How to allow read response in my 2 websites

hi guys , so i have 2 website ,main website & second website
so the main website so whene someone try to buy products from my main website when is ready to pay im redirect the payment to the second website and he pay and then the seconde website redirect & send the payment informations to my main website and he get his products , im do that for many reasons.
so what is the problem , last days i get fake payments so i want to protect my website using clouflare , so im enabled under attake option to protect both of my website from DDOS & Anti Injection Etc…
But Whene the under attake option enabled in both 2 websites i cant receive the payment informations so i want to protect my both website using under attake option and make both 2 website receive the informations etc…
so that mean i want to make whitelist connection between my 2 website only and protected