Steps you do yourself
AI can write the code, but these steps happen in the dashboard or with the platform team. Do them alongside the code.
- 1
Get the API key and secret key
- The platform team issues them to your shop. Testnet and mainnet use different keys.
- Put them in the server environment as
PAYMENT_API_KEYandPAYMENT_SECRET_KEY. Never ship them to a browser or app.
- 2
Set the webhook URL in the dashboard
- Developer → API Key & Webhook. Only the shop owner can change it, with MFA turned on.
- One URL per shop. A
callback_urlsent with a request is not used. - It must be a public HTTPS address. If a firewall sits in front, allow the platform IPs.
- Set it before go-live: changing it later locks withdrawals for 24 hours.
- 3
Copy the webhook secret
- Shown as "App Secret Verify" on the same screen, once. It is not the API secret key.
- Put it in
PAYMENT_WEBHOOK_SECRET. Without it you cannot tell real webhooks from fake ones.
- 4
Decide on withdrawal verify Withdrawals only
- When on, the platform asks your webhook URL to approve every withdrawal before creating it.
- Turning it off or changing it also blocks withdrawals for 24 hours.
- 5
Test on testnet
- Slip / P2P: create a session, open
redirect_urland start the deposit, then call acceptForTesting to complete it. Your server should receivePAYMENT_PAID. - Check Webhook Logs in the dashboard to see every webhook that was sent.
- Slip / P2P: create a session, open
- 6
Go live
- Switch
PAYMENT_BASE_URLto https://mainnet.trustsig.xyz and use the mainnet keys and webhook secret. - Run one small real transaction end to end before opening it to customers.
- Make sure the reconciliation job runs: webhooks are not retried automatically. If one was missed, resend it from Webhook Logs.
- Switch
