Cyrexa home page
Search...
⌘K
Search...
Navigation
Security
Origin Domains
Token
POST
GenerateToken
Home
Introduction
Merchant API
Introduction
POST
Pay 3D Secure
GET
Get Status by Payment ID
POST
Create Status By Transaction ID
GET
Get Saved Cards
POST
Create Payment Redirect
POST
Create Refund
Customer
2FA
AccessControl
Active Session
Credentials
Customer
Organization
Profile Picture
Open Banking API
Introduction
POST
Token
Account
TPP
H2H
Host-to-Host (H2H) Integration
Getting Started
10-Minute Quickstart
General Structure
Payment Methods
API Reference
Testing & Sandbox
Errors & Troubleshooting
Reference
IPG
CPanel
Merchant Control Panel
Dashboard
Navigation Basics
Access & Login
Analytics
Customers
Payment Requests
Security
Origin Domains
Webhook Signatures
Settings
Transactions
Users & Roles
Wallets
Troubleshooting
On this page
Overview
Best practices
Related
Security
Origin Domains
Restrict which website origins may initialize payment flows.
Overview
Add allowed origins (e.g.,
https://www.example.com
) to prevent unauthorized usage from other domains.
Best practices
Add production and sandbox origins separately
Use exact origins (scheme + host + optional port)
Related
Webhook Signatures:
/h2h/cpanel/security/webhook-signatures
Callbacks reference:
/h2h/ipg/callbacks
Refunds & Reversals
Webhook Signatures
Assistant
Responses are generated using AI and may contain mistakes.