The workspace
1
Create the live workspace
Same check and settings as the test one: the workspace type, the minimum age on age workspaces, whether expired documents are accepted and whether one face may verify under several of your users.
2
Add a payment method
Live verifications beyond the free trial need a payment method on the account; without one, creating a verification fails with
402 PAYMENT_METHOD_REQUIRED. See Pricing.3
Set the URLs
The webhook URL of your production handler, over HTTPS, and a redirect URL of your own. A new workspace’s redirect URL is a ProofAge page.
4
Swap the keys
Put the live public key and a live secret key into your production configuration. Copy the live secret key from the console into your secrets manager; for live workspaces it is never returned by the API or the MCP server.
Your integration
- Verifications are created on your backend, signed, with
external_idset to your user’s ID. - The Browser SDK uses the live public key, or the person is redirected to the verification
url. - The page the person returns to does not assume an outcome: it waits for the webhook or reads the status.
- The webhook handler verifies the signature and the timestamp, and rejects anything else with
401. - It handles
approved,declined,resubmission_requested,review,abandonedandexpired. - It answers
2xxquickly and processes in the background. - It skips a delivery ID it has already processed.
- Unknown decision reasons fall back to a generic message.
- Error handling reads all four error shapes, or you use a server SDK.
After the switch
- Run one real verification end to end on the live workspace and check the webhook arrived.
- Look at the workspace’s webhook deliveries in the console for failed attempts during the first days.
- Keep the test workspace for development; its keys never create billable verifications.