Go-live checklist
Check every item before switching to Live keys.
Integration
- Payments are created server-side with a secret key, never from the browser.
- Every POST sends an Idempotency-Key derived from your own record (order or refund ID).
- Orders are fulfilled from the payment.completed webhook or a GET of the payment — never from the return_url alone.
- Your webhook handler verifies the signature and timestamp, answers 2xx within 10 seconds, and de-duplicates by event ID.
- You handle every payment status, including unknown (do not charge the customer again).
- Errors are logged with their request_id.
Refunds
- Refunds send a stable Idempotency-Key, so a retry can never refund twice.
- Your support team knows that providers without a refund API require the refund in the provider's portal.
Security
- Secret keys and webhook secrets are stored in a secrets manager, not in code or client apps.
- Live keys use only the scopes you need.
- Two-factor authentication is on for every dashboard user.
Account
- Email address verified and business verification approved.
- Live provider connections created with your own credentials, and the provider is certified by OneGate.
- Your checkout domain is verified; return URLs use HTTPS.
Do a small real payment and a refund with your own card or wallet right after going live, and check the webhook and dashboard records.