Skip to main content

Test and live keys

Every project has two environments. Build in test; your users use live.

TestLive
Keyslt_pk_test_…, lt_sk_test_…lt_pk_live_…, lt_sk_live_…
Opens onlocalhost (any port), and the sites on your Test listOnly the https sites on your Live list
BilledNeverYes
A mistyped optionStops the editor with options_invalid, so you find it nowDropped with a config:adjusted warning; the editor still opens
Release candidatesOpenNever open

Designs made with test keys and live keys live side by side in the same project: they are kept by the same end-user ids.

Making live keys​

lettrove.com → Settings → Embed → your project → Keys. Under Live, click New publishable key and New secret key. The secret key is shown once: put it straight into your production server's environment.

The go-live checklist​

  • Live keys made; the live secret key is in your production server's environment, not in code or a repository.
  • Your production site is on the Live list (Settings → Embed → Sites), as an origin: https://app.acme.com.
  • Your token route is behind your login, uses each person's own id, and answers with Cache-Control: no-store.
  • Your page uses the live publishable key, and its Content-Security-Policy allows frame-src https://lettrove-embed.com.
  • You keep each designId with your own record, so people can reopen their work.
  • Errors are handled: you show or log the editor's error event and createEditor's rejection, and your server handles LettroveApiError codes.
  • Webhooks (if you use them) point at your production endpoint, with its own signing secret.
  • Your branding is set (Settings → Embed → Branding), if you want your name and logo in the bar.
  • You chose a release policy: follow 1 (the default) or pin (release: '1.2').
  • Erasure is wired into your own account deletion: lettrove.users.erase(userId).
  • Opened the editor once on your production site with the live key, made a design, exported it.