---
title: Going live
description: What you need for live keys, and how to switch.
---

Live keys move real money. You use the same account for test and live, and you verify your business once.

## What you need

- A **business at verification level 2 or higher.** Level 1 is a confirmed phone number and level 2 adds an approved ID document, both done in the [developer console](https://console.example.com). Then:
  - a verified business can give a live key any permission, and
  - until your business is verified, a live key can hold only `collections.read`, `collections.write` and `events.read`.

  This is checked when you create the key and again every time it is exchanged for a token, so a live key stops working if your business drops below level 2 or loses its verification.
- A tested integration. Your code should handle every status, including `in_review` and `held`, and treat unknown ones as in progress, duplicate webhooks and `429`.

What you may move depends on your verification level. The console shows your limits. `GET /v1/limits` returns them too.

## Switch to live

1. Sign in to the live console with the same account. Your verification carries over. Your business profile, settlement accounts and webhook endpoints do not: each environment keeps its own, so set them up in live.
2. Create a live key in the live console.
3. Register your webhook endpoint in live. Live endpoints and secrets are separate from test.
4. In your production config, replace the test client ID and secret with the live ones.
5. Replace the test base URL with the live base URL.
6. Make one small collection. Check it end to end, including the webhook.

Do not mix them. A test key against the live base URL, or the reverse, is rejected with `403 environment_mismatch`.

## Keep the test key

Leave the test key in your staging setup. You can keep testing there after you go live.
