Keys and environments.
Separate environments and capabilities at the code boundary, not just in the UI.
Publishable and secret keys#
| Key | Where it belongs |
|---|---|
| pk_test_ / pk_live_ | Browser/client integration. Permissions remain limited by the service. |
| sk_test_ / sk_live_ | Trusted backend only. Never paste into this playground or ship in a game bundle. |
| Studio admin / operator private keys | Studio-controlled signing environment. Never upload them to Playmos. |
Test and live#
Test keys resolve to Base Sepolia (84532); live keys resolve to Base (8453). Mock mode performs no network or chain transaction. Sandbox server settlement is test-only. A reachable live URL is not production readiness.
Errors and recovery#
| Condition | Response |
|---|---|
| Invalid amount / missing field | Correct the typed input before sending. SDK amounts are decimal strings. |
| 401 / 403 / studio mismatch | Check key type, environment and resource ownership on your backend. |
| 409 / idempotency conflict | The same purchase key was reused with different terms. Recover the original purchase. |
| 429 / sandbox rate limit | Respect backoff. Retry the same purchase key, not a new purchase. |
| Pending / timeout | Keep the receipt/key. Retry verification; a timeout does not prove failure. |
| Degraded chain read | Show stale/unverified state and retry later. Never invent confirmed totals. |
Production integration checklist#
- Scope credentials and records to the verified studio and game.
- Verify payment provenance and expected purchase terms server-side.
- Deduplicate fulfillment and webhook events durably.
- Pin the SDK version and test payment, admission, score and payout recovery.
- Freeze and scan hosted releases before public eligibility.
- Keep operator/private service access behind your approved network controls.
Mainnet availability#
Live keys and funded mainnet operation remain gated by founder/compliance approval. A URL, key-shaped string or typed SDK method does not enable production. When that gate opens, key, chain and USDC change together; a dedicated chain-matched RPC is required for mainnet reads. Own-pool mainnet deployment is a new reviewed pool, not a migration of an existing Sepolia address.
The sandbox documents caps of 1.00 per server-settle request, 5 requests per minute and 20.00 per day. Honor actual service limits and response headers; these are test-service limits, not production pricing. Offline mock: true performs no network/chain transaction and carries mock provenance.
For diagnostics, typed error meanings and ambiguous settlement recovery, continue with Troubleshooting.