---
name: waffo-pancake-checkout
description: "Step-by-step rules for integrating Merchant-of-Record payments via @waffo/pancake-ts. Includes cryptographic webhook signature verification, idempotent ledger records, and refund handling."
---

# SKILL: Waffo Pancake Global Checkout Architecture
## Payment Integration Safety
1. Never expose WAFFO_PRIVATE_KEY to client-side bundles. Only invoke within server endpoints.
2. Webhook verification: Always verify request signature before executing fulfillment transactions.
3. Idempotency: Record incoming event_id in a processed_events database table to prevent double crediting.
4. Support clean redirect flows for both success and cancellation return URLs.
