Go live
Production checklist
Confirm each check in the live environment. Keep this list with your release process.
Credentials and configuration#
| Check | Why |
|---|---|
Live requests use a key that starts with mx_live_. |
A sandbox key reaches only sandbox data. |
| No API key or webhook secret is in client code, source control, or logs. | A leaked key or secret gives access to your account or lets anyone forge events. |
| Each live key holds only the scopes that it needs. | A leaked key can do less. |
| Live configuration has no sandbox price IDs, sandbox keys, or sandbox URLs. | Sandbox IDs do not exist in live. |
| Onboarding is complete in the dashboard. | Onboarding records the business details of your account. See Go live. |
Webhooks#
| Check | Why |
|---|---|
The live endpoint uses https and a public host. |
Live deliveries to other URLs fail. |
| Signature verification is on, with the live signing secret. | Unverified requests can be forged. |
Event processing is idempotent by event id. |
Merxian can deliver an event more than once. |
The endpoint returns 2xx quickly. |
Slow responses cause retries. |
| You monitor failed deliveries and errors in your endpoint. | Deliveries stop after the retry window. See Delivery and retries. |
Payment handling#
| Check | Why |
|---|---|
You fulfil only on payment.succeeded or transaction.completed. |
Other signals do not prove payment. |
| Failed, canceled, and expired payments and sessions are handled. | Each one needs a clear state in your system. |
Refund results come from refund.succeeded and refund.failed. |
A refund request is not a result. |
| You tested the failure paths in the sandbox. | See Test scenarios. |
Operations#
| Check | Why |
|---|---|
Your logs keep X-Request-Id for each API response. |
It identifies a request when you need help. |
Your client handles 429 with Retry-After, and retries 5xx with the same Idempotency-Key. |
Retries must be safe and must not overload the API. |
| A periodic job compares your records with the list of transactions. | It finds changes that events missed. |