> ## Documentation Index
> Fetch the complete documentation index at: https://docs.avraapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Gateway Vault

> Set up gateway profiles safely so your SDK can create checkout sessions without handling provider secrets.

The Gateway Vault is the project-level control centre for payment-gateway configuration. A Workspace owner or an authorized project member configures a gateway profile in AvraAPI. Your application then uses its AvraAPI SDK credential only—it never needs the gateway secret itself.

## What belongs in the Vault

Depending on the provider, a profile can contain merchant IDs, API keys, signing keys, public keys, callback endpoints, permitted domains, and enabled checkout modes. AvraAPI encrypts the credential material and returns only safe, public checkout data to your backend.

<Warning>
  Do not copy a gateway secret into your application `.env` file simply because the same project is using UPG. The provider secrets belong in the Gateway Vault, not in application code, browser code, logs, or support tickets.
</Warning>

## Configure a profile

From the AvraAPI project or Workspace UPG control centre:

1. Select the project with an active UPG slot.
2. Choose a gateway included in the Workspace plan.
3. Add either its Sandbox or Production configuration.
4. Enter the provider callback, return, and permitted-domain details.
5. Validate and activate the profile.
6. Use the SDK `availability()` call from your backend to confirm that it is usable.

## Environment priority

When both production and sandbox profiles are active for a gateway, AvraAPI chooses Production by default. A trusted server-side SDK override can request a specific environment for a controlled test. Browser code cannot choose an environment.

| Choice | When to use it |
| - | - |
| Production default | Your live merchant checkout is ready to take real payments |
| Explicit Sandbox override | Controlled development or provider test flows |
| Explicit configured method | Your backend deliberately offers a specific supported gateway and mode |

If a requested environment has no eligible active profile, AvraAPI fails safely. It does not silently switch to another profile.

## A Vault profile is not a payment method

An active profile may still be unavailable when its project has no active UPG slot, the Workspace plan does not include that gateway, the project is paused, or its configured domain is not permitted. Use `availability()` before showing checkout UI.

See [Project Slots](/universal-payment-gateway/project-slots) and [Quick Setup](/universal-payment-gateway/quick-setup).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.