Testing#
Use a sk_test_ key against https://manage.test.casapay.com. Test-mode sessions never touch EveryPay and never move money.
The simulator#
Instead of a card form, a test-mode checkout shows a panel of outcome buttons. Pick one and the session behaves exactly as it would in production for that outcome - including the webhooks you receive.
Scenarios#
| Scenario | Result |
|---|---|
payment_success | Payment settles. Invoice booked and paid, gateway.session.completed fires. |
payment_failed | Generic failure. Session stays open, gateway.payment.failed fires. |
payment_timeout | Provider timeout. Soft error, retryable. |
payment_bank_declined | Bank declined the payment. Soft error, retryable. |
payment_insufficient_funds | Not enough funds. Soft error, retryable. |
payment_customer_cancelled | Tenant cancelled at the bank. Soft error, retryable. |
payment_3ds_failed | 3-D Secure challenge failed. Soft error, retryable. |
verification_success | Identity verification passes; session advances to payment. |
verification_failed | Verification fails, gateway.verification.failed fires. |
Soft errors keep the session alive
Every scenario except payment_success leaves the session usable so the tenant can retry on the same URL. This is the behaviour you should build against - a failed attempt is not a dead session.
What to test#
| Case | Why |
|---|---|
| Duplicate webhook for one payment | Success is reported twice - on the browser return and the S2S webhook. Your handler must be idempotent. |
| Tenant closes the tab after paying | Your success_url never loads. Only the webhook tells you it succeeded. |
| Retry after a soft failure | Confirms you are not prematurely marking the session dead. |
| Cancel an already-paid session | Must return 400 CANCEL_FAILED. |
Deposit choice both ways | total_amount differs between cash and guaranteed. |
Going live#
- Swap the key for
sk_live_and the base URL forhttps://manage.casapay.com. - Register a live webhook endpoint - test-mode endpoints do not receive live events.
- Verify signatures with the live endpoint secret.
- Confirm your payout bank account is configured, or collected funds cannot be disbursed.