SubscriptionConfirmation message that must be confirmed before notifications flow.?client-id=<your client id> query parameter to the subscription URL at creation (visible on the stored url); your endpoint receives it on every delivery.id, but an upstream replay of the same event generates a new one.SigningCertURL, having first confirmed that URL is an https host under amazonaws.com; never fetch an arbitrary URL taken from the payload. Then compare the envelope's TopicArn against the per-environment topic ARN Kobble issues you at onboarding. The signature alone proves only that a message originated from AWS, not that it originated from Kobble, so an endpoint that checks the signature but not the topic will accept any signed SNS message from any AWS account.ACCEPTED and transaction-accept is delivered. A dishonour after settlement arrives as a new REFUND transaction carrying the original transaction's id in external_id, while the original stays ACCEPTED — a reversal can never be detected by watching the original transaction's status.