Skip to content
OneGate documentation
Dashboard
Guides

Go-live checklist

Check every item before switching to Live keys.

Integration

  • Payments are created server-side with a secret key, never from the browser.
  • Every POST sends an Idempotency-Key derived from your own record (order or refund ID).
  • Orders are fulfilled from the payment.completed webhook or a GET of the payment — never from the return_url alone.
  • Your webhook handler verifies the signature and timestamp, answers 2xx within 10 seconds, and de-duplicates by event ID.
  • You handle every payment status, including unknown (do not charge the customer again).
  • Errors are logged with their request_id.

Refunds

  • Refunds send a stable Idempotency-Key, so a retry can never refund twice.
  • Your support team knows that providers without a refund API require the refund in the provider's portal.

Security

  • Secret keys and webhook secrets are stored in a secrets manager, not in code or client apps.
  • Live keys use only the scopes you need.
  • Two-factor authentication is on for every dashboard user.

Account

  • Email address verified and business verification approved.
  • Live provider connections created with your own credentials, and the provider is certified by OneGate.
  • Your checkout domain is verified; return URLs use HTTPS.
Do a small real payment and a refund with your own card or wallet right after going live, and check the webhook and dashboard records.