API Key used in the wrong environment
This error happens when the API Key from one environment is used to authenticate calls in the other — either the sandbox key used in production or the production key used in sandbox. The root cause and the fix are practically the same in both cases; what changes is when the problem shows up and the initial symptom.
Sandbox used in production
Occurs when the integration moves to production but keeps the API Key generated in sandbox. The integration usually works normally in testing and fails as soon as it switches environments.
How to identify:
- the integration works in sandbox but fails when moving to production;
- the error started immediately after the environment switch;
- only the URL was changed during the migration;
- it is unclear which environment the API Key came from.
Production used in sandbox
Occurs when the integrator uses a production API Key to authenticate calls in sandbox — usually at the start of the integration, before any call has worked in the test environment.
How to identify:
- authentication fails from the very first calls in sandbox;
- the URL is correct, but the key is not accepted;
- there is only one generic variable for the API Key, with no distinction by environment;
- the integrator cannot tell which environment the key was generated in.
How to fix (in both cases)
- Confirm which URL is being used (sandbox or production).
- Check which environment the API Key was generated in.
- Replace the credential with the correct key for the environment in use.
- Make a simple authenticated call to validate the change.
- Continue with the tests or the main flow after confirmation.
Diagnostic flow
%%{init: {"flowchart": {"nodeSpacing": 18,"rankSpacing": 24,"diagramPadding": 4,"padding": 7
}}}%%
flowchart TD
A["Authentication failure"] --> B{"In which environment does the failure occur?"}
B --> BSandbox(("In sandbox"))
B --> BProducao(("In production"))
BSandbox --> C{"Is the URL in use the sandbox one?"}
BProducao --> D{"Is the URL in use the production one?"}
C --> CSim(("Yes"))
C --> CNao(("No"))
D --> DSim(("Yes"))
D --> DNao(("No"))
CNao --> E["Fix the URL for the sandbox environment"]
DNao --> F["Fix the URL for the production environment"]
CSim --> G{"In which environment was the API Key generated?"}
DSim --> G
G --> GSandbox(("Sandbox"))
G --> GProducao(("Production"))
G --> GDuvida(("Not sure"))
GSandbox --> H["Use the sandbox key"]
GProducao --> I["Use the production key"]
GDuvida --> J["Check the dashboard and identify the key's origin"]
J --> H
J --> I
E --> K["Repeat the test call"]
F --> K
H --> K
I --> K
K --> L{"Authentication validated?"}
L --> LSim(("Yes"))
L --> LNao(("No"))
LSim --> M["Proceed with tests or the main flow"]
LNao --> J
classDef inicio fill:#DBEAFE,stroke:#2563EB,color:#1E3A8A,stroke-width:3px
classDef decisao fill:#FEF3C7,stroke:#D97706,color:#78350F,stroke-width:3px
classDef correcao fill:#FFEDD5,stroke:#EA580C,color:#7C2D12,stroke-width:2px
classDef validacao fill:#E0F2FE,stroke:#0284C7,color:#0C4A6E,stroke-width:2px
classDef sucesso fill:#DCFCE7,stroke:#16A34A,color:#14532D,stroke-width:3px
classDef analise fill:#FEE2E2,stroke:#DC2626,color:#7F1D1D,stroke-width:3px
classDef respostaSim fill:#22C55E,stroke:#15803D,color:#FFFFFF,stroke-width:3px
classDef respostaNao fill:#EF4444,stroke:#B91C1C,color:#FFFFFF,stroke-width:3px
classDef respostaDuvida fill:#8B5CF6,stroke:#6D28D9,color:#FFFFFF,stroke-width:3px
class A inicio
class B,C,D,G,L decisao
class E,F,H,I correcao
class J validacao
class M sucesso
class K analise
class BSandbox,BProducao,CSim,DSim,GSandbox,GProducao,LSim respostaSim
class CNao,DNao,LNao respostaNao
class GDuvida respostaDuvida
linkStyle default stroke:#94A3B8,stroke-width:2px
How to prevent
- use separate environment variables for each credential;
- clearly identify which key belongs to which environment;
- avoid manually copying keys between environments;
- validate the URL and API Key before starting tests or go-live;
- include this check in the initial setup checklist and in the go-live checklist.
Each environment requires its own credential. The API Key from one does not work in the other.
Updated 2 days ago
