Go live
What to check before you point production traffic at us.
The API shape doesn't change
# Sandbox
DATTAREMIT_SECRET_KEY=sk_test_...
# Live — same API, same request shapes, different key
DATTAREMIT_SECRET_KEY=sk_live_...Checklist
Your organization is active
Live keys can only be created once we've approved your organization, and a live key stops working the moment an organization is suspended. Check the status badge in Settings.
Your IP allowlist is populated
This one bites people. An empty allowlist means unrestricted for test keys, but a live key with an empty allowlist is refused outright with
ip_allowlist_required— we treat it as a misconfiguration rather than as permission. Add every egress address your servers use, including NAT gateways and any failover region.Secrets live in a secret manager
Never in source control, never in a client bundle, never in a log line. If a key may have leaked, rotate it — rotation issues a replacement and revokes the old key immediately, with no grace period.
You branch on error codes, not messages
codeis the stable contract.titleanddetailare human-facing and can be reworded at any time.You've re-tested against live
Sandbox is not a timing simulator. It settles almost instantly, whereas real ACH funding takes about a business day. Run a small real transaction before pointing production traffic at us.
Verify the swap
Make a read-only call with the live key — listing customers is safe. A 200 from the allowlisted host confirms the swap.
curl https://bank.dattaremit.com/api/customers \
-H "Authorization: Bearer sk_live_YOUR_KEY"If you get a 403 whose error_message names your IP, that address is the one to add to the allowlist.