Skip to main content

Move to production

Who does this: the Secretariat approves; your technical contact and integration engineer do the rest.

Production is not a switch. It is an approval, followed by setting up a second, entirely separate certificate and credential.

ITS calls this environment Production, and the Environments page names it that way. The approval message calls it live access. They are the same thing.

Four checkpoints, and what each one does not mean

Each of these is easy to mistake for the next. Reading this once saves asking for something you already have, or assuming you have something you do not.

CheckpointWhat it does not mean
You are certifiedIt does not approve production access. It only says the four sandbox checks were seen.
Production access approvedIt does not create anything: no certificate, no credential, no secret.
Production certificate acceptedIt does not create your production credential. That is a separate action you take.
Production credential createdIt does not prove a production call will succeed. The final check does that.

Get production access approved

The Secretariat checks that all four sandbox checks are complete and the organisation's records are in order, then approves. You will get a message whose subject names your organisation: your organisation is cleared to go live on the AfCFTA Integrated Transit System. It contains no secret and creates nothing.

If the sandbox record is incomplete, the approval does not happen and should not be asked for. Finish Pass the four checks first. Creating production credentials early does not speed anything up; it leaves an unused credential to look after.

Register your production certificate

Issue a new certificate for production. Do not reuse the sandbox one, and do not reuse its private key. They are separate so that a problem in practice cannot reach real trade.

  1. Upload the production public certificate, selecting the production environment.
  2. Check the fingerprint and the validity dates afterwards.
  3. Confirm it is different from your sandbox certificate.

If it is refused, fix that certificate. The six reasons in Prepare the sandbox connection apply unchanged. Do not create the production credential until the certificate is accepted.

Create your production credential

  1. Create the production credential.
  2. Store the secret before closing the dialog. As with the sandbox one, it is shown once.
  3. Confirm the organisation now reads as LIVE.

If the secret is lost, rotate the credential. Nobody can look it up for you — not the Secretariat, not support. The stored details describe the credential; they do not contain the secret.

Where ITS should send you messages

If your system will receive messages about declarations moving, ITS needs an address to send them to, and that address has to be approved before anything is sent to it.

  1. Declare the address of your receiving service.
  2. Ask the Secretariat to approve it.
  3. Wait until it shows as approved.

If it is declared but not yet approved, nothing will be sent there. That is correct behaviour, not a fault — do not plan a cutover around an address that has not been approved. Receiving announcements explains what ITS will call.

The final check

Make one agreed call through the production gateway, using the production certificate, the production credential and the production gateway host from the Environments page. Confirm all three are the production ones and not left over from the sandbox.

It worked when the call succeeds and the Secretariat sees the same organisation reading as LIVE.

If it fails, write down exactly what happened, then check the production certificate, the production credential and the receiving address separately — one at a time, not all at once. Report the symptom, never a secret, a token or a private key.