Mellat/SEP return the result via a user-browser redirect (POST/GET), so the received IP is the user's, not Shaparak's. The IP allowlist therefore rejected every real callback — including user cancel — with 'forbidden'. Security is provided by the tamper check (RefId/SaleOrderId) and server-side verify. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>