Going live
Everything to check before you take real payments, and after.
There is no test mode, so everything you created while building is real and already in your data. Review it before launch.
Before you launch
0 of 5 done
- Give your production environment a
402s_live_key of its own, restricted to the resources your server uses, and revoke the keys you built with. - Subscribe to
payment.succeeded, pluspayment.underpaidandpayment.needs_reviewif you handle them, verify every signature, and skip deliveries whosewebhook-idyou've already handled. - Point
success_urlandcancel_urlat your production pages, on each payment or link. They must usehttps://;http://works only forlocalhostand127.0.0.1. - Pick your coins and networks, and turn cards on or off, in Settings, under Payments.
- Make sure your integration handles underpaid, overpaid and late transfers and declined cards, and try a small payment of your own from start to finish.
Secure your account
0 of 5 done
- Settings, under General. It signs in without a password or two-step code, and works only on 402pay's own site, so it can't be phished.
- A password manager can make one for you. Change it in Settings if someone may have seen it; that signs out your other devices.
- Settings, under General. Store the recovery codes somewhere other than your authenticator.
- Password resets and security emails go to the address you sign in with, so protect that mailbox with two-step verification too.
- Keep your recovery phrase and encryption password somewhere safe and offline. 402pay can't recover either one.
After launch
- Watch webhook deliveries in the dashboard, and resend any that failed.
- Handle underpaid and late payments as they come in, so no customer is left waiting.
- Rotate a webhook secret or API key whenever someone with access leaves your team.