Testing
Validate your online payments integration against the development environment with test cards.
Test Checkout against the Tapaya development environment. Payments there go through the development gateway with test cards, so no real money moves.
Point your server at the development API
Set TAPAYA_CHECKOUT_API_URL to https://api.sandbox.tapaya.com and store the Secret key from the development Platform's API Keys page in
TAPAYA_CHECKOUT_API_KEY. Keep both on your server.
TAPAYA_CHECKOUT_API_URL=https://api.sandbox.tapaya.com
TAPAYA_CHECKOUT_API_KEY=your-development-secret-keySetting the API base URL alone does not configure the gateway. The merchant behind your key must be set up for the development gateway, with Checkout enabled and return URLs saved in Checkout settings.
Create a test session
Create a session for a test order, exactly as in the Quick Start Guide. Store the returned
id with the order before redirecting, so you can check the result even if the browser is closed.
Pay with a test card
Open the session's url and pay with one of the cards below, any future expiry date, and CVC 123.
Verify from your server
Retrieve the session with your Secret key and compare its order reference, amount, currency, and
paymentStatus with the stored order. The browser returning to your success URL does not prove payment.
Test cards
Use these development gateway test cards.
| Scenario | Card number | Expected result |
|---|---|---|
| Payment succeeds | 4242 4242 4242 4242 | paymentStatus: successful. Your server fulfills the order once. |
| Card is declined | 4916 0184 7581 4056 | paymentStatus: failed, status stays open. The customer can retry while the session is unexpired. |
| 3D Secure required | 4012 0018 0000 0016 | Complete the test challenge. Fulfill only after retrieval confirms success. |
A processing-error card can pass tokenization and fail only when charged, so always check the retrieved status rather than the card form's reaction.
What the development environment covers
- Hosted Checkout: cards with the test cards above. Wallet buttons depend on the merchant's settings and the customer's device and browser, so do not rely on them appearing in every test.
- Embedded payments: cards only. The embedded component does not yet support wallets or live gateway configuration. See Embedded Checkout.
- Session lifetime: sessions expire 30 minutes after creation. Create a fresh session for each independent test.
Once the basic flow passes, work through the QA Checklist, which covers retries, lost responses, and customers who never return.