Skip to main content
After you pass sandbox acceptance and Waffo provisions your production account, complete the account, access, key, and notification setup below. Start processing normal traffic only after you verify your first production order.

Prerequisites

  • You passed the Waffo integration acceptance criteria
  • You submitted the results to the Waffo technical integration group and received confirmation
  • Waffo provisioned the production account and sent an activation email to the Super Admin

Enable the production environment

1

Activate the production account

The Super Admin must open the activation link within 24 hours of receiving the email. If the link expires, contact Waffo technical support to request a new email.
2

Add the developer

The Super Admin signs in to Waffo Dashboard, opens Settings → Operator, adds the project developer’s email address, and assigns the Dev role.Create a separate account for every team member who needs Dashboard access, and grant the minimum role required for their work. See Account activation and team roles.
3

Configure the production public key

The developer opens Settings → Integration, uploads the production merchant public key, completes the signature challenge, and submits it for review. Production API requests can be verified after the key becomes Active.Do not reuse sandbox-generated keys in production. See Configure the merchant public key.
4

Configure notification URLs

Payment notifications continue to use the notifyUrl supplied when each order is created. Configure the global refundNotifyUrl and chargebackNotifyUrl in Dashboard when your integration needs them.See Configure refund and Chargeback notification URLs.
5

Switch to production credentials

  • If you use a Waffo SDK or AI integration tool, change Environment.SANDBOX to Environment.PRODUCTION
  • If you call the API directly, use the production API domain
  • Use the production API Key, merchant private key, and Waffo public key
  • Store the RSA private key in a server-side key management system; never commit it or send it to Waffo
6

Create a production order

Create one low-value real order with the production credentials, then verify:
  • The create-order API succeeds
  • The customer can open Checkout and complete payment
  • notifyUrl receives the final payment status and signature verification succeeds
  • The order inquiry result matches the Webhook result
  • Logs and alerts help you investigate order creation, inquiry, and Webhook handling
You can start processing normal traffic after every check passes.

Security and infrastructure checks

  • All API traffic uses TLS 1.2+
  • Logs do not contain full keys or sensitive payment information
  • The recommended API timeout is 15 seconds and is not lower than 8 seconds
  • The recommended DNS cache duration is 60 seconds; do not pin Waffo IP addresses long term
  • The HTTP Keep-Alive idle timeout is 60 seconds; configure your client connection pool to close idle connections before 60 seconds
  • If your servers are in mainland China, you evaluated network latency to the Waffo API

App checks, if applicable

  • The App WebView can open external Apps and browser pages
  • The App WebView supports downloads, copy, and long-press save
  • Query parameters remain intact when URLs pass between the native App and WebView
  • You reviewed PayPay, Google Pay, Apple Pay, JKOPAY, and other limitations in Payment method integration notes

Post-provisioning message template