postMessage events. Use them to update your UI, for example to close the widget when the user is done or show that a payment method was added.
Payout status changes don’t come through browser events. They reach your backend by webhook.
Listening for events
Take the trusted origin from thewidget_url your backend received, and check both the origin and the source window on every message:
Events
Treat these events as UI signals. For anything that affects money, like a completed or failed payout, rely on the webhook your backend receives.
Commands you can send
After the same origin and source checks, your page can send these commands to the widget withpostMessage:
Refreshing a session
When a session is about to expire, the widget sendsZBD_SESSION_REFRESH_REQUIRED with a request_id. Ask your backend to create a new session, then send the new token back with ZBD_SESSION_REFRESH_RESULT and the same request_id. The user stays where they are in the flow.