From requirement to production
Every CA API integration runs through the same eight stages. Two of them are checkpoints: we agree the scope in writing before you build, and we review your Sandbox integration before you go live. Everything else is you building, with our Developer Support team alongside you.
The eight stages
The chip on each stage shows who drives it.
- 1
Raise your integration requirement
You + CAYou tell Corporate Alliance that you want to integrate the API. Your Account Manager takes ownership of the request and stays your single point of contact for everything commercial throughout the integration.
What you get: A named Account Manager owning your integration.
- 2
Read the documentation
YouWork through the guides for your API surface before anything else. The goal at this stage is not to write code — it is to understand what the platform already does, so you can map your business requirements onto capabilities that exist today.
Keep a list of the questions that come up as you read. They become the agenda for the kickoff meeting in Stage 4.
Client API guides · Program Manager API guides
What you get: A clear view of which capabilities match your requirements.
- 3
Complete the requirements sheet
YouMost of the API is part of every integration, so the sheet is short. It confirms your account structure, captures what we need to open your Sandbox, and collects the questions you want answered at kickoff.
- Your account structure — for Client integrations, whether you need Sub Accounts and which on-behalf-of flows.
- The Sandbox Portal user — first name, last name, and email address.
- The developer email that will receive your API credentials.
- Any questions you want covered at the kickoff meeting.
Fill it in yourself or ask your Account Manager to do it with you, then email it back.
Open the requirements formWhat you get: An agreed scope of work, in writing.
- 4
API integration kickoff meeting
You + CACA hosts a kickoff call once your requirements sheet is in. We walk through the scope you submitted, answer the questions you collected while reading the documentation, and introduce the Developer Support engineers who will support you through the build.
What you get: Scope confirmed, and named Developer Support contacts.
- 5
Sandbox provisioning
CAAfter the kickoff, CA opens your Sandbox. The named user receives access to the Sandbox Portal, and your API credentials are issued to the developer email from your requirements sheet. Sandbox is a full copy of the platform where no real money moves.
Quick Start: your first API callWhat you get: Sandbox Portal access, plus your Sandbox apiUser and apiKey.
- 6
Build and test your integration
YouBuild against the agreed scope and run your own internal testing in Sandbox. Developer Support is available throughout — the engineers introduced at kickoff are there for anything the documentation does not answer.
What you get: An integration that passes your internal testing.
- 7
CA Sandbox review
CATell us when your internal testing is complete. CA then reviews your integration in Sandbox against the requirements sheet — confirming that the flows you scoped have actually been exercised, and that the integration is built to a standard we are comfortable moving into production.
What you get: Sandbox sign-off from CA.
- 8
Production credentials and go-live
You + CAOnce the Sandbox review is signed off, we release your production credentials. The request must reach us by email from your Company Admin, who must be an authorised user on your CA account. CA then issues the production apiUser and apiKey to that Company Admin.
Only the base URL changes between environments — your Sandbox integration works unchanged against production.
What you get: Production credentials, issued to your Company Admin.
Where your credentials are sent
Sandbox and production credentials deliberately go to different people. Plan for the handover before you reach go-live.
Sandbox
To your developer email
The developer email you name on the requirements sheet receives the Sandbox apiUser and apiKey. It cannot be changed afterwards, so we recommend a shared team inbox rather than one person’s address.
Production
To your Company Admin
Production credentials are issued only to the Company Admin who requested them, and only if that person is an authorised user on your CA account. They are never sent to the developer email.
Your engineering team will not receive the production credentials directly. The Company Admin passes them on under your own internal key-handling process — decide who does that, and how, before go-live.
Ready to scope your integration?
Once you have read the guides for your API surface, record what you need on the requirements sheet and send it to your Account Manager.