Environments Overview
Staging (Fin) vs production — URLs, keys, and checkout domains.
DigetPay runs two isolated environments: Fin staging for development and testing, and Production for live payments.
Use this page as the source of truth for environment URLs, API keys, and the rules for switching from staging to production.
Rule of thumb: Staging keys work only with Fin staging URLs. Production keys work only with production URLs. Never mix environments.
Environment comparison
| Item | Fin staging | Production (Live) |
|---|---|---|
| Purpose | Development, testing, and validation | Live merchant payments |
| API base URL | https://fin-api.digetpay.com/v1 | https://api.digetpay.com/v1 |
| Checkout page | https://pay-staging.digetpay.com/pay/checkout | https://pay.digetpay.com/pay/checkout |
| Merchant dashboard | https://pay-staging.digetpay.com | https://pay.digetpay.com |
| API key | Staging x-api-key | Production x-api-key |
| Real payments | No | Yes |
| Typical use | Integration, QA, and UAT | Live payment processing |
Environment rules
Fin staging
Use Fin staging to:
- Build and test your integration
- Validate successful and failed payment flows
- Test webhook delivery
- Verify error handling
- Run integration and UAT testing
- Complete the required production readiness checks
Fin staging transactions do not process real money.
Production
Use production only after:
- Business onboarding is complete
- Your integration has passed the required staging tests
- Production approval has been granted
- You have received production credentials
- Your production configuration has been reviewed and is ready for live traffic
Production transactions may process real payments.
Production warning: Do not use production credentials for development or experimentation. Test new integration changes in Fin staging before deploying them to production.
Authentication
Payment API requests use the x-api-key header.
x-api-key: YOUR_ENVIRONMENT_API_KEY
Content-Type: application/jsonUse the API key issued for the environment you are calling:
- Fin staging API key → Fin staging API
- Production API key → Production API
Keep API keys server-sideStore API keys in a secrets manager or protected environment variable. Never expose API keys in frontend JavaScript, mobile application source code, or public repositories.
For credential management and security guidance, see Authentication & Credentials.
Create a payment in Fin staging
Use the Fin staging API base URL when creating test payments.
curl -X POST "https://fin-api.digetpay.com/v1/payment/checkout/intiate" \
-H "x-api-key: YOUR_STAGING_KEY" \
-H "Content-Type: application/json" \
-d '{
"merchantOrderId": "TEST-001",
"amount": 0.20,
"currency": "SAR",
"customerPhone": "501223324",
"successUrl": "https://your-domain.com/payment/success",
"failureUrl": "https://your-domain.com/payment/failure"
}'Replace YOUR_STAGING_KEY with your Fin staging API key.
For the complete request and response schema, see Create Payment Link.
Switch the same integration to production
After production approval, change your configuration to use the production API URL and production API key.
curl -X POST "https://api.digetpay.com/v1/payment/checkout/intiate" \
-H "x-api-key: YOUR_PRODUCTION_KEY" \
-H "Content-Type: application/json" \
-d '{
"merchantOrderId": "PROD-001",
"amount": 10.50,
"currency": "SAR",
"customerPhone": "501223324",
"successUrl": "https://your-domain.com/payment/success",
"failureUrl": "https://your-domain.com/payment/failure"
}'The request structure remains the same. Only the following values change:
- API base URL
- API key
- Merchant configuration
- Production callback and redirect URLs
Your
successUrlandfailureUrlshould point to your own publicly accessible application URLs. Redirect URLs are not proof of payment; always confirm the final transaction status on your server.
Configuration pattern
Keep environment-specific values outside your application code (PHP / Node.Js / Python )
<?php
$config = [
'staging' => [
'api_base' => 'https://fin-api.digetpay.com/v1',
],
'production' => [
'api_base' => 'https://api.digetpay.com/v1',
],
];
$environment = getenv('DIGETPAY_ENV') ?: 'staging';
$apiBase = $config[$environment]['api_base'];
$apiKey = getenv('DIGETPAY_API_KEY');const API_BASE =
process.env.DIGETPAY_ENV === 'production'
? 'https://api.digetpay.com/v1'
: 'https://fin-api.digetpay.com/v1';
const API_KEY = process.env.DIGETPAY_API_KEY;import os
API_BASE = (
"https://api.digetpay.com/v1"
if os.getenv("DIGETPAY_ENV") == "production"
else "https://fin-api.digetpay.com/v1"
)
API_KEY = os.getenv("DIGETPAY_API_KEY")
API_KEY = os.getenv("DIGETPAY_API_KEY")
API_KEY = os.getenv("DIGETPAY_API_KEY")
Configuration best practices
- Keep staging and production API keys separate.
- Store secrets in protected environment variables or a secrets manager.
- Never hard-code production credentials.
- Validate the selected environment before sending a payment request.
- Do not automatically switch an application from staging to production.
- Test configuration changes in Fin staging before production deployment.
Legacy staging URL
Some older documentation may reference:
https://staging-api.digetpay.com/v1Do not use this URL for new integrations.
Use:
https://fin-api.digetpay.com/v1for all current Fin staging integrations.
Troubleshooting environment issues
Invalid API key
Check that:
- You are using the API key for the correct environment.
- The key has been copied correctly.
- The key has not been revoked or replaced.
- No extra spaces or invalid characters were added.
Endpoint not found
Check that:
- You are using the correct environment API base URL.
- The endpoint path matches the current API reference.
- The request is using the correct HTTP method.
Payment works in staging but not in production
Check that:
- Production activation has been completed.
- You are using production credentials.
- Production URLs are configured correctly.
- Your production callback and redirect URLs are accessible.
- The production configuration matches your approved merchant setup.
Webhooks are not received
Check that:
- Your webhook URL is publicly accessible.
- Your endpoint uses HTTPS where required.
- Your webhook configuration is active.
- Your application accepts incoming webhook requests.
- Your server logs show whether the webhook request reached your endpoint.
See Webhooks for the complete webhook configuration and handling guide.
Before switching to production
Before you send live traffic to the production environment, confirm that:
- Your integration has been tested successfully in Fin staging.
- Successful and failed payment scenarios have been tested.
- Webhook handling has been tested.
- Your server confirms the final transaction status before fulfillment.
- Production API credentials have been issued.
- Production environment URLs are configured.
- Callback and redirect URLs are accessible.
- Secrets are stored securely.
- Monitoring and error logging are enabled.
- The required go-live approval has been completed.
Ready to accept live payments? Continue with the Go-Live Checklist.
Updated 11 days ago

