puffin.js opens the hosted checkout in a
sandboxed iframe modal and reports status back via callbacks.
Install
Open a payment intent
Create the intent server-side (hosted checkout), pass the id to the browser:Open a payment link
No backend at all:customerEmail when you already know it and the payer sees it masked
and locked. Omit it and the modal opens the hosted link page first, which
collects the payer’s own address for the receipt — either way no one signs
in, and callbacks fire the same.