# Go-live checklist

Everything to confirm before production traffic.

> **In a nutshell:** Production token in a secret store, verified callbacks, references on every send, retries in a queue, and connection problems visible to your support team.

## Credentials

- [ ] A **production** token, separate from staging, with only the abilities you use.
- [ ] The token lives in your server's secret store or environment - never in a browser, app, repository or log.
- [ ] Your app calls [`GET /me`](/docs/api/get-me) at startup and fails if an ability is missing.

## Callbacks

- [ ] The production callback URL is HTTPS and registered by a PaalChat operator.
- [ ] Every callback's signature is verified on the raw body; old timestamps are rejected.
- [ ] Deliveries are de-duplicated on `X-PaalChat-Delivery`.
- [ ] The endpoint answers `2xx` within 10 seconds and queues slow work.

## Sending

- [ ] Every send has a `reference` from your own database.
- [ ] Sends run in a background queue with backoff on `429` and `5xx`.
- [ ] `outside_service_window` falls back to a template.
- [ ] Message statuses are applied only forward.

## Customers

- [ ] Connect links go only to the customer's administrator.
- [ ] Your UI shows the connection state and `health.last_error`, and offers "Reconnect".
- [ ] Admins are told to add a payment method in WhatsApp Manager.
- [ ] `message.received` content is stored under your retention and access rules.
- [ ] PaalTech has registered the origins of every `return_url` you use for connect links.

## Operations

- [ ] Alerts for `whatsapp.connection` `revoked` / `setup_failed` / `suspended` / `disconnected` / `token_expiring`.
- [ ] A support view of each customer's WhatsApp health (see [Connection health](/docs/use-cases/connection-health)).
- [ ] A plan to rotate the token and callback secret.
