How it works
The browser cannot be trusted: a customer, or an attacker, can fake a 'payment successful' message or edit the amount in the page. So after checkout, the server checks the gateway's proof. Razorpay returns a signature, an HMAC SHA256 of the order id and payment id made with your secret key, which the server recomputes and compares; other gateways let the server fetch the payment from their API and compare its status, amount and currency with the order it created.
Webhooks are the second half. The gateway calls your server when a payment is captured, fails or is refunded, so the order is updated even if the customer closed the tab. Each webhook carries a signature header (X-Razorpay-Signature, Stripe-Signature) that must be checked against the raw request body with the webhook secret, and the handler should be idempotent, because the same event can arrive more than once.
Related terms
More in Payments
How it works