Certification
Go-Live Process
What happens after certification completes and how to switch to production.
Once your certification run completes, production access follows. Production is a
separate deployment with its own host (api.cresoracommerce.ai), its own Partner
Portal, and its own credentials — nothing from the sandbox carries over.
Getting your production key
- Sign in to the production Partner Portal (access is provisioned at certification completion — your account manager confirms when)
- Go to Developers → API keys and create a key — you create it yourself; Cresora does not email keys
- The secret is displayed once, in the creation dialog — store it in your secrets manager immediately
Deploying to production
- Point your integration at the production host and load the production key from your secrets manager (never source control)
- Register your production webhook endpoint under Developers → Webhooks — the sandbox registration does not carry over; copy the new signing secret (shown once)
- Process a small real transaction as a smoke test
- Monitor the first 24 hours — watch
transaction.failedwebhooks and your decline rate
⚠Warning
Production merchant ids are different UUIDs from sandbox — every merchant is onboarded and taken live in production separately. Update every stored id.
Production key hygiene
- Secrets-manager storage only; never log the key
- Rotate on your own schedule (rotation keeps the old key valid through a grace window); revoke immediately on any suspected compromise — revoke has no grace
- See Key management →
After go-live
- Alert on
transaction.failedspikes - Subscribe to the Changelog RSS → for contract changes