> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hopae.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Go Live

> Take an integration from a sandbox app to production traffic.

You build with a **sandbox app**, then repeat the setup in a separate **production app** and test it with real users before opening it up.

<Steps>
  <Step title="Finish in Sandbox">
    Your integration works end to end with a sandbox app, including failure, cancellation, and expiry. See [Sandbox Testing](/v2/guides/concepts/testing/sandbox-test).
  </Step>

  <Step title="Create a production app">
    Production apps require an **Enterprise** subscription. Contact Hopae to upgrade. Nothing is copied from the sandbox app: create a production app in the [Console](https://console.hopae.com) and copy its App ID and App Secret. The URLs stay the same. See [Apps & Environments](/v2/guides/concepts/apps).
  </Step>

  <Step title="Activate connections">
    Activate every connection you need. Registration connections wait for the provider's review, and contract connections need an onboarding call, so start early. See [Activate Connections](/v2/guides/concepts/connections/activation).
  </Step>

  <Step title="Configure the app">
    Set up the workflow, the redirect URIs, and webhooks, as in Sandbox. Saves take effect immediately.
  </Step>

  <Step title="Test with a small group">
    Run real verifications with internal users or a pilot group. Test each connection on its own: one working connection of a provider says nothing about another.

    <Warning>
      Production traffic uses real identity data and is billed.
    </Warning>
  </Step>

  <Step title="Open it up">
    Check the list below, then expand access.
  </Step>
</Steps>

## Launch checklist

<AccordionGroup>
  <Accordion title="Connections" icon="link">
    * Every connection you need shows **Activated** in the production app and is enabled in its workflow.
    * Claims, assurance level, and countries are confirmed for each connection.
    * Success, cancellation, failure, and expiry paths pass in production.
  </Accordion>

  <Accordion title="Integration and security" icon="shield-check">
    * The production App ID and App Secret are in use, and the secret lives only on your backend.
    * Every callback is in the production app's **Redirect URL Allowlist**.
    * OIDC: `state`, `nonce`, `iss`, and the ID token signature are validated.
    * Webhooks: signatures are verified and duplicate deliveries are handled.
    * A [custom domain](/v2/guides/concepts/custom-domain), if you use one, is `active`.
  </Accordion>

  <Accordion title="Operations" icon="gauge">
    * Alerts cover provider errors and webhook failures.
    * Owners for support and incidents are named.
    * Billing reports match your own counts.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.