# Setup

> Before calling Issuing APIs, read the flow below carefully.

## Setup steps

<steps level="3">

### Select the base URL

Use the base URL that matches the environment of your `ApiKey`.

| Environment | Base URL |
| --- | --- |
| Production | `https://issuer.onerway.com/api/v1/merchant` |
| Sandbox | `https://sandbox-issuer.onerway.com/api/v1/merchant` |

<note>

Sandbox and production credentials are separate. API paths, request methods, and request structures stay the same across environments, but the base URL and `ApiKey` must come from the same environment.

</note>

### Create a sandbox merchant account

Provide your email address, source IP address, and event callback URL to Onerway. After the sandbox account is created, sign in to the merchant portal from the email link and obtain the merchant number and secret key used for integration and webhook verification.

### Provide source IP addresses

Send your stable server source IP addresses to Onerway so they can be added to the Issuing allowlist.

- Provide only stable server source IP addresses.
- If sandbox and production use different source IP addresses, provide them separately.
- If a source IP address changes, update the allowlist before switching traffic.

### Store credentials securely

Issuing APIs identify caller permissions through the `ApiKey` request header. Store the `ApiKey`, merchant number, and webhook secret on your server.

<warning>

Do not expose issuing credentials in frontend pages, mobile apps, client-side bundles, logs, or public repositories.

</warning>

### Configure event callbacks

Configure a server-side callback URL that can receive card operation and transaction event webhooks. The callback must verify `x-signature`, deduplicate events by `request_id`, and return `respCode=20000` after accepting an event.

</steps>

## Integration flow

| Step | Action | Endpoint or source |
| --- | --- | --- |
| 1 | Get card product information and confirm the `productId` with Onerway. | Card product list |
| 2 | Create a cardholder that matches the card product. | [Create cardholder](/issuing/api-reference/endpoints/create-cardholder) |
| 3 | Create a card with `productId`, `cardholderId`, and the deposit amount. | [Create card](/issuing/api-reference/endpoints/create-card) |
| 4 | Query card operation progress, basic card information, balance, and sensitive information when needed. | [Card queries](/issuing/api-reference/endpoints/get-operate-record-list) |
| 5 | Receive card operation event notifications. | [Card operation event](/issuing/api-reference/webhooks/card-operation-event) |
| 6 | Query card transaction records and receive transaction event notifications. | [Query transaction records](/issuing/api-reference/endpoints/query-transaction-records) |

## Next steps

- [API specifications](/issuing/api-reference) — review common Issuing API rules
- [Create cardholder](/issuing/api-reference/endpoints/create-cardholder) — create a cardholder before card creation
- [Create card](/issuing/api-reference/endpoints/create-card) — create the first virtual card
- [Event webhooks](/issuing/api-reference/webhooks/card-operation-event) — configure card operation and transaction event handling
