Skip to content

Testing & going live

New accounts start in sandbox: payments are processed by the gateway’s test environment and no real money moves. The API host is the same in sandbox and production (https://api.creditcore.io). Whether an account runs in sandbox or production is configured by CreditCore.

Card Number Result
Visa 4111 1111 1111 1111 Approved
Mastercard 5431 1111 1111 1111 Approved
American Express 3411 1111 1111 111 Approved
Discover 6011 6011 6011 6611 Approved

Use any future expiry date and any CVC. If you need to test declines, ask CreditCore for a sandbox product configured to decline.

  1. Sessions are created on your server, never in the browser, and the API token isn’t exposed in any page or repository.

  2. The domain passed to POST /api/session and to the SDK is your production host name.

  3. Your onMessage handler checks message.detail.code === 'OK', and not just type === 'success'.

  4. Access or fulfilment is granted from the TRANSACTION webhook (success: true), not from the checkout response.

  5. Your webhook endpoint answers 2xx quickly, handles duplicate or out-of-order events, and verifies events against the API.

  6. You tested a refund and an unsubscribe end to end.

  7. Ask CreditCore to switch your account to production.