Go-live checklist
Go through this list on staging, then again on your live site.
Keys and calls
Section titled “Keys and calls”- The website key comes from your configuration, not your code, and your live site uses its own.
- Every call is made over HTTPS, from your server, or from a browser only on the addresses your live site’s key lists as allowed origins (why).
- No secret key reaches a browser.
Prices and money
Section titled “Prices and money”- Every price a traveller sees comes from the API:
from_priceon cards, and a quote once they choose a date and travellers. Nothing is added up on your side. - Amounts are shown from minor units with the currency’s own decimals: 2 for USD, 3 for OMR, 0 for JPY (money).
- What is paid now (
due_now) and what is paid on the day (pay_locally) are shown apart.
Booking
Section titled “Booking”- The hold’s time left is shown, and
HoldExpiredsends the traveller back to hold again (checkout). - Every refusal a quote, hold or checkout can give has a message of your own (errors).
- The confirmation page shows the booking’s status:
confirmed, orpendingwhile the seller confirms or the payment arrives. - Bank details are shown from the checkout’s answer, never typed into your pages.
After booking
Section titled “After booking”- Your site has a page to manage a booking, and the seller has set its
address, with
{ref}and{token}in it, in the portal under Contact for travellers. The emails and the voucher link there (vouchers). - Travellers can see the refund before they cancel (managing a booking).
- Tokens and travellers’ details stay out of your logs and analytics (personal data).
Content and search engines
Section titled “Content and search engines”- Pages in a language the trip isn’t published in are marked
lang="en"and kept out of search engines for that language (languages). - Old addresses go through
GET /v1/public/redirectbefore your 404 page (SEO). - The sitemap lists the trips and the published pages.
Caching and change
Section titled “Caching and change”- Catalog reads are cached briefly on your server; quotes, holds and bookings never are.
- Your code ignores fields and error codes it doesn’t know (versioning).
- Someone reads the changelog.
Rate limits per key (issue #530) and webhooks (issue #522) are coming; this list will grow with them.