Getnet DocsGetnet Docs

Configure Environments and Credentials

This guide explains how to configure your application to switch between the Test (Sandbox) and Production environments of the Get Smart API Cloud. It also details the credentials required to authenticate your merchant account.

Environments

The API Cloud provides two distinct environments. You must ensure your application sends requests to the correct base URL depending on your development stage.

Test Environment (Sandbox)

Use this environment for development and integration testing. Transactions here do not process real money.

  • Base URL: https://tpvpc-i.redsys.es:27443/TPV_PC/services/rest/tpvpcwss/v1
  • Characteristics:
    • Requires specific test credentials.
    • Uses port 27443.
    • Strictly for integration verification.

Production Environment

Use this environment for live transaction processing.

  • Base URL: https://tpvpc.redsys.es/TPV_PC/services/rest/tpvpcwss/v1
  • Characteristics:
    • Requires live production credentials issued by your acquiring bank.
    • Processes real financial transactions.

Network Configuration: Ensure your outbound firewall rules allow traffic to the specific domains and ports listed above. Both environments require connections via TLS 1.2 or higher.

Required Credentials

To interact with the API, you need a set of identifiers and secrets. These are typically provided by your acquiring bank or entity.

CredentialVariable NameFormatDescription
Merchant CodecomercioNumeric (9 digits)A unique identifier for your business. Included in every JSON request payload.
Terminal NumberterminalNumeric (2 digits)The identifier for the specific physical terminal. Included in the JSON request payload.
Merchant key(Not sent directly)Alphanumeric StringThe “clave de firma” used to generate the cryptographic signature. Never send this key in your API requests.

Managing Keys

  • Test Keys: You will receive a specific key for the test environment (e.g., AAABBB is often used as a placeholder in documentation, but you must use the one assigned to you).
  • Production Keys: Upon certification of your integration, you will be issued a separate production key.

Security Best Practice: Never hardcode your merchant key in client-side code (e.g., mobile apps or frontend web code). Signature generation must happen on your secure backend server to prevent key leakage.

Next Steps

With your environment URLs and credentials ready, you need to implement the security logic to sign your requests.

  • Authenticate Requests: Learn how to use your merchant key to generate the signature required for every API call.