Docs βΊ Guides
Go-live checklist
Everything to verify before switching to a live key.
Run through this list in the sandbox, then switch to your dfk_live_ key.
Integration
- [ ] Every order uses your own unique order number as
externalId. - [ ] Network errors and
5xxare retried with the sameexternalIdand exponential backoff. - [ ]
400 VALIDATION_ERRORresponses are logged witherror.details[], and not retried blindly. - [ ] Every stop has a full address and a reachable mobile
contactPhone. - [ ] Windows are sent with a time-zone offset, e.g.
-07:00. - [ ]
subtotalCentsandtipCentsare in cents (integers). - [ ] You can cancel an order from your system (
POST /v1/orders/{externalId}/cancel).
Webhooks
- [ ] Endpoint is HTTPS, publicly reachable, and answers
2xxwithin a few seconds. - [ ] Signatures are verified against the raw body; messages older than 5 minutes are rejected.
- [ ] Messages are deduplicated on
dragonfly-id. - [ ]
delivery.failedanddelivery.canceled_by_*are handled, not just success. - [ ] A test message (
POST /v1/webhooks/{id}/test) was received and verified.
Security
- [ ] The API key lives only server-side, in a secrets manager or env var. It is never in code, logs or a browser.
- [ ] One key per system or agent, with a clear label.
- [ ] You know who can revoke keys (the account owner, on the API access page).
Switching
- Get production access (how) and create a
dfk_live_key. - Register your production webhook endpoint with the live key. Endpoints belong to the key that made them.
- Send one real order with your account manager watching, then turn on full traffic.
Something unclear or missing? Tell us.