Proteside Docs

Payment integrity

See, method by method, whether what the customer sees at checkout is the payment your store generated.

The Payment Integrity page shows a card for each payment method monitored in the store: card, Pix, clipboard, cryptocurrency, boleto and others. For each one, you see whether the observed payments are intact and whether the recipient shown to the customer really belongs to your store.

Payment Integrity page with the Credit card, Pix and Clipboard cards, the Intact status, the unregistered recipient notice on Pix and the Show other available methods link
A method's card (1), status (2), recipient notice with Register (3) and other methods (4).

What each card shows

Each card (1) includes:

  • the method's name and a description of what's monitored;
  • the status (2), explained below;
  • Last validated, when the last payment was checked, or "Waiting for the first transaction of this type";
  • the recipient's situation (3), for methods that have a recipient (Pix, cryptocurrency, UPI and boleto).

Credit card has no recipient: the SDK checks the payment provider's form and iframes. On Clipboard and the other methods, the card says the method doesn't need a registered recipient.

Status

StatusMeaning
NOT CONFIGUREDThe store hasn't sent any SDK event yet, or the method isn't among the monitored ones.
WAITINGThe SDK is active, but no payment of this type has been observed yet. It changes on its own when a customer pays.
INTACTThe last observed payment was validated and there's no open tampering alert.
TAMPEREDThere's an open tampering alert for the method. The card turns red and shows Divergence detected.

The alerts that make each method TAMPERED:

MethodAlerts
Credit cardKeylogger Detected, Form Action Hijack, Iframe Replaced, Unexpected Iframe, Card Field Outside Vault, Amount Tampered
PixPix Tampered (and Amount Tampered on Pix)
CryptocurrencyCrypto Address Swap, QR Tampered
BoletoBoleto Tampered
UPIUPI Tampered
ClipboardClipboard Hijack

See what each alert means in Alerts.

When a method shows as TAMPERED

Open the alert

On the red card, click View Alert →. The Alerts page opens with the alert highlighted.

Investigate

Check the Technical details to see what changed and on which page. A Pix with a recipient outside your list or a form with a changed destination point to an attack until proven otherwise: check the page's scripts in Scripts and the recent changes to the site.

Resolve the alert

After you deal with the cause, resolve the alert with a note. The method goes back to INTACT or WAITING.

Snoozing doesn't take the method out of TAMPERED

A snoozed alert stays open, and the method remains TAMPERED until you resolve the alert. The date in Divergence detected is when the most recent open alert was created, not when it last occurred.

Trusted recipients

The recipient check compares the Pix key, the crypto address, the UPI VPA or the boleto bank shown at checkout with the list of recipients that belong to your store. Without this list, a code tampered with from the first time it's shown would pass as legitimate.

The card shows one of three situations:

  • Recipient matches the trusted list: all good.
  • Recipient does NOT match the trusted list: the recipient shown isn't yours. Treat it as an incident.
  • No trusted recipient registered for this method., with the Register link (3).

Click Register

The link (3) opens Settings → Payment protection, in the Trusted recipients section, with the method already selected. On the Cryptocurrency card, the selected method is always Bitcoin; for Ethereum, change it in the Method field.

Add the recipient

Enter the Key and, if you like, a Label, and click Add. The full walkthrough is in Payment protection.

Only owners and admins can register recipients. Proteside stores only the hash and a mask of the key.

Other available methods

Methods that aren't among the store's monitored methods are collapsed. Click Show other available methods (N) (4) to see all of them, such as boleto, QR wallets (Mercado Pago, PicPay and others), UPI and instant payments from other countries (PayNow, PromptPay, DuitNow, QR Ph, HK FPS, Transferencias 3.0 and CoDi). They show as NOT CONFIGURED, with the Enable in Payment protection link.

A method with observed payments or with an open alert always shows in the main grid, even if it isn't selected.

Limitations

Unselecting a method doesn't turn off detection

In Payment protection → Payment methods, the list of methods only decides which cards are featured on this page. The SDK keeps recognizing and validating every method. If no method is selected, the page assumes card and Pix, contrary to what the notice on that screen says.

Dynamic Pix and utility boletos without recipient check

Dynamic Pix (a QR code with a charge link, common with gateways) doesn't carry the recipient's key in the code, so there's no way to compare it with your list. The same applies to utility and tax boletos (48-digit line), which have no bank code. In these cases, the SDK only detects changes to the code after it's first shown, and the method's card keeps showing "No trusted recipient registered", even with recipients on the list.

The unregistered recipient notice may be wrong

On a TAMPERED method, the card always shows "No trusted recipient registered", even if you've registered one. The same can happen with old SDK versions. Check the list in Payment protection before registering again.

  • QR wallets and instant payments from other countries never become TAMPERED on this page. When the SDK detects a changed QR code on these methods, the QR Tampered alert appears on the Cryptocurrency card.
  • Clipboard shows as INTACT as soon as the store sends any event. It means there's no open content-swap alert, not that a copy was observed.
  • Pix code in a form field (for example, a read-only field with the Pix copy-and-paste code) isn't read by the SDK. Show the code as text on the page.
  • Short history: events are deleted after the plan's history period (30 days on Essential). If there are no events in the period, every method goes back to NOT CONFIGURED.
  • The page shows whether the payment matches or not, without a side-by-side comparison of the expected and observed values. The data for each divergence is in the alert.

Who can see it

Every role sees this page. It has no actions that change anything: registering recipients and choosing methods are done in Payment protection.

Next steps

On this page