Skip to content

Sandbox

Sandbox is a complete second account that shares your login: its own settings, webhook endpoints, sessions, contracts, and API keys. It opens as soon as your account is approved.

Getting sandbox access

  1. Business details. Fill them in on the onboarding wizard.
  2. Review. We look at the account. This usually takes one business day, and we email you when it is done.
  3. Sandbox opens. Build the whole integration here.
  4. FFL licence. Upload it once you are approved. Verifying it is what opens live; sandbox stays open throughout.

Approval is what both halves of the account wait on, so there is no state in which live works and sandbox does not.

Sandbox and live, side by side

Sandbox Live
Key prefix sk_test_ sk_live_
Needed to issue a key An approved account and a verified email. The above, plus a verified FFL licence.
Payments Simulated. Nothing is charged. Real money.
Data Sandbox sessions and contracts only. Live sessions and contracts only.
Settings Its own copy. Its own copy.
Webhook endpoints Registered per mode. Registered per mode.
livemode in webhooks false true

Use the sk_test_ key and you are in sandbox. Once the account is approved there is nothing further to opt into: both keys are issued from the same page.

What "simulated" means

Every sandbox charge is answered by a simulation that always succeeds, stamped with a sim_ reference rather than a charge id — a sandbox payment cannot be made to fail. Where the checkout collects a card, use a test card.

Previewing the checkout page

Preview checkout in the merchant dashboard opens a workbench at /merchant/preview: enter an order total, press Pay with ShotPay, and the page a customer would see opens beside the form. Completing or cancelling follows the redirect to a stand-in for your return_url, which shows both halves of the handshake side by side.

The preview is always sandbox, so it can never open a live customer session.

Driving a full plan

  1. Open a session with your sk_test_ key, as in Quick Start.
  2. Follow checkout_url and confirm the plan. contract.activated then session.completed are delivered.
  3. Pay the remaining installments from the same page — contract.paid for each, contract.completed when the last one settles.

Going live

  • The account is approved and the FFL licence is verified.
  • Layaway is enabled in the live settings — sandbox settings do not carry over.
  • A live webhook endpoint is registered and subscribed, with its signing secret deployed.
  • GET /v1/ping with the live key returns the right merchant and layaway.available is true.

Then replace sk_test_ with sk_live_ in your configuration. Nothing else changes.