Skip to content

Go-live checklist

Work through this before you point an application at production.

  • Your Pesepay merchant account has been approved (see Onboarding)
  • You’ve swapped sandbox base URLs (api.test.sandbox.pesepay.com) for production (api.pesepay.com) — see API Introduction
  • Your production integration key and encryption key are stored as server-side secrets, never in client code — see API Keys & Credentials
  • Sandbox keys are gone from the production build entirely, not just unused
  • Your payout account is configured and approved, for every currency you charge in
  • resultUrl is a publicly reachable HTTPS endpoint on your server that handles the result callback
  • Your handler verifies before fulfilling — it calls Check Payment Status rather than trusting the callback body (why)
  • Your handler is idempotent, keyed on referenceNumber
  • You run a reconciliation job for orders whose callback never arrived — callbacks are never retried
  • Nothing marks an order paid on returnUrl alone
  • You’ve tested at least one full payment per method you plan to support, using real small-value transactions
  • You’ve tested a failed payment per method, not just successes
  • You have made a small-value production payment for every method the sandbox can’t exercise — InnBucks, Omari, Zimswitch, PayGo, and any Zimbabwe dollar checkout
  • Your checkout validates amounts against each method’s limits — they differ per method and currency, and Get Payment Methods by Currency returns the live values
  • If you accept EcoCash, you handle payments above $500 — the customer sees several prompts, and a partial failure reverses the whole payment
  • Your error handling covers the statuses in the error catalog and the non-success transaction statuses, not just the happy path
  • You are sending customers to the hosted page for card entry — card payments are redirect-only, so no card data should ever reach your servers