Going live
Everything you built against the sandbox runs unchanged with a live key. What changes is what the key can do, and what must be true before it exists.
1. The organisation
- Onboarding is complete in the Yona app and the organisation’s tax number is verified.
- Live access has been requested from the app and approved. Until it is, a live key is refused with
BIZ006.
2. The tax connection
- Your business has selected Elyonar as its access point on the authority’s taxpayer portal, and the Yona app shows the connection as connected.
- Your crypto key is installed. Without it, Yona cannot sign invoices as your business.
GET /i/v1/tax-connectionreports the state.
3. The key
- A
sk_live_key exists, created from a session with a second factor, with the smallest preset that covers what your integration does. - The key lives in your server’s environment, not in code or in a client.
- You know how to rotate it, and the grace period your deployment needs.
4. Credits
- The plan grants enough credits for your monthly volume; see Credits and billing.
- A low-balance threshold is set in the app, and someone will act on it.
- Your code treats
402withBIZ001as “stop and top up”, not as a failure to retry.
5. The code
- It handles
409withBIZ201andBIZ004(the invoice is not in a state for this) by reading the invoice instead of retrying. - It honours
Retry-Afteron429. - It sends an
Idempotency-Keywhere an operation accepts one, and never retries a submission blindly. - It logs
meta.requestIdfrom every error. - It handles the rejection path (reopen, correct, submit again) and the parked path (retry, or renumber on a number clash). Both were exercised on the sandbox.
- It polls
GET /i/v1/invoices/{id}/statusonly for invoices it is waiting on, or it uses webhooks.
6. Webhooks
- If you use them: a live endpoint exists (sandbox endpoints only receive sandbox events), it verifies
Yona-Signature, answers within seconds, and deduplicates onYona-Event-Id. See Webhooks.
The switch
Replace the key. Issue one small invoice to a buyer you control, watch it reach reported, download the PDF, and record its payment. Then open the flow to everyone.
Common mistakes
- Reusing a sandbox buyer id with a live key. Sandbox and live data are separate; create the buyer again.
- Creating the live key from a session without a second factor and reading the
403as a permissions bug. - Submitting before the crypto key is installed; the submission parks with
connection_required. - Treating a
parkedsubmission as failed. Parked runs resume.