Go live

What to check before you point production traffic at us.

The API shape doesn't change

Going live is a credential swap, not a migration. Same endpoints, same request and response shapes — only the key prefix differs.
.env
# Sandbox
DATTAREMIT_SECRET_KEY=sk_test_...

# Live — same API, same request shapes, different key
DATTAREMIT_SECRET_KEY=sk_live_...

Checklist

  1. Your organization is active

    Live keys can only be created once we've approved your organization, and a live key stops working the moment an organization is suspended. Check the status badge in Settings.

  2. Your IP allowlist is populated

    This one bites people. An empty allowlist means unrestricted for test keys, but a live key with an empty allowlist is refused outright with ip_allowlist_required — we treat it as a misconfiguration rather than as permission. Add every egress address your servers use, including NAT gateways and any failover region.

  3. Secrets live in a secret manager

    Never in source control, never in a client bundle, never in a log line. If a key may have leaked, rotate it — rotation issues a replacement and revokes the old key immediately, with no grace period.

  4. You branch on error codes, not messages

    code is the stable contract. title and detail are human-facing and can be reworded at any time.

  5. You've re-tested against live

    Sandbox is not a timing simulator. It settles almost instantly, whereas real ACH funding takes about a business day. Run a small real transaction before pointing production traffic at us.

Verify the swap

Make a read-only call with the live key — listing customers is safe. A 200 from the allowlisted host confirms the swap.

curl https://bank.dattaremit.com/api/customers \
  -H "Authorization: Bearer sk_live_YOUR_KEY"

If you get a 403 whose error_message names your IP, that address is the one to add to the allowlist.