Go-live checklist
There is no sandbox, so your first real customers are your launch. Walk through this before you switch your checkout on.
Account
- Verification documents are approved and live payments are enabled (keys can be generated).
- Your verification tier's limits cover your largest expected order and a busy day. See Limits.
- At least two people on your team have dashboard access, so you are never locked out.
Keys and secrets
- The secret key and webhook secret are in your server's environment or secret manager, not in code or the browser.
- Each website or app has its own connected app, keys and webhook URL.
- You know how to rotate keys (Rotating keys).
Creating charges
- Amounts are converted to minor units with the right decimals for each currency.
- Every
POSTsends anIdempotency-Keythat stays the same across retries. - Timeouts and 5xx responses are retried with the same key; 4xx responses are shown to the customer, not retried.
network_requiredis handled by asking the customer for their network.- The order stores SkanPay's charge id and your reference.
Webhooks
- The endpoint is HTTPS, public, and answers 2xx within 10 seconds.
- Signatures are verified over the raw body, with the timestamp check.
- Handling is idempotent on the event id.
- A paid order can never move back to unpaid.
- The amount and currency are checked against the order before fulfilment.
- Unknown event types are acknowledged with 2xx and ignored.
Customer experience
- After creating a charge, the customer sees clear instructions to approve on their phone.
- The page updates by asking your server, which learns from the webhook. The browser never calls SkanPay.
- Each
failure_codemaps to a helpful message, with a retry option.
Operations
- A scheduled job checks orders still awaiting payment after 30+ minutes (Reconciliation).
- You log SkanPay's
request_idwith every failed call. - You have made a real end-to-end charge to your own phone and seen the webhook arrive and the order update.