# Sandbox & live

One API, two environments. `https://api.fluense.social` serves both; the credential decides which environment a request touches.

| | Sandbox | Live |
| --- | --- | --- |
| API keys | `fl_test_…` | `fl_live_…` |
| Money | test funds only | real money |
| Merchant gate | none | KYB approved |
| Consumer gate | none | KYC approved + a banking partner for the country |

## How the environment is resolved

- **API key requests**: from the key prefix — `fl_test_` routes to sandbox, `fl_live_` to live.
- **Session requests**: resolved at sign-in. A session becomes live only when the identity is verified (KYC for consumers, KYB for businesses) **and** a live banking partner is connected for the jurisdiction. Otherwise it is sandbox.
- `GET /auth/live-eligibility?org_id=` returns `{eligible, blockers}` so the console can explain what is missing.
- `POST /auth/mode {env, org_id?}` re-evaluates the rule and returns a fresh session token.

## Isolation

Environment-scoped data includes checkouts, charges, cashback, wallets, sales and social content. Identity (users, orgs, members, follows) is global. A key or session can never cross the boundary: a sandbox key calling live data gets `403 key env mismatch`.

## Going live

1. Complete **KYB** for the organization: `POST /compliance/kyb/start {org_id, country_code}` returns a hosted verification URL.
2. Wait for approval — capture in live requires an approved KYB.
3. Issue a `fl_live_` API key from the console.
4. Consumers must complete KYC and their country needs a live banking partner; the US uses ACH today, and more countries follow as partners come online.
