Skip to main content
Cresora Commerce
Getting Started

Go-Live Checklist

Complete these steps before moving from sandbox to production.

Before you can receive production credentials, Cresora requires you to pass certification. Work through this checklist in order.

Certification

πŸ”’Required

All partners must complete Cresora certification before going live. Certification validates your integration handles edge cases (declines, refunds, webhook retries) correctly.

See the Certification overview β†’

Technical checklist

  • All API calls use Idempotency-Key headers
  • Webhook signatures verified server-side (HMAC-SHA256)
  • Webhook receiver handles retries idempotently
  • Error handling covers 4xx and 5xx responses gracefully
  • No raw card data passes through your server
  • PCI scope documented and SAQ completed
  • Test card flows verified: approval, soft decline, hard decline, refund
  • ACH return handling implemented (if using ACH)

Operational checklist

  • Merchant onboarded and approved in production
  • Go-live gates cleared (see Merchant Onboarding)
  • Support escalation path documented
  • Monitoring and alerting wired to webhook transaction.failed events

Switching to production

Once certification is complete and Cresora grants your production credentials:

  1. Point your integration at the production host (api.cresoracommerce.ai) and swap your sandbox key for your production key in your secrets manager
  2. Verify your webhook endpoint URL is publicly reachable
  3. Process a small real transaction as a smoke test
  4. Monitor your first 24 hours of live traffic closely