[{"data":1,"prerenderedAt":45},["ShallowReactive",2],{"docs:rendered-article:\u002Fdocs\u002Fpublic\u002Fguides\u002Fproduction-checklist":3},{"path":4,"slug":5,"title":8,"description":9,"category":6,"categoryLabel":10,"order":11,"status":12,"family":13,"subfamily":13,"content":14,"html":15,"examplesHtml":16,"excerpt":17,"readTimeMinutes":18,"headings":19,"examplesHeadings":38,"lastUpdated":13,"endpointId":13,"requiredFlag":13,"relatedArticlePaths":39,"badge":13},"\u002Fdocs\u002Fguides\u002Fproduction-checklist",[6,7],"guides","production-checklist","Production checklist","Hardening checklist for auth, retries, quotas, webhook handling, and support readiness.","Guides",45,"updated",null,"\nYou've built your integration. Run through this checklist to make sure everything is production-ready.\n\n## Before go-live\n\n- Store API keys server-side or in a secure secrets manager. See [Authentication](\u002Fdocs\u002Fauthentication#keep-your-key-safe).\n- Log `metadata.requestId` for every request so support can trace issues quickly.\n- Monitor `quotas.workspace.credits.left` and `quotas.workspace.minuteRateLimit.left` from the [Usage endpoint](\u002Fdocs\u002Fendpoints\u002Fusage).\n- Route async workflows through a durable [webhook receiver](\u002Fdocs\u002Fguides\u002Fwebhooks#2-set-up-a-receiver), not a manual test endpoint.\n- Make webhook processing idempotent by deduplicating on `webhookId`. See [Webhooks](\u002Fdocs\u002Fguides\u002Fwebhooks#security-best-practices).\n\n## Request safety\n\n- Use timeouts on every outbound request.\n- Retry only `429` and `5xx` with exponential backoff. See [Error handling](\u002Fdocs\u002Fguides\u002Ferrors-retries#when-to-retry).\n- Respect `minuteRateLimit.nextReset` before retrying a throttled request.\n- Treat `4xx` validation or auth failures as permanent until you change the input or credentials.\n\n## Webhook safety\n\n- Use HTTPS for every production webhook URL.\n- Return `200` quickly, then process heavy work asynchronously.\n- Validate that each callback contains `webhookId` + `data` or `webhookId` + `errorCode`. See [Webhook payload](\u002Fdocs\u002Fguides\u002Fwebhooks#webhook-payload).\n- Deduplicate on `webhookId` to handle rare duplicate deliveries.\n\n## Monitoring & alerts\n\n- Alert on repeated `401`, `402`, `429`, and `5xx` responses.\n- Surface credit exhaustion before it blocks critical workflows. See [Rate limits & credits](\u002Fdocs\u002Fguides\u002Frate-limits-credits).\n- Keep one smoke test for a sync endpoint and one for an async endpoint (see below).\n- Document which team owns [API key rotation](\u002Fdocs\u002Fguides\u002Fapi-key-management), webhook incidents, and quota alerts.\n\n## Recommended smoke tests\n\n1. `GET \u002Fv2\u002Fusage` returns `200` and a valid `quotas` object.\n2. `POST \u002Fv2\u002Ffetch\u002Fpersons\u002Fcheck` returns `200` with `creditsConsumed: 0`.\n3. One async endpoint returns an immediate response and the result is delivered to your webhook URL.\n4. Your application logs both the outbound request and the webhook completion using the same `requestId` or `webhookId`.\n\n## You're ready to go live\n\nIf you've checked every item above, your integration is solid. Ship it.\n","\u003Cp>You’ve built your integration. Run through this checklist to make sure everything is production-ready.\u003C\u002Fp>\n\u003Ch2 id=\"before-go-live\">Before go-live\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Store API keys server-side or in a secure secrets manager. See \u003Ca href=\"\u002Fdocs\u002Fauthentication#keep-your-key-safe\" target=\"_blank\" rel=\"noopener\">Authentication\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Log \u003Ccode>metadata.requestId\u003C\u002Fcode> for every request so support can trace issues quickly.\u003C\u002Fli>\n\u003Cli>Monitor \u003Ccode>quotas.workspace.credits.left\u003C\u002Fcode> and \u003Ccode>quotas.workspace.minuteRateLimit.left\u003C\u002Fcode> from the \u003Ca href=\"\u002Fdocs\u002Fendpoints\u002Fusage\">Usage endpoint\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Route async workflows through a durable \u003Ca href=\"\u002Fdocs\u002Fguides\u002Fwebhooks#2-set-up-a-receiver\" target=\"_blank\" rel=\"noopener\">webhook receiver\u003C\u002Fa>, not a manual test endpoint.\u003C\u002Fli>\n\u003Cli>Make webhook processing idempotent by deduplicating on \u003Ccode>webhookId\u003C\u002Fcode>. See \u003Ca href=\"\u002Fdocs\u002Fguides\u002Fwebhooks#security-best-practices\" target=\"_blank\" rel=\"noopener\">Webhooks\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"request-safety\">Request safety\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Use timeouts on every outbound request.\u003C\u002Fli>\n\u003Cli>Retry only \u003Ccode>429\u003C\u002Fcode> and \u003Ccode>5xx\u003C\u002Fcode> with exponential backoff. See \u003Ca href=\"\u002Fdocs\u002Fguides\u002Ferrors-retries#when-to-retry\" target=\"_blank\" rel=\"noopener\">Error handling\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Respect \u003Ccode>minuteRateLimit.nextReset\u003C\u002Fcode> before retrying a throttled request.\u003C\u002Fli>\n\u003Cli>Treat \u003Ccode>4xx\u003C\u002Fcode> validation or auth failures as permanent until you change the input or credentials.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"webhook-safety\">Webhook safety\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Use HTTPS for every production webhook URL.\u003C\u002Fli>\n\u003Cli>Return \u003Ccode>200\u003C\u002Fcode> quickly, then process heavy work asynchronously.\u003C\u002Fli>\n\u003Cli>Validate that each callback contains \u003Ccode>webhookId\u003C\u002Fcode> + \u003Ccode>data\u003C\u002Fcode> or \u003Ccode>webhookId\u003C\u002Fcode> + \u003Ccode>errorCode\u003C\u002Fcode>. See \u003Ca href=\"\u002Fdocs\u002Fguides\u002Fwebhooks#webhook-payload\" target=\"_blank\" rel=\"noopener\">Webhook payload\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Deduplicate on \u003Ccode>webhookId\u003C\u002Fcode> to handle rare duplicate deliveries.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"monitoring-alerts\">Monitoring &amp; alerts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Alert on repeated \u003Ccode>401\u003C\u002Fcode>, \u003Ccode>402\u003C\u002Fcode>, \u003Ccode>429\u003C\u002Fcode>, and \u003Ccode>5xx\u003C\u002Fcode> responses.\u003C\u002Fli>\n\u003Cli>Surface credit exhaustion before it blocks critical workflows. See \u003Ca href=\"\u002Fdocs\u002Fguides\u002Frate-limits-credits\">Rate limits &amp; credits\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Keep one smoke test for a sync endpoint and one for an async endpoint (see below).\u003C\u002Fli>\n\u003Cli>Document which team owns \u003Ca href=\"\u002Fdocs\u002Fguides\u002Fapi-key-management\">API key rotation\u003C\u002Fa>, webhook incidents, and quota alerts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"recommended-smoke-tests\">Recommended smoke tests\u003C\u002Fh2>\n\u003Col>\n\u003Cli>\u003Ccode>GET \u002Fv2\u002Fusage\u003C\u002Fcode> returns \u003Ccode>200\u003C\u002Fcode> and a valid \u003Ccode>quotas\u003C\u002Fcode> object.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fv2\u002Ffetch\u002Fpersons\u002Fcheck\u003C\u002Fcode> returns \u003Ccode>200\u003C\u002Fcode> with \u003Ccode>creditsConsumed: 0\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>One async endpoint returns an immediate response and the result is delivered to your webhook URL.\u003C\u002Fli>\n\u003Cli>Your application logs both the outbound request and the webhook completion using the same \u003Ccode>requestId\u003C\u002Fcode> or \u003Ccode>webhookId\u003C\u002Fcode>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2 id=\"youre-ready-to-go-live\">You’re ready to go live\u003C\u002Fh2>\n\u003Cp>If you’ve checked every item above, your integration is solid. Ship it.\u003C\u002Fp>\n","","You've built your integration. Run through this checklist to make sure everything is production-ready. Before go-live - Store API keys server-side or in a secure secrets manager...",2,[20,23,26,29,32,35],{"id":21,"title":22,"level":18},"before-go-live","Before go-live",{"id":24,"title":25,"level":18},"request-safety","Request safety",{"id":27,"title":28,"level":18},"webhook-safety","Webhook safety",{"id":30,"title":31,"level":18},"monitoring-alerts","Monitoring & alerts",{"id":33,"title":34,"level":18},"recommended-smoke-tests","Recommended smoke tests",{"id":36,"title":37,"level":18},"youre-ready-to-go-live","You're ready to go live",[],[40,41,42,43,44],"\u002Fdocs\u002Fauthentication","\u002Fdocs\u002Fguides\u002Ferrors-retries","\u002Fdocs\u002Fguides\u002Frate-limits-credits","\u002Fdocs\u002Fguides\u002Fwebhooks","\u002Fdocs\u002Fguides\u002Fapi-key-management",1785860237201]