Skip to content

Onboarding

Collect the merchant’s legal identity, currency, timezone, support contact, and fiscal configuration before enabling payments. The merchant remains responsible for products, delivery, cancellations, and refunds. Create separate test and production credentials; API_ORIGIN, TIMBRO_PAYMENTS_SECRET_KEY, and webhook secrets remain server-side.

Provider activation, wallets, and fiscal issuance are confirmed per account, environment, and domain. An environment variable, loaded screen, or HTTP 200 is not qualified capability evidence.

  • Exact test account and merchant identified.
  • Checkout URL and API origin recorded.
  • Signed webhook consumer with retries and inquiry recovery.
  • Paid test and receipt delivery proven in the same composition.

Before opening the flow, verify the API origin and merchant are the intended pair and run one test purchase with a persisted idempotency key. Retain Request-Id, the Payment identifier, environment, and fiscal outcome for support; redact them before telemetry.