Skip to main content
Every Payra workspace is either sandbox or live, and its keys follow it. A key only reaches the workspace it was created in, so objects never cross between sandbox and live. To check which environment a key belongs to, retrieve the account and read environment.

Going live

Nothing in your code changes shape between the two; what changes is which workspace it talks to:
  • Keys. Create a secret key and, for Elements, a publishable key in the live workspace (Settings → Integrations) and swap them into your server and page. A sandbox key answers 401 invalid_api_key on the live workspace’s objects and the other way round: pay_test_… ids never appear in live, and pay_live_… never in sandbox.
  • Webhooks. Endpoints belong to one workspace and environment. Register your endpoint again with a live key (POST /webhook-endpoints) and store the new whsec_live_… secret next to the whsec_test_… one: a delivery is signed with the secret of the endpoint it goes to, so your verify step needs the secret that matches livemode.
  • Money. A live charge moves money and a live refund sends it back. Test cards are refused, the processor’s own batch schedule decides when a bank debit settles and when a card refund is accepted, and a bank return or a chargeback can arrive days after succeeded, as payment.returned.
  • Processor. Sandbox and live use the processor accounts Payra set up on each workspace, so a currency or a payment method your sandbox accepted may answer 400 payment_provider_not_configured on live until Payra enables it there. Check with Payra before launch.

Switching a workspace between sandbox and live

Payra switches a workspace’s environment for you. When it does, every one of its API keys is revoked, and requests with them answer 401 invalid_api_key. Create new keys after the switch and replace them in your server. Webhook endpoints belong to one environment too: register them again, and store their new signing secrets.