Orientation
Sandbox & credentials
Once your organization is onboarded you can make your first API call. This page covers what you need and how sandbox differs from production.
What you need
- Sandbox access: an isolated environment with its own users and contracts. Nothing in sandbox touches real money.
- An API client: a
client_idand aclient_secret. Create it in the Waffy business portal under Settings, API clients. The secret is shown only once. Each environment has its own client. Once you are signed in to this site, the dashboard lists your clients and gives you a Postman environment for each. - Your organization admin's login: the same username and password as in the business portal. It is used to get the client admin token for contracts, settlement, balance and withdrawals.
- A webhook signing secret: used to HMAC-verify inbound webhooks so you can trust the payload came from Waffy.
- A pre-configured payment-method set: the subset of methods enabled on your org at onboarding (Mada, Visa, Mastercard, Apple Pay, STC Pay, Tabby, Tamara, Neo, manual bank transfer). The hosted checkout displays only the ones that are on for you.
Three kinds of token
Your client gives you an
org token, and your admin login gives you a client admin token. A third value, the payment ticket, is requested by your backend for one buyer and one payment, right before the checkout redirect. See Authentication.If you don't have these yet, you're not onboarded yet. Reach out to your Waffy account manager to get started.
Environments
| Aspect | Sandbox (dev) | Staging | Production |
|---|---|---|---|
| Waffy ID (tokens) | https://id-dev.waffyapp.com | https://id-stg.waffyapp.com | https://id.waffyapp.com |
| Business API | https://dev-api.waffyapp.com | https://api-stg.waffyapp.com | https://api.waffyapp.com |
| Authentication service | https://dev-auth.waffyapp.com | https://auth-stg.waffyapp.com | https://auth.waffyapp.com |
| Checkout | https://external-dev.waffyapp.com | https://external-stg.waffyapp.com | https://external.waffyapp.com |
| Webhook URL | Configured by Waffy at provisioning. Contact your account manager to change. | Same mechanism. | Confirmed with Waffy before go-live. |
| Payments | Simulated. | Simulated or real. | Real. Real money moves. |
| Webhooks | Fire on every state change, same payload shape. | Same. | Same. |
| Approval required | No. | No. | Yes: compliance review and Waffy’s readiness checklist. |
Use the same code across all environments
The only thing that changes between environments is the base URLs and the credential set. Your request shapes, response schemas, and webhook payloads are identical. Keep the URLs in configuration, named like the Postman environment variables:
id_base_url, api_base_url, auth_base_url and checkout_base_url. The Postman collection already works this way.