A key only reaches the workspace it was created in, so objects never cross between sandbox and live.
To check which environment a key belongs to, retrieve the account and
read
environment.
Going live
Nothing in your code changes shape between the two; what changes is which workspace it talks to:- Keys. Create a secret key and, for Elements, a publishable key in the live workspace (Settings → Integrations)
and swap them into your server and page. A sandbox key answers
401 invalid_api_keyon the live workspace’s objects and the other way round:pay_test_…ids never appear in live, andpay_live_…never in sandbox. - Webhooks. Endpoints belong to one workspace and environment. Register your endpoint again with a live key
(
POST /webhook-endpoints) and store the newwhsec_live_…secret next to thewhsec_test_…one: a delivery is signed with the secret of the endpoint it goes to, so your verify step needs the secret that matcheslivemode. - Money. A live charge moves money and a live refund sends it back. Test cards are refused, the processor’s
own batch schedule decides when a bank debit settles and when a card refund is accepted, and a bank return or a
chargeback can arrive days after
succeeded, aspayment.returned. - Processor. Sandbox and live use the processor accounts Payra set up on each workspace, so a currency or a
payment method your sandbox accepted may answer
400 payment_provider_not_configuredon live until Payra enables it there. Check with Payra before launch.
Switching a workspace between sandbox and live
Payra switches a workspace’s environment for you. When it does, every one of its API keys is revoked, and requests with them answer401 invalid_api_key. Create new keys after the switch and replace them in your
server. Webhook endpoints belong to one environment too: register them again, and store their new signing
secrets.