Reference

Go-Live Checklist

Before switching to production, complete this checklist to ensure your integration is secure and ready.

Security

  • [ ] Production API keys stored in secure environment variables
  • [ ] Webhook signature verification implemented
  • [ ] HTTPS enforced for all API calls
  • [ ] No API keys in version control or client-side code
  • [ ] Webhook endpoint uses HTTPS
  • [ ] Input validation on all customer-facing endpoints

Payment Flow

  • [ ] Test checkout flow with a test (cp_test_) key
  • [ ] Implement payment status polling or webhook handling
  • [ ] Test duplicate webhook delivery and confirm only one wallet credit
  • [ ] Verify reconciliation is enabled and observe one five-minute interval
  • [ ] Handle all payment statuses (pending, completed, failed, voided, expired)
  • [ ] Generate unique idempotency keys for each transaction
  • [ ] Display clear error messages to customers
  • [ ] Complete KYC with valid ID front, ID back, and selfie images
  • [ ] Confirm your account is KYC-verified before going live

Webhooks

  • [ ] Webhook registered on your developer app
  • [ ] Webhook endpoint deployed and accessible
  • [ ] Signature verification implemented
  • [ ] Idempotent event handling (process events only once)
  • [ ] Async processing (return 200 immediately)
  • [ ] Checked GET .../webhook/deliveries for repeated failures

Payouts

  • [ ] Verify sufficient wallet balance before payout
  • [ ] Display fee breakdown to users
  • [ ] Handle payout failures and reversals
  • [ ] Understand that ambiguous payouts remain recoverable until provider status is confirmed
  • [ ] Implement refund logic for failed payouts

Monitoring

  • [ ] Log all API requests and responses (without sensitive data)
  • [ ] Monitor webhook delivery success rate
  • [ ] Set up alerts for failed payments
  • [ ] Track idempotency key usage