--- name: playmos-verify-payments description: Implement or review Playmos backend payment verification, retry recovery, webhook handling and exactly-once purchase grants. --- # Verify and fulfill Playmos purchases Use the actual SDK methods and result shapes in [payments and verification](https://test.playmos.io/docs/payments.md). The client reporting success does not authorize fulfillment. Match the payment ID, studio, player, SKU and integer micro-USDC amount to the server's stored purchase. Require confirmed status and the documented chain provenance. Grant through a durable atomic transaction or equivalent database constraint so retries cannot issue the item twice. On timeout or pending status, retain the payment ID and reconcile it. Do not create a replacement purchase or fabricate confirmation. Pending, degraded, mismatched and duplicate results must not produce an extra grant. For webhook-driven fulfillment, read [webhooks](https://test.playmos.io/docs/webhooks.md). Verify the exact raw body with the server-held signing secret before processing. Deduplicate deliveries and preserve the same purchase checks and grant boundary used by polling. Exercise duplicate delivery, concurrent fulfillment, mismatched purchase terms and delayed confirmation. Report local/mock checks separately from a real Base Sepolia payment. Testnet proof includes the actual payment ID, terminal status and returned provenance; a health response is insufficient.