Steps you do yourself

AI can write the code, but these steps happen in the dashboard or with the platform team. Do them alongside the code.

  1. 1

    Get the API key and secret key

    • The platform team issues them to your shop. Testnet and mainnet use different keys.
    • Put them in the server environment as PAYMENT_API_KEY and PAYMENT_SECRET_KEY. Never ship them to a browser or app.
    About the API key
  2. 2

    Set the webhook URL in the dashboard

    • Developer → API Key & Webhook. Only the shop owner can change it, with MFA turned on.
    • One URL per shop. A callback_url sent with a request is not used.
    • It must be a public HTTPS address. If a firewall sits in front, allow the platform IPs.
    • Set it before go-live: changing it later locks withdrawals for 24 hours.
    How to set the webhook
  3. 3

    Copy the webhook secret

    • Shown as "App Secret Verify" on the same screen, once. It is not the API secret key.
    • Put it in PAYMENT_WEBHOOK_SECRET. Without it you cannot tell real webhooks from fake ones.
    Webhook setup
  4. 4

    Decide on withdrawal verify Withdrawals only

    • When on, the platform asks your webhook URL to approve every withdrawal before creating it.
    • Turning it off or changing it also blocks withdrawals for 24 hours.
    Withdrawal verify
  5. 5

    Test on testnet

    • Slip / P2P: create a session, open redirect_url and start the deposit, then call acceptForTesting to complete it. Your server should receive PAYMENT_PAID.
    • Check Webhook Logs in the dashboard to see every webhook that was sent.
    Testing slip / P2P Webhook Logs
  6. 6

    Go live

    • Switch PAYMENT_BASE_URL to https://mainnet.trustsig.xyz and use the mainnet keys and webhook secret.
    • Run one small real transaction end to end before opening it to customers.
    • Make sure the reconciliation job runs: webhooks are not retried automatically. If one was missed, resend it from Webhook Logs.
    How webhooks work
Back to the AI prompt