Why your merchant ID was withdrawn
Aggregation, the tightening of scheme enforcement, and the three structures acquirers will actually accept, with what each one costs.
Written down so we stop rediscovering them. Payments infrastructure, regulated data, testing discipline, and systems that outlive the people who wrote them.
Aggregation, the tightening of scheme enforcement, and the three structures acquirers will actually accept, with what each one costs.
Rewriting API calls is a week. Stored tokens, webhook semantics and provider vocabulary sitting in your schema are the quarter.
Not a scale problem, a risk problem. Four of the five triggers are about something going wrong. Build, buy, and the cheap version first.
Better authorisation rates and cards that survive reissue. Whether they also free you from your gateway depends on whose name is on the Token Requestor ID.
Six structural reasons they diverge, why a balance column fails at the first chargeback, and reconciliation that still gets read after a fortnight.
Three ways to take money with genuinely different economics. Cost, settlement, reversals, friction and recurring, compared plainly.
Open banking was meant to give merchants a cheaper alternative to cards. Below a certain volume it mostly has not, and the reason is arithmetic.
Licensing is the obvious constraint. The one that catches teams out is that the card schemes classify your category independently, and marketplaces get it worst.
Realistic data makes better software. A production restore in staging makes a breach inevitable. A pipeline gets you the first without the second.
Generated code is fluent and confident regardless of correctness, which neutralises the reviewer's best heuristic. The suite does not care how plausible it looks.
Four requirements, all of which turn out to be what a new engineer needs stated explicitly. Which is why disciplined projects needed almost no changes.
Our working standard, published. Enforced conventions rather than documented ones, per-layer coverage, deterministic data, migrations checked before merge.
Renewals, trials, instalments and dunning are all time-dependent. Read from the system call they are untestable, and they fail on the 31st.
Caches, sequential IDs, file storage, search indexes, error reporting, email. Isolation is not a database property.
Someone abandons at step six and returns a fortnight later. That is the normal case, not the recovery case.