Go live
1. Verify your business#
Live keys and live operations need a verified business. Start verification in the dashboard, or with POST /account/verification (scope kyc:write), which returns a verificationUrl to send the business owner to. Check progress with GET /account (account:read or kyc:read).
You will be asked for business documents and details of the people who own or control the business.
2. Set up your settlement account#
Add the bank account where you want to be paid on the Settlement account page of the dashboard. Only the business owner or an admin can do this. API payouts go only to this saved account: see Payouts.
3. Accept the merchant agreement#
The owner or an admin accepts the Merchant Services Agreement in the dashboard and signs it electronically.
4. Create a live key#
Create an olp_live_ key with only the scopes the integration needs. Add an IP allowlist and an expiry if your servers have fixed addresses. Keep it in your secret store.
5. Point your webhook at production#
Register your production HTTPS URL with POST /webhooks using the live key. Save the signing secret (shown once).
6. Pre-launch checklist#
- Sandbox test plan passed, including retries and duplicates
- Every money-moving request sends an idempotency key
- Webhook signatures are verified and old timestamps are rejected
- Your handler is safe to run twice for the same event
- You back off on
429and5xx - Live keys are not in source control, logs or client-side code
- You log
X-Request-Idfor failed calls - Someone is watching the delivery log for failed webhooks
Limits at launch#
Payouts and refunds above a per-currency threshold return 202 and wait for a second person in your business to approve them. This is by design and applies to API keys too.