Go Live
This guide walks you through moving your integration from the sandbox to production once testing is complete.
Before You Switch
Prerequisites
Before going live, complete your contract with Hecto Financial and obtain your production merchant ID and production keys. Ask your account manager to confirm that acquirer review has been completed for every payment method you plan to use.
Testing Checklist
Verify all of the following in the sandbox before switching:
- Successful payments, with notifications arriving at your notiUrl
- Your pktHash verification logic works correctly
- Every payment method you plan to offer works end to end
- Encryption and license keys exist only on your server (never exposed to the client)
- Failed payments are handled gracefully
- Payment cancellation works correctly
Configuration Changes
Replace the following values with their production counterparts:
| Item | Sandbox | Production |
|---|---|---|
| Checkout URL | https://tbnpg.settlebank.co.kr | https://npg.settlebank.co.kr |
| API URL | https://tbgw.settlebank.co.kr | https://gw.settlebank.co.kr |
| SDK URL | https://tbnpg.settlebank.co.kr/resources/js/v1/SettlePG_v1.2.js | https://npg.settlebank.co.kr/resources/js/v1/SettlePG_v1.2.js |
| Merchant ID | Sandbox ID (e.g. nxca_jt_il) | Your production merchant ID |
| License key | ST1009281328226982205 | Your production license key |
| AES key | pgSettle30y739r82jtd709yOfZ2yK5K | Your production AES key |
Double-check your keys
When deploying to production, confirm that the merchant ID, license key, and AES key have all been replaced with production values. Any leftover sandbox key will cause payments to fail in production.
Firewall Configuration
- Inbound: Allow the Hecto Financial notification server IPs so payment notifications can reach your notiUrl.
- Outbound: Allow HTTPS (TCP/443) access from your server to the checkout and API domains.
See Preparation for the domains and IP addresses of each environment.
Allow both Primary and Secondary
The Hecto Financial system runs across a primary and a secondary data center. Allow both production IPs — if either is missing, notifications from that center will not be received during a failover. Use DNS lookup rather than pinning IPs in a hosts file, as pinned entries cannot follow a center failover.
After the Switch
Run a small live payment right after switching and verify:
- The payment is approved and the notification arrives at your notiUrl
- Payment details are stored correctly in your database
- Cancellation works correctly (verify through approval cancellation)
- No unexpected errors in your logs
Troubleshooting
No payments go through at all
- Confirm production keys are in place (merchant ID, license key, AES key)
- Confirm the checkout, SDK, and API URLs point to production
- Confirm acquirer review is complete (ask your account manager)
Notifications are not received
- Confirm the notification server IPs are allowed through your firewall (Primary + Secondary)
- Confirm your notiUrl uses HTTPS (HTTP is not supported)
- Confirm your notiUrl responds with
OKas plain text
pktHash mismatch errors
- Confirm the production license key (hash generation key) is in place
- Confirm the hash field order is correct (see Preparation)
- Confirm hash generation uses plaintext values for encrypted fields such as the amount
Related Documents
More Resources
Need technical support?
Code Samples
HectoFinancial GitHub