Orientation

Sandbox & credentials

Once your organization is onboarded you can make your first API call. This page covers what you need and how sandbox differs from production.

What you need

  • Sandbox access: an isolated environment with its own users and contracts. Nothing in sandbox touches real money.
  • An API client: a client_id and a client_secret. Create it in the Waffy business portal under Settings, API clients. The secret is shown only once. Each environment has its own client. Once you are signed in to this site, the dashboard lists your clients and gives you a Postman environment for each.
  • Your organization admin's login: the same username and password as in the business portal. It is used to get the client admin token for contracts, settlement, balance and withdrawals.
  • A webhook signing secret: used to HMAC-verify inbound webhooks so you can trust the payload came from Waffy.
  • A pre-configured payment-method set: the subset of methods enabled on your org at onboarding (Mada, Visa, Mastercard, Apple Pay, STC Pay, Tabby, Tamara, Neo, manual bank transfer). The hosted checkout displays only the ones that are on for you.

Three kinds of token

Your client gives you an org token, and your admin login gives you a client admin token. A third value, the payment ticket, is requested by your backend for one buyer and one payment, right before the checkout redirect. See Authentication.

If you don't have these yet, you're not onboarded yet. Reach out to your Waffy account manager to get started.

Environments

AspectSandbox (dev)StagingProduction
Waffy ID (tokens)https://id-dev.waffyapp.comhttps://id-stg.waffyapp.comhttps://id.waffyapp.com
Business APIhttps://dev-api.waffyapp.comhttps://api-stg.waffyapp.comhttps://api.waffyapp.com
Authentication servicehttps://dev-auth.waffyapp.comhttps://auth-stg.waffyapp.comhttps://auth.waffyapp.com
Checkouthttps://external-dev.waffyapp.comhttps://external-stg.waffyapp.comhttps://external.waffyapp.com
Webhook URLConfigured by Waffy at provisioning. Contact your account manager to change.Same mechanism.Confirmed with Waffy before go-live.
PaymentsSimulated.Simulated or real.Real. Real money moves.
WebhooksFire on every state change, same payload shape.Same.Same.
Approval requiredNo.No.Yes: compliance review and Waffy’s readiness checklist.

Use the same code across all environments

The only thing that changes between environments is the base URLs and the credential set. Your request shapes, response schemas, and webhook payloads are identical. Keep the URLs in configuration, named like the Postman environment variables: id_base_url, api_base_url, auth_base_url and checkout_base_url. The Postman collection already works this way.