> For the complete index of the 402pay docs, see [llms.txt](https://developer.402pay.co/llms.txt).

# Going live

Everything to check before you take real payments, and after.

> During the beta, test and live keys act on the same business: what you create with a test key shows up in your dashboard and in every list, like anything else, and every event's `mode` is `live`. On a live business a test key can read everything, but creating a payment, a checkout or a remainder, or changing what customers see or pay, answers 403 `test_mode_unavailable`, so a test key never moves real money or changes a live checkout. See [test and live keys](https://developer.402pay.co/testing.md#test-and-live). Everything you tried while building is already in your live data, so review it before launch.

## Before you launch

- [ ] **Create a live secret key**: Swap your `402s_test_` key for a `402s_live_` one in your production environment, and restrict it to the resources your server uses.
- [ ] **Take out test-only calls**: `simulate` and `POST /checkouts/{id}/mark-sent` exist for testing. Make sure production code never sends either.
- [ ] **Add a production webhook endpoint**: Subscribe to `payment.succeeded`, plus `payment.underpaid` and `payment.needs_review` if you handle them, verify every signature, and skip deliveries whose `webhook-id` you've already handled.
- [ ] **Set your redirect URLs**: Point `success_url` and `cancel_url` at your production pages, on each payment or link. They must use `https://`; `http://` works only for `localhost` and `127.0.0.1`.
- [ ] **Choose what checkout accepts**: Pick your coins and networks, and turn cards on or off, in Settings, under Payments.
- [ ] **Rehearse every outcome**: Run each [simulated outcome](https://developer.402pay.co/testing.md#simulate) through your integration, including underpaid and late transfers and [declined cards](https://developer.402pay.co/testing.md#card-outcomes).

## Secure your account

- [ ] **Add a passkey**: Settings, under General. It signs in without a password or two-step code, and works only on 402pay's own site, so it can't be phished.
- [ ] **Use a long, unique password**: A password manager can make one for you. Change it in Settings if someone may have seen it; that signs out your other devices.
- [ ] **Turn on two-step verification**: Settings, under General. Store the recovery codes somewhere other than your authenticator.
- [ ] **Keep your email account secure**: Password resets and security emails go to the address you sign in with, so protect that mailbox with two-step verification too.
- [ ] **Back up your wallet**: Keep your recovery phrase and encryption password somewhere safe and offline. 402pay can't recover either one.

## After launch

- Watch webhook deliveries in the dashboard, and resend any that failed.
- Handle [underpaid and late payments](https://developer.402pay.co/guides/underpayments.md) as they come in, so no customer is left waiting.
- Rotate a webhook secret or API key whenever someone with access leaves your team.
