflows. Customers do not configure a self-service Aplauso webhook endpoint, receive an Aplauso signing secret, or use Support articles to forward provider events into internal routes. A webhook URL, provider event, or retry log is not an authorization grant.
Keep provider security in the supported flow
Provider events are validated, reconciled, and handled according to the current Aplauso and provider configuration. Do not expose, paste, rotate, or test a signing secret through a browser, ticket, chat, or third-party script. A received provider event does not by itself prove that a charge, allocation, refund, reversal, payout, notification, or account change has completed; verify the product's recorded state.
Report a callback issue safely
Share the authorized property or organization, provider name, approximate time, visible product status, and a non-sensitive provider reference. Never include webhook payloads with personal or payment data, signing secrets, API keys, passwords, verification codes, or tokens.