What belongs in the Vault
Depending on the provider, a profile can contain merchant IDs, API keys, signing keys, public keys, callback endpoints, permitted domains, and enabled checkout modes. AvraAPI encrypts the credential material and returns only safe, public checkout data to your backend.Configure a profile
From the AvraAPI project or Workspace UPG control centre:- Select the project with an active UPG slot.
- Choose a gateway included in the Workspace plan.
- Add either its Sandbox or Production configuration.
- Enter the provider callback, return, and permitted-domain details.
- Validate and activate the profile.
- Use the SDK
availability()call from your backend to confirm that it is usable.
Environment priority
When both production and sandbox profiles are active for a gateway, AvraAPI chooses Production by default. A trusted server-side SDK override can request a specific environment for a controlled test. Browser code cannot choose an environment.
If a requested environment has no eligible active profile, AvraAPI fails safely. It does not silently switch to another profile.
A Vault profile is not a payment method
An active profile may still be unavailable when its project has no active UPG slot, the Workspace plan does not include that gateway, the project is paused, or its configured domain is not permitted. Useavailability() before showing checkout UI.
See Project Slots and Quick Setup.