Configure Environments and Credentials
This guide explains how to configure your application to switch between the Test (Sandbox) and Production environments of the Get Smart API Cloud. It also details the credentials required to authenticate your merchant account.
Environments
The API Cloud provides two distinct environments. You must ensure your application sends requests to the correct base URL depending on your development stage.
Test Environment (Sandbox)
Use this environment for development and integration testing. Transactions here do not process real money.
- Base URL:
https://tpvpc-i.redsys.es:27443/TPV_PC/services/rest/tpvpcwss/v1 - Characteristics:
- Requires specific test credentials.
- Uses port 27443.
- Strictly for integration verification.
Production Environment
Use this environment for live transaction processing.
- Base URL:
https://tpvpc.redsys.es/TPV_PC/services/rest/tpvpcwss/v1 - Characteristics:
- Requires live production credentials issued by your acquiring bank.
- Processes real financial transactions.
Network Configuration: Ensure your outbound firewall rules allow traffic to the specific domains and ports listed above. Both environments require connections via TLS 1.2 or higher.
Required Credentials
To interact with the API, you need a set of identifiers and secrets. These are typically provided by your acquiring bank or entity.
| Credential | Variable Name | Format | Description |
|---|---|---|---|
| Merchant Code | comercio | Numeric (9 digits) | A unique identifier for your business. Included in every JSON request payload. |
| Terminal Number | terminal | Numeric (2 digits) | The identifier for the specific physical terminal. Included in the JSON request payload. |
| Merchant key | (Not sent directly) | Alphanumeric String | The “clave de firma” used to generate the cryptographic signature. Never send this key in your API requests. |
Managing Keys
- Test Keys: You will receive a specific key for the test environment (e.g.,
AAABBBis often used as a placeholder in documentation, but you must use the one assigned to you). - Production Keys: Upon certification of your integration, you will be issued a separate production key.
Security Best Practice: Never hardcode your merchant key in client-side code (e.g., mobile apps or frontend web code). Signature generation must happen on your secure backend server to prevent key leakage.
Next Steps
With your environment URLs and credentials ready, you need to implement the security logic to sign your requests.
- Authenticate Requests: Learn how to use your merchant key to generate the
signaturerequired for every API call.