1
Verify configuration
Copy the live API URL from the dashboard. Register every success and
cancellation origin and confirm they use HTTPS where required by your setup.
2
Verify secrets
Keep test and live API keys separate. Store keys and the webhook signing secret
server-side, restrict access, and remove test credentials from live services.
3
Exercise the full flow
Create a small test checkout, redirect a customer, process a duplicate create
retry, observe a pending result, and confirm that only
completed fulfills.
For CS2, verify the eight-day reservation sequence: once hold begins, keep the
merchant order reserved and finalize only on payment.completed, using the
returned holdUntil rather than a local timer. For canceled, declined, failed,
or reverted results, keep fulfillment disabled and release the reservation
through your normal process.4
Verify webhooks
Use a public HTTPS endpoint, verify exact raw bytes and timestamp freshness,
return 2xx after durable storage, and test duplicate delivery safely.
5
Go live and monitor
Switch to the live key, preserve idempotency across network retries, monitor
status and warnings, and retain checkout/event/request IDs for support.
