Environments & access

Test anything. Lock down everything.

One protected production environment plus unlimited sandboxes, keys bound to an environment, 111 granular API scopes, team roles, and a workspace audit log.

As many sandboxes as you need

Every workspace has exactly one production environment — it can’t be deleted, archived, or duplicated. Alongside it, create as many non-production environments as your process needs: staging, UAT, QA, a demo for a client. Each one uses sandbox credentials with your processors and tax and shipping providers.

Everything that changes is scoped to an environment: customers, carts, orders, payments, subscriptions, discounts, webhooks, settings, even idempotency keys. Testing can’t touch live data, because there’s no path for it to.

Keys that can’t wander

  • Secret keys (sk_) live on your server; publishable keys (pk_) are safe in a browser and limited to five browser-safe scopes.
  • Each key is minted for one environment for life, and its prefix says which — sk_live_ for production, sk_test_ or sk_uat_ for the rest.
  • Keys are shown once and can be rotated.

Permissions down to the route

Keys carry granular scopes — 111 of them, each a resource:read or resource:write — and every API route declares the one it needs. Give an integration exactly the access it uses and nothing else.

Roles for the whole team

LevelRoles
WorkspaceOwner, workspace admin, member
ApplicationAdmin, developer, finance, viewer

Members can also be limited by environment — production only, non-production only, or a chosen list — so a contractor can build in staging without ever seeing live orders. Invitations are emailed and must be accepted by the invited address, and can be resent or revoked.

Many applications, one workspace

A workspace holds as many applications as you run — storefronts, brands, client projects — each with its own settings in each environment. Agencies run every client from one login.

An audit trail

Administrative, team, and billing actions are recorded in a workspace audit log, tagged with the environment they touched.

Good to know

  • The audit log covers administrative actions, not every read of your data.
  • Going live is its own checklist — see going live.