Graduation

Live keys are issued by Teddoh Ops after graduation. This action does not mint a live secret.

  1. Build against sandbox until the quickstart, webhooks, and idempotency checks pass.
  2. Run teddoh test --endpoint against your webhook URL with TEDDOH_WEBHOOK_SECRET. A bad signature must return 401. The same event id sent twice must ack with duplicate true, or the header x-teddoh-dedup: duplicate. An ack over 3000 ms is a warning. Add --marketplace if you must ack app.uninstalled with tokensRevoked true. A pass does not mint a live key.
  3. Ask Teddoh Ops for graduation. Sandbox self-serve does not approve live access.
  4. Ops provisions pk_live_ and shows it once. This portal does not mint it.
  5. Staging keys use the pk_staging_ prefix. Live keys use pk_live_.

Step 2 stays blocked until this checklist is complete. Submitting it does not call your webhook and does not mint a key.

A verified review also needs the partner security attestation.

Graduation · Teddoh