Finix runs two full credential sets: sandbox and production are separate API key usernames (US...), API key passwords, Application IDs (AP...), and Merchant IDs (MU...). Never mix them: sandbox keys against the live API fail with auth errors that look like bad credentials, and the reverse fails the same way. Keep both sets stored side by side in your config (sandbox set + live set), and gate on an explicit test-mode flag, not on which key happens to be loaded. When testing webhooks locally, remember the sandbox signing key differs from the live one too, so signature verification config must switch with the environment.