Docs β€Ί Guides

Go-live checklist

Everything to verify before switching to a live key.

Run through this list in the sandbox, then switch to your dfk_live_ key.

Integration

  • [ ] Every order uses your own unique order number as externalId.
  • [ ] Network errors and 5xx are retried with the same externalId and exponential backoff.
  • [ ] 400 VALIDATION_ERROR responses are logged with error.details[], and not retried blindly.
  • [ ] Every stop has a full address and a reachable mobile contactPhone.
  • [ ] Windows are sent with a time-zone offset, e.g. -07:00.
  • [ ] subtotalCents and tipCents are in cents (integers).
  • [ ] You can cancel an order from your system (POST /v1/orders/{externalId}/cancel).

Webhooks

  • [ ] Endpoint is HTTPS, publicly reachable, and answers 2xx within a few seconds.
  • [ ] Signatures are verified against the raw body; messages older than 5 minutes are rejected.
  • [ ] Messages are deduplicated on dragonfly-id.
  • [ ] delivery.failed and delivery.canceled_by_* are handled, not just success.
  • [ ] A test message (POST /v1/webhooks/{id}/test) was received and verified.

Security

  • [ ] The API key lives only server-side, in a secrets manager or env var. It is never in code, logs or a browser.
  • [ ] One key per system or agent, with a clear label.
  • [ ] You know who can revoke keys (the account owner, on the API access page).

Switching

  1. Get production access (how) and create a dfk_live_ key.
  2. Register your production webhook endpoint with the live key. Endpoints belong to the key that made them.
  3. Send one real order with your account manager watching, then turn on full traffic.

Something unclear or missing? Tell us.