Skip to content

Going live

When your integration works in the sandbox, you can move it to production. You do all the steps in the partner portal. The Setup guide in the portal shows which steps are complete.

Before go-live

1. Complete your partner profile and due diligence

On Home, click Complete your profile and answer the questions. Due diligence starts when your profile is complete. It runs at the same time as your integration work, so start it early.

2. Add your IP addresses to the allowlist

Production accepts requests only from IP addresses on your allowlist.

  1. Open Developers → API keys & sandbox and select Production.
  2. In IP allowlist, add each egress address that your servers use to call Jiko. You can add an IPv4 or IPv6 address, or a CIDR range such as 203.0.113.0/24. Add a label to show what each address is, for example Primary egress — us-east-1.
Add all addresses before go-live

After go-live, you cannot change the allowlist in the portal. To change it after go-live, contact your Jiko account manager. Make sure that the list includes all your regions and failover addresses.

3. Wait for go-live

When your profile, due diligence and allowlist are complete, Jiko opens production for your partnership. Home then shows You're live, and the production credentials unlock.

After go-live

4. Get your production credentials

Production has its own credentials. Keys, tokens and the shared secret from the sandbox do not work in production.

  1. On Home, click Set up production keys. Or open API keys & sandbox and select Production.
  2. Make a new keypair for production and register the public key. Do not use your sandbox key again. See Authentication: Make a keypair.
  3. Copy the production values into the configuration of your production service:
ValueChange from sandbox
Base URLUse the production base URL for all API calls
Token endpointPost your assertions here, and use it as the aud claim
API usernameUse it as the iss and sub claims
Shared secretUse it to sign requests (x-jiko-signature)
Private key and kidSign assertions with the production key

Keep the production private key and shared secret in your production secrets manager. Do not put them in the same location as your sandbox credentials.

5. Register your webhooks

Webhook subscriptions are also separate for each environment. Register your production endpoints on the Production tab of the webhooks page.

6. Make a test call

Get a token from the production token endpoint, then make a signed request that only reads data, for example GET /api/v1/customers/. If you get an error:

ResponsePossible cause
400 with aud_mismatch from the token endpointThe assertion aud is the sandbox token endpoint
400 with invalid_assertion from the token endpointThe assertion is signed with the sandbox key, or iss/sub is the sandbox username
403 from the APIThe request is signed with the sandbox shared secret
The request is refused or does not connectThe request comes from an IP address that is not on the allowlist

For all token endpoint errors, see Authentication: Errors from the token endpoint.