---
title: "Configure live Stripe keys"
method: POST
path: "/api/apps/{app_id}/payments/stripe/configure-live-keys"
---

# Configure live Stripe keys

`POST /api/apps/{app_id}/payments/stripe/configure-live-keys`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Switches the app to live mode using live Stripe keys you already have from the Stripe dashboard, sent directly in the request body, rather than keys Base44 creates for you. Use [Provision live Stripe keys](/api-reference/provision-live-stripe-keys) instead to have Base44 create them automatically once the sandbox's Stripe account is activated.

Stores the keys, backs up the current test credentials, and redeploys backend functions with the updated secrets.

Key prefixes are checked, but success does not verify that the keys belong to the same Stripe account or can process payments.

Automatic webhook migration is best effort.

Requires write access to the app. Workspace viewers cannot call this operation.

## Path parameters

- `app_id` string, required — ID of the Base44 app.

## Request body

- ConfigureLiveKeysRequest — Request to configure live mode API keys.
  - `publishable_key` string, required — Live Stripe publishable key beginning with `pk_live_`.
  - `secret_key` string, required — Live Stripe secret or restricted key beginning with `sk_live_` or `rk_live_`.
  - `webhook_secret` string, nullable — Live webhook signing secret beginning with `whsec_`. Defaults to `null`, which attempts automatic migration when an existing webhook secret is present.

## Response `200`

The operation result.

- StripeLiveKeysResult — The result of storing live Stripe credentials.
  - `success` boolean, required — Whether live keys were stored and the app was switched to live mode.
  - `message` string, required — Human-readable configuration result.
  - `live_keys_configured` boolean, required — Whether the stored completion flag was confirmed. It can be `false` even after keys were stored if finalization failed.
  - `webhook_migrated` boolean, required — Whether this call automatically migrated the webhook. It is `false` when a webhook secret was supplied directly.

## Other responses

- `400` — A key has an invalid prefix.
- `401` — Missing or invalid credentials.
- `403` — The credential is not permitted or you don't have the required app access. A missing app also fails the app access check.
- `404` — No Stripe sandbox exists or the app is outside the credential grant.
- `409` — The workspace requires an unlocked SSO session.
- `422` — The body is missing, `publishable_key` or `secret_key` is missing, or a value doesn't match its field's type.

## Changes

> 18 revisions in range; 1 not diffed.

- **2026-09-16** `ca10c5ce328c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/payments/stripe/configure-live-keys/post.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/28fc82924122?raw)
