Skip to main content
You build with a sandbox app, then repeat the setup in a separate production app and test it with real users before opening it up.
1

Finish in Sandbox

Your integration works end to end with a sandbox app, including failure, cancellation, and expiry. See Sandbox Testing.
2

Create a production app

Production apps require an Enterprise subscription. Contact Hopae to upgrade. Nothing is copied from the sandbox app: create a production app in the Console and copy its App ID and App Secret. The URLs stay the same. See Apps & Environments.
3

Activate connections

Activate every connection you need. Registration connections wait for the provider’s review, and contract connections need an onboarding call, so start early. See Activate Connections.
4

Configure the app

Set up the workflow, the redirect URIs, and webhooks, as in Sandbox. Saves take effect immediately.
5

Test with a small group

Run real verifications with internal users or a pilot group. Test each connection on its own: one working connection of a provider says nothing about another.
Production traffic uses real identity data and is billed.
6

Open it up

Check the list below, then expand access.

Launch checklist

  • Every connection you need shows Activated in the production app and is enabled in its workflow.
  • Claims, assurance level, and countries are confirmed for each connection.
  • Success, cancellation, failure, and expiry paths pass in production.
  • The production App ID and App Secret are in use, and the secret lives only on your backend.
  • Every callback is in the production app’s Redirect URL Allowlist.
  • OIDC: state, nonce, iss, and the ID token signature are validated.
  • Webhooks: signatures are verified and duplicate deliveries are handled.
  • A custom domain, if you use one, is active.
  • Alerts cover provider errors and webhook failures.
  • Owners for support and incidents are named.
  • Billing reports match your own counts.