Reference
Go-Live Checklist
Before switching to production, complete this checklist to ensure your integration is secure and ready.
Security
- [ ] Production API keys stored in secure environment variables
- [ ] Webhook signature verification implemented
- [ ] HTTPS enforced for all API calls
- [ ] No API keys in version control or client-side code
- [ ] Webhook endpoint uses HTTPS
- [ ] Input validation on all customer-facing endpoints
Payment Flow
- [ ] Test checkout flow with a test (cp_test_) key
- [ ] Implement payment status polling or webhook handling
- [ ] Test duplicate webhook delivery and confirm only one wallet credit
- [ ] Verify reconciliation is enabled and observe one five-minute interval
- [ ] Handle all payment statuses (pending, completed, failed, voided, expired)
- [ ] Generate unique idempotency keys for each transaction
- [ ] Display clear error messages to customers
- [ ] Complete KYC with valid ID front, ID back, and selfie images
- [ ] Confirm your account is KYC-verified before going live
Webhooks
- [ ] Webhook registered on your developer app
- [ ] Webhook endpoint deployed and accessible
- [ ] Signature verification implemented
- [ ] Idempotent event handling (process events only once)
- [ ] Async processing (return 200 immediately)
- [ ] Checked GET .../webhook/deliveries for repeated failures
Payouts
- [ ] Verify sufficient wallet balance before payout
- [ ] Display fee breakdown to users
- [ ] Handle payout failures and reversals
- [ ] Understand that ambiguous payouts remain recoverable until provider status is confirmed
- [ ] Implement refund logic for failed payouts
Monitoring
- [ ] Log all API requests and responses (without sensitive data)
- [ ] Monitor webhook delivery success rate
- [ ] Set up alerts for failed payments
- [ ] Track idempotency key usage
