Testing and launch
End-to-end verification of your integration before going live.
Authorization and identity
Verify accepted and denied consent, incorrect state, incorrect redirect, expired code and repeated exchange. Connect two local users to two Pura accounts and ensure one cannot use the other’s store. For confidential clients ensure the secret never appears in the browser.
Refresh across workers
Expire the access token and send concurrent requests from two app instances. A single valid rotation must be saved and every worker must read the new tokens. Simulate a database error and verify rollback and lock release.
Webhook delivery
Send a console test and verify delivered status beyond the queued response. Replay the same event, alter signature and timestamp, simulate rollback and sequence reordering. Invalid events must never reach the store; committed duplicates must receive 2xx.
Production launch
Use production redirects and secrets, a persistent secret store, refresh/error/webhook metrics and disconnection procedures. Confirm the SDK version and available services. Model mappings stay in Pura environment variables; do not put models or providers in the host app.