Braintree is PayPal’s payment processing platform, used by merchants to accept cards, digital wallets, and other payment methods through a hosted gateway. Two distinct kinds of automated traffic are associated with it, and it’s worth separating them clearly. The first is outbound: a merchant’s own server calling Braintree’s API (api.braintreegateway.com) to create transactions, tokenize payment methods, or manage subscriptions. The second — the traffic relevant to a bot-management context — is inbound: Braintree’s servers calling a merchant-configured webhook endpoint to push real-time notifications about events like a completed subscription charge, a dispute, or a disbursement.
Unlike a search crawler or a monitoring probe, Braintree does not publish a distinct, memorable user-agent string for its webhook calls. Its authentication model is built around a different mechanism entirely: every webhook notification carries a signed payload (bt_signature and bt_payload) that the receiving application verifies cryptographically using its Braintree private key, via the official SDK. Braintree also publishes its production and sandbox IP addresses and domains in a JSON file specifically so merchants can allowlist its infrastructure at the network layer, in addition to signature verification. Because this traffic sits directly in a payment flow, DataDome classifies Braintree under security intelligence and payment infrastructure — automated, essential traffic where spoofing risk carries real financial consequence rather than a mere nuisance.