payment.expired fires when a payment request reached its expires_at without being paid, 23 hours after it was created.
Read the payload
Thedata object is the full PaymentRequest from the API contract, the same object Retrieve a payment request returns. The envelope around it is the same on every event and is described in the event catalog.
Handle the event
Close the order fordata.id, or create a new request if the person still wants to pay.

