Testing
Test API keys
Test keys should be visibly separate from live keys and tied to sandbox/staging data.
Prefixes and labels
Use a Server Test Key (sk_test_) for backend tests and a Browser Publishable Key (pk_publishable_) from the Test project for browser activation. The publishable prefix is the same across environments; check the project and environment in the dashboard. Do not paste live server keys into examples or test fixtures.
Test origins
Add localhost and staging origins to test publishable keys only. Production origins belong on live keys.
Rotation drills
Practice key rotation before launch so operational ownership is clear.
Need help with your integration?
Share the affected endpoint, request ID, and the behavior you expected. Leave out keys and user content.