Detect
Signed Razorpay webhooks — payment.failed, mandate and invoice events — verified by HMAC before anything else.
Every failed payment has a reason. RecoverFlow reads the evidence, picks one bounded recovery action, and waits for a human — leaving a tamper-evident trail behind every decision.
Built for OTP timeouts
Detect → Diagnose → Bound → Recover
Regression suite, reproducible with npm run evaluate
At most one retry per payment per day
Pure Node. Nothing to patch, nothing to trust.
Signed Razorpay webhooks — payment.failed, mandate and invoice events — verified by HMAC before anything else.
Evidence-grounded cause with a calibrated confidence. No evidence, no recommendation.
A deterministic policy layer checks consent, retry limits, duplicates and amount thresholds.
A human approves one action. The outcome and its evidence are sealed into the audit chain.
Each entry commits to the one before it. Edit history and the chain visibly breaks.
public/ is servedThese run on every event, before a human ever sees a recommendation.
Try to break them →No contact after opt-out. Ever.
Payments above ₹5,00,000 go to senior review.
Duplicates, disputes and mandate loops are held for a human.
Unsure diagnoses never become actions.
Everything else still needs one explicit approval.
No. The demo uses synthetic payments, and the optional integration only accepts Razorpay Test Mode keys. No action executes without human approval.
The AI classifies the cause and drafts an intervention. A deterministic policy engine decides what is allowed, and a human approves it.
The diagnosis, policy engine, HMAC verification, idempotency and audit chain are real code with tests. The sample payments and the batch outcome simulator are illustrative and labelled as such.
Deploy, set RAZORPAY_WEBHOOK_SECRET, add /webhooks/razorpay in the Test Mode dashboard, and trigger a failed test payment. See the deployment runbook in the repo.
Open the dashboard, run a sweep, and approve your first recovery in under a minute.