Get started
Environments & go-live
One application, two deployments. Build and prove flows in sandbox, then switch credentials once production is approved.
Sandbox and production
| Sandbox | Production | |
|---|---|---|
| Client ID | plm_test_… | plm_live_… |
| API | https://api.sandbox.paylumia.com | https://api.paylumia.com |
| Checkout | https://pay.sandbox.paylumia.com | https://pay.paylumia.com |
| Operator | Mock only | Live Orange |
| Money | None | Real operator charges |
| Status at creation | Active | Not live until approved |
| Webhook URL & secret | Its own | Its own |
Sandbox is mock only
Sandbox never charges a real line. Use it to prove create, checkout, webhooks and cancel before you ask for production.
Both deployments share the application’s offers and consent policy. Credentials never cross: a sandbox token cannot reach production.
Path to production
- Build and prove flows in sandbox (
plm_test_, mock). - Pass the go-live checklist, then ask for production approval (
plm_live_).
Go-live checklist
- Every create sends a unique, stable
Idempotency-Key(your order or attempt id). - Access is granted from a verified webhook or a server-side read, never from the return URL alone.
- Your webhook handler verifies signatures, answers 2xx quickly and tolerates the same event twice.
entitlement.revokedandsubscription.*events remove access when a subscription ends.- Your pages show the offer, its price and period before sending the customer to checkout, and a way to cancel.
- Your sandbox and production webhook URLs are set and reachable over HTTPS.
Approval

When your sandbox integration passes the checklist, ask your Hadruvo contact for a go-live review. Once approved, the production deployment becomes active and its credentials are issued. The secret is shown once.
Not integrating yet?
Request sandbox access and we’ll set up your application and first offers with you.