# The Go-Live Checklist — Stripe Payments

Source: https://www.skillbyai.com/en/stripe-payments/p-golive

> Live keys, live webhooks, fraud and tax.

## Switching to live mode

Going live means activating the account (business details, bank account, identity verification), replacing test keys with **live keys** in your production secrets, and creating **live webhook endpoints** with their own signing secrets, because test endpoints do not receive live events. Recreate products and prices in live mode or copy them. Review **Radar**, Stripe's fraud screening, which scores payments by risk; you can add rules, for example to block or review payments based on risk level or failed CVC checks. If you must collect sales tax, VAT or GST, consider **Stripe Tax**, which calculates tax in Checkout, Invoicing and Billing once you add your registrations. Set a clear **statement descriptor** so customers recognise charges.

## Automatic tax in Checkout

Requires Stripe Tax to be set up for your account.

```javascript
const session = await stripe.checkout.sessions.create({
  mode: 'payment',
  line_items: [{ price: 'price_...', quantity: 1 }],
  automatic_tax: { enabled: true },          // Stripe Tax calculates the tax
  billing_address_collection: 'required',    // address helps determine tax location
  success_url: 'https://example.com/success?session_id={CHECKOUT_SESSION_ID}',
  cancel_url: 'https://example.com/cart',
});

```

## Keep test and live configuration separate

Use separate environment variables and deployments for test and live keys, and alert if a production server starts with an sk_test_ key or a staging server with an sk_live_ key.

**Quiz:** After switching to live keys, why do webhooks still not arrive?

- [x] A live-mode webhook endpoint with its own secret has not been created
- [ ] Live mode does not support webhooks
- [ ] Webhooks only work with publishable keys
- [ ] Radar blocks all webhooks

*Answer:* A live-mode webhook endpoint with its own secret has not been created. Test and live endpoints are configured separately.
