IOSOR Learn

Sandbox traffic must not hit the wallet

A Live key in a test harness is an incident. Detect leaked Live credentials, freeze holds, and rotate before pilot volume.

Sandbox traffic must never open a prepaid hold. If a Live key leaks into a test harness, treat it as an incident — not a clever shortcut to “see real DLR faster” before the pilot week starts.

IOSOR expects test lanes to stay flat on the wallet. A leaked Live credential turns CI into a spend engine: retries, load jobs, and demo scripts all debit as if they were pilot traffic. Stop the leak before you debate why staging “needed” production reach for a screenshot. Keep the incident clock short: every hour of leaked Live CI is prepaid you cannot unspend after rotate.

Detect Live keys in test paths

Scan CI secrets, staging hosts, and local .env files for Live key prefixes on a fixed cadence. Any hit opens an incident ticket: revoke, rotate, and confirm no open hold from the leaked key on the same day.

Include shared runners and forgotten cron containers — they keep old secrets longer than laptops. Publish the scan owner so the ticket does not bounce between developers and fraud ops for a full shift.

Freeze holds spawned by leaked Live traffic

If test jobs already opened holds on the wallet, pause those holds and export the stuck rows with timestamps. Do not let the harness keep retrying into Live debit while you investigate the secret path.

Map each stuck hold to the job id that spawned it. That map is what finance needs when they ask whether the debit was “real pilot” or a leaked key burning through prepaid.

Separate abuse spikes from sandbox mistakes

An abuse spike stops without fake success. A leaked Live key in tests looks similar on the ledger — both need a hard stop. Label the incident so fraud ops and developers do not talk past each other: abuse vs credential leak vs mis-bound staging environment.

Wrong labels burn a day of chat while holds keep aging on the wallet. Put the label on the ticket title before the first status update goes to finance.

Re-prove isolation after rotation

After revoke and rotate, re-run the sandbox OTP proof with the sandbox key only. Export zero hold for that window. Only then restore staging automation and CI secrets that point at sandbox credentials.

If the proof still shows a hold, stop — another Live secret is still in the path. Do not reopen volume until the ledger is flat again and the scan is clean.

Related ops paths

Start with IOSOR

Search every test host for Live keys. Revoke any leak, export open holds, and re-bind CI to sandbox only. Send one sandbox OTP and prove the ledger stayed flat before restarting automation — then keep the scan on the weekly ops checklist.

IOSOR takeaway

A Live key in a test harness is an incident: revoke, freeze holds, re-prove sandbox OTP with a flat ledger, then restore CI. Do not reopen pilot volume while any Live secret still sits on a staging host.

Was this guide helpful?

Related guides