Onerway
Get Started

Setup

Activate a sandbox account, obtain API credentials, configure your IP allowlist, and send your first test transaction before going live.

To integrate with Onerway Payments, first activate a sandbox account, obtain API credentials, and configure the sandbox IP allowlist. Develop and test your integration in the sandbox before configuring the production environment and going live.

Integration steps

Activate your sandbox account

Contact Onerway technical support with your and to receive a dashboard invitation. Once you click the link in that email, your merchant account is active in the sandbox.

If you show the Apple Pay button on your own pages through the Web SDK or the Direct API, every sandbox and production domain involved must pass Apple domain verification, either through your own Apple Developer account or registered by Onerway; the Onerway-hosted checkout page does not need this step. See Apple Pay setup.

For Google Pay through the Direct API, complete website registration before going live; Checkout and the Web SDK need no registration.

Retrieve your credentials

Log in to the merchant portal and obtain the following API credentials for server-side API calls.

CredentialPathDirect link
Settings → User infoSandbox · Production
Settings → Payment → Application listSandbox · Production
Developers → API credentialsSandbox · Production
Keep your secret on the server side. Never embed it in client-side code, mobile binaries, or version control.

Configure your IP allowlist

Before making your first server-side API request in the sandbox, you must add every public IP address from which your server calls Onerway to the sandbox IP allowlist. In the sandbox merchant portal, go to Developers → IP allowlist and add these addresses. Use your server's outbound IP addresses, not the IP addresses of customers visiting your website.

Configure the IP allowlist separately for the sandbox and production environments. Before going live, you must add all public outbound IP addresses used by your production servers in the production merchant portal. Add the IP addresses in each environment even if they are the same.

EnvironmentWhen to configurePortal link
SandboxBefore your first server-side API request in the sandboxSandbox IP allowlist
ProductionBefore your first server-side API request in productionProduction IP allowlist

When the IP allowlist is enabled, requests from IP addresses that are not on the allowlist for the target environment may be rejected.

Build and test

After configuring the sandbox IP allowlist, use your sandbox credentials to develop and test your integration. Verify all payment flows, error handling, and webhooks. Before switching to the production API base URL and credentials, you must add your production servers' public outbound IP addresses to the production IP allowlist. Also complete any required payment method setup, such as Apple Pay domain verification or Google Pay website registration.

Next steps

  • Request signing — learn how Onerway authenticates requests via signatures and how to generate sign
  • Currency and amount validation — validate orderCurrency, orderAmount, and payment method limits before creating a payment request
  • Sandbox testing — use sandbox test cards to validate success, failure, subscription, and token payment scenarios