Testing & going live
Sandbox
Section titled “Sandbox”New accounts start in sandbox: payments are processed by the gateway’s test environment and no real money moves. The API host is the same in sandbox and production (https://api.creditcore.io). Whether an account runs in sandbox or production is configured by CreditCore.
Test cards
Section titled “Test cards”| Card | Number | Result |
|---|---|---|
| Visa | 4111 1111 1111 1111 |
Approved |
| Mastercard | 5431 1111 1111 1111 |
Approved |
| American Express | 3411 1111 1111 111 |
Approved |
| Discover | 6011 6011 6011 6611 |
Approved |
Use any future expiry date and any CVC. If you need to test declines, ask CreditCore for a sandbox product configured to decline.
Go-live checklist
Section titled “Go-live checklist”-
Sessions are created on your server, never in the browser, and the API token isn’t exposed in any page or repository.
-
The
domainpassed toPOST /api/sessionand to the SDK is your production host name. -
Your
onMessagehandler checksmessage.detail.code === 'OK', and not justtype === 'success'. -
Access or fulfilment is granted from the
TRANSACTIONwebhook (success: true), not from the checkout response. -
Your webhook endpoint answers
2xxquickly, handles duplicate or out-of-order events, and verifies events against the API. -
You tested a refund and an unsubscribe end to end.
-
Ask CreditCore to switch your account to production.