Create a test order, pay it with a test card, and see the webhook arrive at your server. About ten minutes.
You need an Inkress organisation. Create one and you get test keys straight away. Test mode never moves real money.
1Get your test key
Open API keys in the portal. Your test secret key starts with sk_test_. Keep it on your server; never put it in a browser or an app.
With the Node SDK, pass mode: "sandbox" so requests go to the test API. Test keys don't work on the live API.
2Create an order
Send the sample request. reference_id, kind, total and customer.email are required. The response carries payment_urls.payment_url.
3Pay it with a test card
Open the payment_url and pay with a test card. Every card payment goes through 3-D Secure; the approved test card passes it without a prompt.
Card number
What happens
4012 0000 0002 0071
Visa. Approved without a prompt.
4012 0000 0002 0006
Visa. The bank asks for a password: enter 3ds2.
4012 0000 0002 0121
Visa. Authentication fails, so the payment is declined.
Use any future expiry date and any three-digit CVV.
4Receive the webhook
Add an endpoint under Webhooks for orders.paid. Check the X-Inkress-Webhook-Signature header before you trust the body; Verify signatures shows how.
Don't mark an order paid because the customer came back to your return_url. Customers close tabs and redirects can be faked; the webhook is the record.