Sandbox live

Production onboarding

Integrate against sandbox first. Production is a cutover, not a second copy of the sandbox key.

StudentPay coordinates Production enablement and certification. Do not create an unsolicited Production enrolment.


What changes

Sandbox Production
API host https://sandbox-api.studentpay.co.nz https://api.studentpay.co.nz
Provider API key Sandbox key A separate Production key
Salesforce PIC Sandbox PIC, Environment = Sandbox Production PIC, Environment = Production, Active, API-enabled
GoCardless GoCardless sandbox (test bank details) Live BECS NZ
Student data Fictional only Real enrolments only
Outbound webhooks Optional; often not configured Delivered only if StudentPay has configured a Production destination

Never reuse sandbox credentials, tokens, or webhook secrets in Production.


Provider checklist (before live traffic)

StudentPay and the provider confirm:

  1. A Production provider_code and server-side Production API key
  2. Production PIC is Active, API-enabled, Environment = Production, Account linked
  3. GET https://api.studentpay.co.nz/v1/environment returns environment=production and ready_for_api_calls=true
  4. The provider backend uses the Production base URL only
  5. The payer is sent to the Production setup_url (live GoCardless BECS NZ)
  6. Confirm still uses setup_complete, not Authorised
  7. Webhook destination, if required for go-live, is configured by StudentPay (this is not automatic)

Allowlist Production enrolment origins with StudentPay if you open or embed hosted setup from your domain.


Certification

Hosted Enrolment Checkout has already completed NZ production certification.

Enrolment Integration Production certification is a StudentPay-run exercise against your provider-owned client once sandbox sign-off is complete.

Do not:

  • reuse a sandbox key on api.studentpay.co.nz
  • mint your own Production “canary” enrolments without StudentPay
  • treat a later-cancelled test mandate as a reason to enrol again

If you need a Production checkout investigated, send StudentPay the checkout_id, provider_order_id, and request_id — not bank details.


After go-live

  • Keep API keys on the server
  • Retry create/confirm with the same provider_order_id
  • Poll GET; do not block confirm on mandate active
  • Treat webhook event_id as idempotent if webhooks are enabled for you

Contact partners@studentpay.com.au to start Production onboarding.