Sandbox
Sandbox is a complete second account that shares your login: its own settings, webhook endpoints, sessions, contracts, and API keys. It opens as soon as your account is approved.
Getting sandbox access
- Business details. Fill them in on the onboarding wizard.
- Review. We look at the account. This usually takes one business day, and we email you when it is done.
- Sandbox opens. Build the whole integration here.
- FFL licence. Upload it once you are approved. Verifying it is what opens live; sandbox stays open throughout.
Approval is what both halves of the account wait on, so there is no state in which live works and sandbox does not.
Sandbox and live, side by side
| Sandbox | Live | |
|---|---|---|
| Key prefix | sk_test_ |
sk_live_ |
| Needed to issue a key | An approved account and a verified email. | The above, plus a verified FFL licence. |
| Payments | Simulated. Nothing is charged. | Real money. |
| Data | Sandbox sessions and contracts only. | Live sessions and contracts only. |
| Settings | Its own copy. | Its own copy. |
| Webhook endpoints | Registered per mode. | Registered per mode. |
livemode in webhooks |
false |
true |
Use the sk_test_ key and you are in sandbox. Once the account is approved
there is nothing further to opt into: both keys are issued from the same page.
What "simulated" means
Every sandbox charge is answered by a simulation that always succeeds, stamped
with a sim_ reference rather than a charge id — a sandbox payment cannot be
made to fail. Where the checkout collects a card, use a
test card.
Previewing the checkout page
Preview checkout in the merchant dashboard opens a workbench at
/merchant/preview: enter an order total, press Pay with ShotPay, and the
page a customer would see opens beside the form. Completing or cancelling
follows the redirect to a stand-in for your return_url, which shows both
halves of the handshake side by side.
The preview is always sandbox, so it can never open a live customer session.
Driving a full plan
- Open a session with your
sk_test_key, as in Quick Start. - Follow
checkout_urland confirm the plan.contract.activatedthensession.completedare delivered. - Pay the remaining installments from the same page —
contract.paidfor each,contract.completedwhen the last one settles.
Going live
- The account is approved and the FFL licence is verified.
- Layaway is enabled in the live settings — sandbox settings do not carry over.
- A live webhook endpoint is registered and subscribed, with its signing secret deployed.
-
GET /v1/pingwith the live key returns the right merchant andlayaway.availableistrue.
Then replace sk_test_ with sk_live_ in your configuration. Nothing else
changes.