When your integration works in the sandbox, you can move it to production. You do all the steps in the partner portal. The Setup guide in the portal shows which steps are complete.
On Home, click Complete your profile and answer the questions. Due diligence starts when your profile is complete. It runs at the same time as your integration work, so start it early.
Production accepts requests only from IP addresses on your allowlist.
- Open Developers → API keys & sandbox and select Production.
- In IP allowlist, add each egress address that your servers use to call Jiko. You can add an IPv4 or IPv6 address, or a CIDR range such as
203.0.113.0/24. Add a label to show what each address is, for examplePrimary egress — us-east-1.
After go-live, you cannot change the allowlist in the portal. To change it after go-live, contact your Jiko account manager. Make sure that the list includes all your regions and failover addresses.
When your profile, due diligence and allowlist are complete, Jiko opens production for your partnership. Home then shows You're live, and the production credentials unlock.
Production has its own credentials. Keys, tokens and the shared secret from the sandbox do not work in production.
- On Home, click Set up production keys. Or open API keys & sandbox and select Production.
- Make a new keypair for production and register the public key. Do not use your sandbox key again. See Authentication: Make a keypair.
- Copy the production values into the configuration of your production service:
| Value | Change from sandbox |
|---|---|
| Base URL | Use the production base URL for all API calls |
| Token endpoint | Post your assertions here, and use it as the aud claim |
| API username | Use it as the iss and sub claims |
| Shared secret | Use it to sign requests (x-jiko-signature) |
Private key and kid | Sign assertions with the production key |
Keep the production private key and shared secret in your production secrets manager. Do not put them in the same location as your sandbox credentials.
Webhook subscriptions are also separate for each environment. Register your production endpoints on the Production tab of the webhooks page.
Get a token from the production token endpoint, then make a signed request that only reads data, for example GET /api/v1/customers/. If you get an error:
| Response | Possible cause |
|---|---|
400 with aud_mismatch from the token endpoint | The assertion aud is the sandbox token endpoint |
400 with invalid_assertion from the token endpoint | The assertion is signed with the sandbox key, or iss/sub is the sandbox username |
403 from the API | The request is signed with the sandbox shared secret |
| The request is refused or does not connect | The request comes from an IP address that is not on the allowlist |
For all token endpoint errors, see Authentication: Errors from the token endpoint.