Skip to main content
AgentBank has two fully isolated API environments. Select the base URL before onboarding a merchant or storing any integration state. Set AGENTBANK_BASE_URL in trusted backend configuration to the selected URL. Every API path is relative to it: signed Partner routes use /v1/partner/*, portal routes use /v1/merchant/*, and public discovery routes use /api/*.

Environment isolation

Sandbox and Production do not share any merchant resource or credential:
  • merchant IDs and Ed25519 key registrations
  • portal usernames, passwords, and JWTs
  • webhook endpoint IDs and HMAC signing secrets
  • end-user IDs, KYC versions, rail readiness, payment IDs, and payment history
Register the merchant again in Production, use a Production-only key pair or securely provisioned Production key, register Production webhook endpoints, and repeat KYC/payment testing with approved live procedures before go-live.

Configuration

Do not make the base URL user-controlled. Pin it in trusted backend configuration and allow only HTTPS outbound traffic to the selected host.