Developer documentation

Test and Live environments

Test and Live share one contract and stay isolated by credential, OAuth audience, data scope, and MCP endpoint.

Test

Use Test for integration work, configurable IP fixtures, policy simulation, and synthetic claims. Test is persistent but bounded: original encrypted requests remain for up to 7 days, activity for up to 30 days, and redacted security events for up to 90 days. Once-ever Test eligibility becomes available again after retained claim activity expires. Test credentials cannot read or write Live data. The remote MCP endpoint is /mcp/test.

Long-history scenarios

Test cannot reproduce retained 90–365-day real history. Use simulations for those scenarios. Active configuration does not expire by age, and encrypted backup copies can take up to 7 additional days to age out.

Copy Test setup to Live

In Live organization settings, check compatibility before copying. Veltor copies benefits, current custom policies, registered custom identifiers, and unexpired exceptions only when the whole setup can be copied without conflicts. Download a plain-text report if any conflict needs attention. After a clean check, confirm the copy; either every item is committed or none is. You can return to this option later, even after Live has activity.

Clear or reset Test

Clear Test activity removes Test activity, analytics, imports and their files, and exports while keeping setup and credentials. Reset Test environment also removes customer-created Test setup, server keys, connections, and browser settings before restoring the built-in presets and fixtures. Both keep the Test PUBLISHABLE KEY unchanged and leave Live untouched. Live has no reset action.

Live

Use Live only for real customer traffic after Test and canary verification pass. Live credentials cannot read or write Test data. The remote MCP endpoint is /mcp/live.

Mirrored permissions

Scope names mean the same thing in both environments. Test fixture scopes are the only exception and are unavailable in Live. Never infer an environment from a request field; the credential or MCP URL is authoritative.