Getting Started
Go-Live Checklist
Complete these steps before moving from sandbox to production.
Before you can receive production credentials, Cresora requires you to pass certification. Work through this checklist in order.
Certification
πRequired
All partners must complete Cresora certification before going live. Certification validates your integration handles edge cases (declines, refunds, webhook retries) correctly.
See the Certification overview β
Technical checklist
- All API calls use
Idempotency-Keyheaders - Webhook signatures verified server-side (HMAC-SHA256)
- Webhook receiver handles retries idempotently
- Error handling covers
4xxand5xxresponses gracefully - No raw card data passes through your server
- PCI scope documented and SAQ completed
- Test card flows verified: approval, soft decline, hard decline, refund
- ACH return handling implemented (if using ACH)
Operational checklist
- Merchant onboarded and approved in production
- Go-live gates cleared (see Merchant Onboarding)
- Support escalation path documented
- Monitoring and alerting wired to webhook
transaction.failedevents
Switching to production
Once certification is complete and Cresora grants your production credentials:
- Point your integration at the production host (
api.cresoracommerce.ai) and swap your sandbox key for your production key in your secrets manager - Verify your webhook endpoint URL is publicly reachable
- Process a small real transaction as a smoke test
- Monitor your first 24 hours of live traffic closely