Guides
Going live
The checklist to run before collecting real payments.
Account and affiliations
- The production organisation is verified (identity, documents, signed contract).
- One active affiliation per provider you offer, with your production credentials.
- The production payment account is identified (production Wallet ID).
Keys and secrets
- A production API key, distinct from the sandbox key, kept in a vault or a server environment variable.
- The key appears in no code repository, log, URL, web page or mobile app.
- A procedure to revoke and replace the key if it leaks.
Integration
- The API URL points to production (
https://api.konnect.network), not the sandbox. - The order is delivered only after reading the payment:
statusiscompleted, amount andorderIdmatch. - Webhook handling is idempotent and answers within 10 seconds.
-
successUrlandfailUrluse HTTPS and show a clear message to the buyer. - Amounts are in millimes (TND) and checked on an order with several items.
-
4xxand5xxerrors are logged without the API key or card data.
Plugins
- The installed version is the latest on the Plugins page, its SHA-256 sum checked.
- The mode is switched from Sandbox to Production, with the production key and Wallet ID.
First day
- A small real payment, end to end, then its refund if needed.
- The first payments followed in the dashboard; any anomaly reported to Konnect support.