TL;DR: A 3D Secure or HTML flow is missing the origin field. Send your checkout page origin (scheme plus host) and make sure it matches the origins registered for your client key.

The exact error:

```text
14_013 - For HTML Response; origin has to be provided
```

## The fix

1. Read the page origin (scheme plus host, no path) on the client and send it as the origin field.
   Expected: You know which origin the checkout page is served from.
2. Check the allowed origins in the Adyen Customer Area and add the missing one.
   Expected: The origin matches what is registered for your client key.
3. Resubmit and confirm the origin in the request matches the page the shopper is on.
   Expected: The HTML flow completes instead of returning 14_013.

## When this applies

- A redirect or 3DS step returns 14_013
- You just moved checkout to a new domain
- Testing on a new environment whose origin was never registered

## When it does NOT apply

- You use /sessions, where origin is set once on session creation
- The error is about the client key rather than a missing origin
- A pure API-to-API flow with no shopper-facing HTML

## Versions

Adyen Checkout API v68 through v71.

## Why it happens

HTML-response flows need the merchant origin for security checks and response construction. Without it Adyen cannot verify the request came from a registered checkout page, so it rejects the call.

## Edge cases and pitfalls

- The origin must match the domain registered for your client key, including the scheme
- YOUR_HOST testing needs its own registered origin; the live domain will not cover it
- Some flows accept notificationURL instead, but redirect and 3DS flows want origin
