Operate
Sandbox & testing
Prove every path in sandbox before you ask for a go-live review. Most reviews stall on the unhappy paths, so start there.
How sandbox behaves
- Sandbox is a separate deployment at
https://api.sandbox.paylumia.com(checkouthttps://pay.sandbox.paylumia.com) withplm_test_credentials, its own webhook URL and secret. It is mock only — no operator charges a real line. - It runs the same API, the same checkout pages and the same events as production.
- Test lines and the way to trigger declines are provided by the Hadruvo integration team when your application is set up. Ask them for the current list.
After sandbox: go-live
When the cases below pass in sandbox, ask for a go-live review. Production uses live Orange with
plm_live_ credentials. See environments & go-live.Test cases to pass
| Case | What you do | What must happen |
|---|---|---|
| Success | Complete checkout with a test line | Access granted from payment.succeeded, not from the return URL |
| Decline | Use a line set up to fail | payment.failed received; the user can start a new payment |
| Abandoned | Open checkout, then leave | Status becomes EXPIRED after expiresAt; nothing granted |
| Cancel | Call POST …/cancel while REQUIRES_ACTION | Status CANCELED; nothing granted |
| Retry | Replay the same create with the same Idempotency-Key | Same payment returned; no second session |
| Duplicate event | Deliver the same webhook twice | Second delivery is a no-op |
| Bad signature | Send an event with a wrong signature | Rejected with 400; nothing processed |
| Token expiry | Let a token expire mid-session | Client fetches a new one transparently |
| Subscription end | Cancel with PERIOD_END, then NOW | Access kept until cancelAt, then removed on entitlement.revoked |
Testing sessions
When your sandbox integration is ready, book a testing session with the integration team. Send your test report (the table above, with results) before the session so time is spent on fixes, not on setup.
Let your agent do the report
The PayLumia skill turns this list into a pass / fix report for your codebase.