Hacker News new | past | comments | ask | show | jobs | submit login

This is wrong. All you have to do is return a "200 OK" and PayPal will stop sending IPNs. You don't even need to perform the validation postback at all. It's completely optional.



But if you don't do the validation postback, anyone can fake an IPN message if they know your IPN URL.


I'm just saying the validation is not required. There are different ways to ensure the IPN is valid.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: