Test anything. Lock down everything.
One protected production environment plus unlimited sandboxes, keys bound to an environment, 111 granular API scopes, team roles, and a workspace audit log.
As many sandboxes as you need
Every workspace has exactly one production environment — it can’t be deleted, archived, or duplicated. Alongside it, create as many non-production environments as your process needs: staging, UAT, QA, a demo for a client. Each one uses sandbox credentials with your processors and tax and shipping providers.
Everything that changes is scoped to an environment: customers, carts, orders, payments, subscriptions, discounts, webhooks, settings, even idempotency keys. Testing can’t touch live data, because there’s no path for it to.
Keys that can’t wander
- Secret keys (
sk_) live on your server; publishable keys (pk_) are safe in a browser and limited to five browser-safe scopes. - Each key is minted for one environment for life, and its prefix says which —
sk_live_for production,sk_test_orsk_uat_for the rest. - Keys are shown once and can be rotated.
Permissions down to the route
Keys carry granular scopes — 111 of them, each a resource:read or resource:write — and every API route declares the one it needs. Give an integration exactly the access it uses and nothing else.
Roles for the whole team
| Level | Roles |
|---|---|
| Workspace | Owner, workspace admin, member |
| Application | Admin, developer, finance, viewer |
Members can also be limited by environment — production only, non-production only, or a chosen list — so a contractor can build in staging without ever seeing live orders. Invitations are emailed and must be accepted by the invited address, and can be resent or revoked.
Many applications, one workspace
A workspace holds as many applications as you run — storefronts, brands, client projects — each with its own settings in each environment. Agencies run every client from one login.
An audit trail
Administrative, team, and billing actions are recorded in a workspace audit log, tagged with the environment they touched.
Good to know
- The audit log covers administrative actions, not every read of your data.
- Going live is its own checklist — see going live.