Graduation
Live keys are issued by Teddoh Ops after graduation. This action does not mint a live secret.
- Build against sandbox until the quickstart, webhooks, and idempotency checks pass.
- Run teddoh test --endpoint against your webhook URL with TEDDOH_WEBHOOK_SECRET. A bad signature must return 401. The same event id sent twice must ack with duplicate true, or the header x-teddoh-dedup: duplicate. An ack over 3000 ms is a warning. Add --marketplace if you must ack app.uninstalled with tokensRevoked true. A pass does not mint a live key.
- Ask Teddoh Ops for graduation. Sandbox self-serve does not approve live access.
- Ops provisions pk_live_ and shows it once. This portal does not mint it.
- Staging keys use the pk_staging_ prefix. Live keys use pk_live_.
A verified review also needs the partner security attestation.