# Configure Environments and Credentials

This guide explains how to configure your application to switch between the **Test** (Sandbox) and **Production** environments of the Get Smart API Cloud. It also details the credentials required to authenticate your merchant account.

## Environments

The API Cloud provides two distinct environments. You must ensure your application sends requests to the correct base URL depending on your development stage.

### Test Environment (Sandbox)

Use this environment for development and integration testing. Transactions here do not process real money.

* **Base URL:** `https://tpvpc-i.redsys.es:27443/TPV_PC/services/rest/tpvpcwss/v1`
* **Characteristics:**  
  * Requires specific test credentials.  
  * Uses port **27443**.  
  * Strictly for integration verification.

### Production Environment

Use this environment for live transaction processing.

* **Base URL:** `https://tpvpc.redsys.es/TPV_PC/services/rest/tpvpcwss/v1`  
* **Characteristics:**  
  * Requires live production credentials issued by your acquiring bank.  
  * Processes real financial transactions.

> **Network Configuration**: Ensure your outbound firewall rules allow traffic to the specific domains and ports listed above. Both environments require connections via **TLS 1.2** or higher.

## Required Credentials

To interact with the API, you need a set of identifiers and secrets. These are typically provided by your acquiring bank or entity.

| Credential | Variable Name | Format | Description |
| :---- | :---- | :---- | :---- |
| **Merchant Code** | `comercio` | Numeric (9 digits) | A unique identifier for your business. Included in every JSON request payload. |
| **Terminal Number** | `terminal` | Numeric (2 digits) | The identifier for the specific physical terminal. Included in the JSON request payload. |
| **Merchant key** | *(Not sent directly)* | Alphanumeric String | The "clave de firma" used to generate the cryptographic signature. **Never send this key in your API requests.** |

### Managing Keys

* **Test Keys:** You will receive a specific key for the test environment (e.g., `AAABBB` is often used as a placeholder in documentation, but you must use the one assigned to you).  
* **Production Keys:** Upon certification of your integration, you will be issued a separate production key.

> **Security Best Practice**: Never hardcode your merchant key in client-side code (e.g., mobile apps or frontend web code). Signature generation must happen on your secure backend server to prevent key leakage.

## Next Steps

With your environment URLs and credentials ready, you need to implement the security logic to sign your requests.

* [**Authenticate Requests**](/en/get-smart/get-smart-api-cloud/first-steps/authtenticate-requests): Learn how to use your merchant key to generate the `signature` required for every API call.