Going live
Test mode is open to everyone. Taking real money needs your business verified first: it’s how we keep customers and merchants safe, and it’s required of payment businesses in Nigeria.
1. Verify your business
Section titled “1. Verify your business”In the dashboard, open Verify business. The first question is whether your business is registered with the Corporate Affairs Commission (CAC).
Not registered (a sole trader or side business). Have ready:
- Your business name, what you sell, your website or social media page, and your address.
- Your legal name as on your BVN, date of birth, phone number and home address.
- Your BVN.
- A photo of your ID: NIN slip or card, international passport, driver’s licence or voter’s card (front and back, or the passport’s photo page).
- Your own personal bank account for payouts. It must be in your name.
Registered (a Business Name, Limited Company or Incorporated Trustees). Have ready:
- The registered name exactly as on the CAC certificate, the CAC number (
BN…,RC…orIT…) and registration date. A limited company also needs its TIN. - What you sell, your website or social media page, and your registered address.
- The CAC certificate. A limited company also needs its status report (or form CAC 1.1); incorporated trustees, the list of trustees.
- For every proprietor, director or trustee, and anyone owning 25% or more: their legal name, date of birth, BVN and a photo of their ID. You must be one of them.
- A bank account in the business’s registered name for payouts. A Business Name may use a proprietor’s own account.
Your answers save as you go. Photos and documents can be JPG, PNG or PDF, up to 5 MB each. BVNs, ID numbers and documents are encrypted, and only ever shown to Stack’s review team.
2. We review it
Section titled “2. We review it”Submit when every step shows a tick. We check each application by hand and email you when it’s done. We may:
- Approve it. Your business is verified.
- Ask for changes. Only the parts we name open for editing; fix them and submit again.
- Turn it down, with the reason. You can fix it and apply again.
Registered with CAC later? Apply again as a registered business from the same page; you stay verified while we review it.
3. Switch to live
Section titled “3. Switch to live”Once verified, switch the dashboard from Test to Live. Everything the dashboard shows then is live: your live balance, payments, payouts, API keys and webhooks.
- Live keys (
pk_live_…,sk_live_…) are under API keys in live mode. The API address stays the same, so swapping the keys is the only code change. - Live has its own webhook endpoint and signing secret. Add it under Webhooks in live mode; test events keep going to your test endpoint.
- Your live balance starts at zero. Test money never becomes live money.
- Card, bank and transfer payments move real money, and payouts are real transfers to your bank account.
- Test cards and Simulate the transfer don’t work with live keys.
Changing your payout account
Section titled “Changing your payout account”After you’re verified, a new payout account is checked by us before live money goes there. Live payouts pause until we’ve approved it; test payouts carry on. The account must follow the same rule as when you verified: in your own name, or the business’s.
Limits
Section titled “Limits”We may set a limit on a business’s live payments (per payment or per month), for example
while a new business settles in. A payment over a limit is refused with a
limit_exceeded error.
Checklist
Section titled “Checklist”- Payments are created on your server, with amounts your server works out, never taken from the app.
- Orders are fulfilled from the webhook, not from
presentPaymentSheet’s result. - Your webhook handler verifies signatures, answers within 10 seconds, and handles duplicates. See the checklist.
- Idempotency keys on every payment and refund your server creates.
- The secret key is only on your server, in an environment variable, and never in source control.
- Live keys and the live webhook secret are set on your production server, and test keys stay on your test setup.