Going live
Your live key (bp_live_) works once Biftpay has approved your business. Before switching:
Your account#
- Finish verification. In the dashboard, complete Verify business (KYC): business details, directors and documents. Biftpay reviews it; the dashboard shows when you're approved.
- Add a settlement bank account in the business's name.
- Check your terms under Settings: settlement timing, payout limits, and any limits on single payments or monthly collections (businesses not yet registered with CAC start with limits that rise once you are).
Your integration#
- Create a live API key and keep it on your server only.
- Add a live webhook endpoint. Test endpoints don't receive live events. Store its new signing secret.
- Your webhook handler checks signatures, rejects old timestamps, answers within 10 seconds and skips events it has already handled.
- Every
POSTsends anIdempotency-Key, and retries reuse it. - You fulfil orders on
payment_intent.successful, not on the customer returning to your site. - You handle
abandonedpayments that later becomesuccessful. - Amounts are integers in kobo or cents end to end.
Keeping your account in good standing#
Biftpay asks you to keep your KYC current: documents that expire (IDs, licences) need replacing, and accounts are reviewed every one to three years. If something lapses, payouts pause after 14 days until it's updated; collections carry on. Keep your dispute rate low and respond to disputes on time.