Docs / Get started
Go live
The checklist to move your Tranzak integration from the sandbox to production: verification, live keys, webhook URL and a first real payment.
When your integration passes the sandbox scenarios, you can take real payments. Going live is a step you take in the dashboard.
What changes in production
| Sandbox | Production | |
|---|---|---|
| API key | tk_test_… |
tk_live_… |
| Money | Simulated | Real |
| Cards | Stripe test cards | Real cards, after Tranzak approves card access |
| Base URL | https://api.tranzak.co/api/gateway/v1 |
The same |
The code and the URLs do not change. Only the key changes.
Checklist
- Verify your identity. Live mode unlocks after Tranzak approves your identity verification from the dashboard.
- Generate a live key (
tk_live_…) under Developer → API Keys and store it as an environment variable on your production server. Keep your test key for your staging environment. - Register your production webhook URL. It must be a public
https://address on a domain name, notlocalhost, not an IP address and not a private network. - Set your return URL if customers should come back to your site after paying.
- Request card access (only if you accept cards). Open Payment methods → Request access in the dashboard. Until Tranzak approves it, live card payments answer
403 payment_method_not_approved. - Run a real payment with a small amount and check the whole path: the order is created, the customer pays, the webhook arrives, the order is marked paid once.
Production readiness
- No key or secret in code, front end, repository history or logs.
- Amount and currency are computed on your server from your own order data.
- Orders are fulfilled only after server-side confirmation, exactly once.
- The webhook checks the signature on the raw body, answers
2xxquickly and ignores duplicates. - Pending orders are reconciled on a timer, because no webhook is guaranteed for an expired payment.
- Each order has a unique
reference, and a double click on Pay cannot create two payments. - Every error in Errors and rate limits is handled, with no technical detail shown to customers.
- A
429response is handled with a back-off.
Tip Keep a separate website, with its own webhook secret and keys, for each environment (staging and production).