E-commerce11 min read

Payment go-live: sandbox to production checklist in 2026

Mohamed Bah·Fondateur, Kolonell
August 26, 2026
Share:
Payment go-live: sandbox to production checklist in 2026

Payment go-live: sandbox to production checklist in 2026

E-commerce

The verdict in three sentences

Moving from sandbox to live without breakage comes down to a verification discipline: separate keys, webhooks re-tested in production, validated merchant KYC, and a real 1 FCFA payment made before opening. Most launch incidents come from test keys left in production or webhooks still pointing at the staging URL. This 12-point checklist turns a risky go-live into a half-day operation.

The 12 pre-launch control points

Each point below must be checked before opening payments to real customers.

#Control pointExpected status
1Merchant account activated (live mode)done
2Full KYC (registration, director ID)done
3Live API keys separate from test keysrotated
4Webhook URL pointed at productiontested
5HMAC signature verified in liveactive
6Real 1 FCFA payment testedpassed
7Test refund performedpassed
8Database idempotency validatedactive
9Live limits known (e.g. 3M FCFA/day)configured
10Success/failure return pagetested
11Transaction loggingactive
12Daily reconciliation scheduledactive

A single unchecked point — typically #3 or #4 — is enough to silently fail real payments.

Delays and limits: what live changes

Going to production changes activation delays and imposes limits absent from the sandbox. Here are 2026 orders of magnitude.

ItemSandboxLive
Account activationinstant2-10 business days
KYC requirednoregistration + ID
Daily limitunlimited~3,000,000 FCFA/day (default)
Per-transaction limitunlimited500,000-2,000,000 FCFA
Key rotationfreerecommended each deploy
Test amountfakereal (1 FCFA)

Default limits are raised on request with the aggregator, often after a few weeks of clean transaction history.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Mini case study

Moussa, who runs an online grocery in Dakar, launches his Wave payments on a Friday evening. He ticked 11 of 12 points but missed #4: his webhook still points to staging. As a result, 17 paid orders over the weekend stay in "pending" status, or 255,000 FCFA of unfulfilled sales at a 15,000 FCFA average basket. A Monday reconciliation recovers everything, but 6 customers had already contacted support. The checklist would have prevented the incident in five minutes.

FAQ

How long does merchant account activation take? From 2 to 10 business days depending on the aggregator and the completeness of your KYC file (business registration, director's ID).

Why test a real 1 FCFA payment? Because the sandbox never perfectly reproduces live: a minimal real payment validates keys, webhook and settlement end to end.

Must I change API keys on every deploy? Not mandatory, but regular rotation limits the impact of a leak. Never leave a test key active in production.

What live limits should I expect? Often 3,000,000 FCFA per day and 500,000 to 2,000,000 FCFA per transaction at first, raisable on request after a few weeks of history.

What if payments stay pending after launch? Run an immediate reconciliation against the status API, fix the webhook URL, then replay the missing notifications to fulfil the orders.

Let's talk about your project. We drive your go-live with this 12-point checklist, with no lost payment. WhatsApp +221 77 596 93 33.

Tags:#go-live#sandbox#checklist#merchant kyc#api keys#production#integration#payment
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.