The verdict in three sentences
Moving from sandbox to live without breakage comes down to a verification discipline: separate keys, webhooks re-tested in production, validated merchant KYC, and a real 1 FCFA payment made before opening. Most launch incidents come from test keys left in production or webhooks still pointing at the staging URL. This 12-point checklist turns a risky go-live into a half-day operation.
The 12 pre-launch control points
Each point below must be checked before opening payments to real customers.
| # | Control point | Expected status |
|---|---|---|
| 1 | Merchant account activated (live mode) | done |
| 2 | Full KYC (registration, director ID) | done |
| 3 | Live API keys separate from test keys | rotated |
| 4 | Webhook URL pointed at production | tested |
| 5 | HMAC signature verified in live | active |
| 6 | Real 1 FCFA payment tested | passed |
| 7 | Test refund performed | passed |
| 8 | Database idempotency validated | active |
| 9 | Live limits known (e.g. 3M FCFA/day) | configured |
| 10 | Success/failure return page | tested |
| 11 | Transaction logging | active |
| 12 | Daily reconciliation scheduled | active |
A single unchecked point — typically #3 or #4 — is enough to silently fail real payments.
Delays and limits: what live changes
Going to production changes activation delays and imposes limits absent from the sandbox. Here are 2026 orders of magnitude.
| Item | Sandbox | Live |
|---|---|---|
| Account activation | instant | 2-10 business days |
| KYC required | no | registration + ID |
| Daily limit | unlimited | ~3,000,000 FCFA/day (default) |
| Per-transaction limit | unlimited | 500,000-2,000,000 FCFA |
| Key rotation | free | recommended each deploy |
| Test amount | fake | real (1 FCFA) |
Default limits are raised on request with the aggregator, often after a few weeks of clean transaction history.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Moussa, who runs an online grocery in Dakar, launches his Wave payments on a Friday evening. He ticked 11 of 12 points but missed #4: his webhook still points to staging. As a result, 17 paid orders over the weekend stay in "pending" status, or 255,000 FCFA of unfulfilled sales at a 15,000 FCFA average basket. A Monday reconciliation recovers everything, but 6 customers had already contacted support. The checklist would have prevented the incident in five minutes.
FAQ
How long does merchant account activation take? From 2 to 10 business days depending on the aggregator and the completeness of your KYC file (business registration, director's ID).
Why test a real 1 FCFA payment? Because the sandbox never perfectly reproduces live: a minimal real payment validates keys, webhook and settlement end to end.
Must I change API keys on every deploy? Not mandatory, but regular rotation limits the impact of a leak. Never leave a test key active in production.
What live limits should I expect? Often 3,000,000 FCFA per day and 500,000 to 2,000,000 FCFA per transaction at first, raisable on request after a few weeks of history.
What if payments stay pending after launch? Run an immediate reconciliation against the status API, fix the webhook URL, then replay the missing notifications to fulfil the orders.
Let's talk about your project. We drive your go-live with this 12-point checklist, with no lost payment. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

