Go-live checklist
Work through this before you point an application at production.
Credentials and environment
Section titled “Credentials and environment”- Your Pesepay merchant account has been approved (see Onboarding)
- You’ve swapped sandbox base URLs (
api.test.sandbox.pesepay.com) for production (api.pesepay.com) — see API Introduction - Your production integration key and encryption key are stored as server-side secrets, never in client code — see API Keys & Credentials
- Sandbox keys are gone from the production build entirely, not just unused
- Your payout account is configured and approved, for every currency you charge in
Getting paid reliably
Section titled “Getting paid reliably”-
resultUrlis a publicly reachable HTTPS endpoint on your server that handles the result callback - Your handler verifies before fulfilling — it calls Check Payment Status rather than trusting the callback body (why)
- Your handler is idempotent, keyed on
referenceNumber - You run a reconciliation job for orders whose callback never arrived — callbacks are never retried
- Nothing marks an order paid on
returnUrlalone
Payments and amounts
Section titled “Payments and amounts”- You’ve tested at least one full payment per method you plan to support, using real small-value transactions
- You’ve tested a failed payment per method, not just successes
- You have made a small-value production payment for every method the sandbox can’t exercise — InnBucks, Omari, Zimswitch, PayGo, and any Zimbabwe dollar checkout
- Your checkout validates amounts against each method’s limits — they differ per method and currency, and Get Payment Methods by Currency returns the live values
- If you accept EcoCash, you handle payments above $500 — the customer sees several prompts, and a partial failure reverses the whole payment
- Your error handling covers the statuses in the error catalog and the non-success transaction statuses, not just the happy path
If you take cards
Section titled “If you take cards”- You are sending customers to the hosted page for card entry — card payments are redirect-only, so no card data should ever reach your servers