TL;DR: Keep both sets stored side by side in your config (sandbox set + live set), and gate on an explicit test-mode flag, not on which key happens to be loaded. Finix runs two full credential sets: sandbox and production are separate API key usernames (US...), API key passwords, Application IDs (AP...), and Merchant IDs (MU...).

## Fix
1. Keep both sets stored side by side in your config (sandbox set + live set), and gate on an explicit test-mode flag, not on which key happens to be loaded.
   Expected: this specific failure stops.
2. When testing webhooks locally, remember the sandbox signing key differs from the live one too, so signature verification config must switch with the environment.
   Expected: the request routes instead of erroring.

## Details
Finix runs two full credential sets: sandbox and production are separate API key usernames (US...), API key passwords, Application IDs (AP...), and Merchant IDs (MU...). Never mix them: sandbox keys against the live API fail with auth errors that look like bad credentials, and the reverse fails the same way.

## When to use
You hit exactly this: Finix sandbox and live credentials are fully separate sets; store both, gate on test mode in Finix.

## When not to use
A different error, or the same symptom in a different tool. This page only covers the failure above.

## Compatibility
Finix.