> For the complete index of the 402pay docs, see [llms.txt](https://402pay.co/docs/llms.txt).

# Going live

Everything to check before you take real payments, and after.

> There is no test mode, so everything you created while building is real and already in your data. Review it before launch.

## Before you launch

- [ ] **Create a production secret key**: Give your production environment a `402s_live_` key of its own, restricted to the resources your server uses, and revoke the keys you built with.
- [ ] **Add a production webhook endpoint**: Subscribe to `payment.succeeded`, plus `payment.underpaid` and `payment.needs_review` if you handle them, verify every signature, and skip deliveries whose `webhook-id` you've already handled.
- [ ] **Set your redirect URLs**: Point `success_url` and `cancel_url` at your production pages, on each payment or link. They must use `https://`; `http://` works only for `localhost` and `127.0.0.1`.
- [ ] **Choose what checkout accepts**: Pick your coins and networks, and turn cards on or off, in Settings, under Payments.
- [ ] **Handle every outcome**: Make sure your integration handles [underpaid, overpaid and late transfers](https://402pay.co/docs/guides/underpayments.md) and [declined cards](https://402pay.co/docs/guides/card-payments.md#failure-codes), and try a small payment of your own from start to finish.

## Secure your account

- [ ] **Add a passkey**: Settings, under General. It signs in without a password or two-step code, and works only on 402pay's own site, so it can't be phished.
- [ ] **Use a long, unique password**: A password manager can make one for you. Change it in Settings if someone may have seen it; that signs out your other devices.
- [ ] **Turn on two-step verification**: Settings, under General. Store the recovery codes somewhere other than your authenticator.
- [ ] **Keep your email account secure**: Password resets and security emails go to the address you sign in with, so protect that mailbox with two-step verification too.
- [ ] **Back up your wallet**: Keep your recovery phrase and encryption password somewhere safe and offline. 402pay can't recover either one.

## After launch

- Watch webhook deliveries in the dashboard, and resend any that failed.
- Handle [underpaid and late payments](https://402pay.co/docs/guides/underpayments.md) as they come in, so no customer is left waiting.
- Rotate a webhook secret or API key whenever someone with access leaves your team.
