Skip to main content
Waffo uses two-way RSA signing to protect production API traffic. Upload your merchant public key in Waffo Dashboard (Merchant Portal), then prove that you control the matching private key.

Prerequisites

  • You activated the production account.
  • Your role is Super Admin, Admin, or Dev.
  • You generated an RSA key pair used only for production.
  • You can securely access the merchant private key. Never upload the private key to Dashboard or send it to Waffo.

Public-key requirements

Generate the production key pair

Upload the contents of merchant_public_key.base64. Store merchant_private_key.pem and merchant_private_key.base64 in your server-side key management system.

Configure the key

1

Sign in to Dashboard

Open Waffo Dashboard, then go to Settings → Integration.
2

Start configuration

In Merchant Sign Configuration Details, click Configure and set API Operation Type to Payin.
3

Upload the public key

Paste the complete merchant public key into the public-key field.
4

Generate the verification signature

Copy the verification string generated for the current Merchant. Sign it with the matching merchant private key using SHA256WithRSA.
Replace WAFFO_VERIFY_XXXXXXXXXX with the complete string shown in Dashboard.
5

Submit for review

Paste the single-line Base64 signature into the verification field. Click Confirm, then click Confirm again in the confirmation dialog.

Check the review status

After submission, the key first appears as Pending. Waffo normally completes the review within one business day and sends the result by email.
Do not send production transactions with the new key before its status becomes Active.

Add or rotate a key

The existing Active key remains valid while Waffo reviews a new key. Switch the production private key only after the new public key becomes Active. If the new public key is identical to an existing Active key, Dashboard returns public key already exists. Generate a new key pair before submitting again.

Resubmit a rejected key

  1. Open Settings → Integration.
  2. Find the version under Historical Versions and read its Reject Reason.
  3. Regenerate or correct the key based on that reason.
  4. Repeat public-key configuration and signature verification.
Each submission creates a new history entry and does not affect an existing Active key.

Common errors

Next: Return to Production go-live and verify a production order.