> ## Documentation Index
> Fetch the complete documentation index at: https://waffo.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure the merchant public key

> Upload a production merchant public key in Waffo Dashboard, complete the signature challenge, and track its review status.

Waffo uses two-way RSA signing to protect production API traffic. Upload your merchant public key in Waffo Dashboard (Merchant Portal), then prove that you control the matching private key.

| Key | Holder | Purpose |
| - | - | - |
| Merchant private key | Merchant | Signs API requests and Webhook responses |
| Merchant public key | Waffo | Verifies merchant signatures |
| Waffo private key | Waffo | Signs API responses and Webhooks |
| Waffo public key | Merchant | Verifies Waffo signatures |

## Prerequisites

* You activated the production account.
* Your role is **Super Admin**, **Admin**, or **Dev**.
* You generated an RSA key pair used only for production.
* You can securely access the merchant private key. Never upload the private key to Dashboard or send it to Waffo.

## Public-key requirements

| Item | Requirement |
| - | - |
| Key size | 2048 bits |
| Signature algorithm | `SHA256WithRSA` |
| Public-key format | Single-line X.509/SPKI Base64 without PEM headers or footers |
| Public-key string length | 392 characters |

## Generate the production key pair

```bash theme={null}
openssl genpkey -algorithm RSA \
  -pkeyopt rsa_keygen_bits:2048 \
  -out merchant_private_key.pem

openssl pkcs8 -topk8 -inform PEM -outform PEM -nocrypt \
  -in merchant_private_key.pem \
  | grep -v '^-----' \
  | tr -d '\n' > merchant_private_key.base64

openssl rsa -in merchant_private_key.pem -pubout \
  | grep -v '^-----' \
  | tr -d '\n' > merchant_public_key.base64
```

Upload the contents of `merchant_public_key.base64`. Store `merchant_private_key.pem` and `merchant_private_key.base64` in your server-side key management system.

## Configure the key

<Steps>
  <Step title="Sign in to Dashboard">
    Open [Waffo Dashboard](https://dashboard.waffo.com/auth/login), then go to **Settings → Integration**.
  </Step>

  <Step title="Start configuration">
    In **Merchant Sign Configuration Details**, click **Configure** and set **API Operation Type** to **Payin**.
  </Step>

  <Step title="Upload the public key">
    Paste the complete merchant public key into the public-key field.
  </Step>

  <Step title="Generate the verification signature">
    Copy the verification string generated for the current Merchant. Sign it with the matching merchant private key using `SHA256WithRSA`.

    ```bash theme={null}
    echo -n "WAFFO_VERIFY_XXXXXXXXXX" | \
      openssl dgst -sha256 -sign merchant_private_key.pem | \
      base64 | tr -d '\n'
    ```

    Replace `WAFFO_VERIFY_XXXXXXXXXX` with the complete string shown in Dashboard.
  </Step>

  <Step title="Submit for review">
    Paste the single-line Base64 signature into the verification field. Click **Confirm**, then click **Confirm** again in the confirmation dialog.
  </Step>
</Steps>

## Check the review status

After submission, the key first appears as **Pending**. Waffo normally completes the review within one business day and sends the result by email.

| Status | Meaning |
| - | - |
| **Pending** | Submitted and waiting for Waffo review |
| **Active** | Activated and available for production API requests |
| **Rejected** | Not approved; review the reason and submit again |

<Warning>
  Do not send production transactions with the new key before its status becomes **Active**.
</Warning>

## Add or rotate a key

The existing **Active** key remains valid while Waffo reviews a new key. Switch the production private key only after the new public key becomes **Active**.

If the new public key is identical to an existing **Active** key, Dashboard returns `public key already exists`. Generate a new key pair before submitting again.

## Resubmit a rejected key

1. Open **Settings → Integration**.
2. Find the version under **Historical Versions** and read its **Reject Reason**.
3. Regenerate or correct the key based on that reason.
4. Repeat public-key configuration and signature verification.

Each submission creates a new history entry and does not affect an existing **Active** key.

## Common errors

| Error | Cause | Resolution |
| - | - | - |
| `signature verification failed` | The private key does not match the public key, or the signature is incomplete or contains spaces or line breaks | Confirm the key pair and generate a complete single-line Base64 signature |
| `public key count exceeds limit` | The **API Operation Type** has reached its **Active** key limit | Contact Waffo technical support to deactivate an unused key |
| `public key record not found` | The target public-key record does not exist | Refresh the history; if the problem continues, contact support with a screenshot |
| `public key already exists` | The submitted key matches an existing **Active** key | Generate a completely new public and private key pair |

Next: Return to [Production go-live](/docs/en/developer-docs/getting-started/go-live) and verify a production order.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.