Skip to content
Developer guide

Go-live checklist

What must be true before you point production traffic at us.

1 / 3

Before the switch

Secret keys are server-side only
Not in a mobile binary, not in a front-end bundle, not in a repository.
Idempotency-Key on every money call
Derived from your order id — stable across retries.
Webhook signature verified
Over the RAW body, with the 5-minute window enforced.
Webhook handler is idempotent
The same delivery id can arrive twice.
Handler answers in under 10 seconds
Persist, return 2xx, process asynchronously.
You poll pending charges
A lost webhook must not become a lost payment.
You handle missing_required_fields
Ask the buyer for the field and retry with the same key.
You show amountLocal to the buyer
Never the USD figure.
You handle 429 with Retry-After
Back off on the header.
Key2Pay Developer documentationAPI v1
Documentation
Dashboard