Sandbox and test mode
Test your Tranzak integration with a test key: how each payment method behaves in the sandbox, test scenarios, test cards and local development without a public URL.
With a test key (tk_test_…), no real money moves. The behaviour is different for each method, so know it before you write your tests.
How each method behaves in test
| Method | Create | How it becomes completed |
Webhook sent | Failure test |
|---|---|---|---|---|
moncash |
201 with test_mode: true and simulated: true. payment_url is a sandbox URL that does nothing. |
Call POST /payments/{id}/verify. |
No | An amount of 1 answers 400 payment_processing_failed ("TEST MODE: Simulated payment failure"). |
natcash |
201. payment_url is a Tranzak URL. |
Open payment_url in the browser: the payment is completed and you are redirected to your return URL. Or call verify. |
Yes when opened through payment_url, no with verify. |
None: an amount of 1 is below the 20 HTG minimum. |
lakaypay_card |
201. The hosted page opens. |
The page simulates the confirmation, no card needed. | Yes | An amount of 1 answers 400, as above. |
card |
Real Stripe test mode, with a client_secret. |
Stripe test cards in the widget. | Yes, through Stripe. | Stripe decline test cards. |
Test cards
The card widget runs in Stripe test mode with a test key.
| Card number | Result |
|---|---|
4242 4242 4242 4242 |
Payment succeeds. |
4000 0000 0000 0002 |
Card is declined. |
Use any future expiry date and any three-digit security code.
Scenarios to run before going live
- A successful payment for each method you enable.
- A failed payment, where a failure test exists. The order must stay unpaid.
- A delayed confirmation: the customer returns before the payment is confirmed. Your page shows "checking", and polling completes it later.
- The webhook: a valid signature is accepted, a tampered body is rejected with 403, and the same event delivered twice fulfils the order once.
- A return URL with a modified
amountor an invalidsignatureis rejected or ignored.
Test your webhook handler without Tranzak
Build a signed request yourself: compute the HMAC of a sample body with a test secret (see Verify the signature) and send it to your endpoint. This also covers MonCash, which sends no sandbox webhook.
Local development without a public URL
Tranzak only sends webhooks to public addresses. You have two options:
- Poll
GET /payments/{id}(orPOST /payments/{id}/verify), and read the events feed. Feed the events to the same handler function you use for real webhooks. - Use an HTTPS tunnel (for example ngrok or Cloudflare Tunnel) and register the tunnel URL as the webhook URL of your website.
If you only need a placeholder while you test, register https://example.com/webhook and read the events feed.
Test data
Test transactions are removed by a nightly maintenance job. Do not rely on test data staying for more than a day.
Going further
When the scenarios pass, follow Go live.