Skip to content

Going live

Everything to check before you take real payments, and after.

There is no test mode, so everything you created while building is real and already in your data. Review it before launch.

Before you launch

0 of 5 done

  • Give your production environment a 402s_live_ key of its own, restricted to the resources your server uses, and revoke the keys you built with.
  • Subscribe to payment.succeeded, plus payment.underpaid and payment.needs_review if you handle them, verify every signature, and skip deliveries whose webhook-id you've already handled.
  • Point success_url and cancel_url at your production pages, on each payment or link. They must use https://; http:// works only for localhost and 127.0.0.1.
  • Pick your coins and networks, and turn cards on or off, in Settings, under Payments.
  • Make sure your integration handles underpaid, overpaid and late transfers and declined cards, and try a small payment of your own from start to finish.

Secure your account

0 of 5 done

  • Settings, under General. It signs in without a password or two-step code, and works only on 402pay's own site, so it can't be phished.
  • A password manager can make one for you. Change it in Settings if someone may have seen it; that signs out your other devices.
  • Settings, under General. Store the recovery codes somewhere other than your authenticator.
  • Password resets and security emails go to the address you sign in with, so protect that mailbox with two-step verification too.
  • Keep your recovery phrase and encryption password somewhere safe and offline. 402pay can't recover either one.

After launch

  • Watch webhook deliveries in the dashboard, and resend any that failed.
  • Handle underpaid and late payments as they come in, so no customer is left waiting.
  • Rotate a webhook secret or API key whenever someone with access leaves your team.