# Support and go-live checklist

Before production launch, confirm with Percents that:

- production source IPs are allowlisted;
- production API and signing tokens are stored securely;
- the issuer is correctly provisioned;
- Omni catalog access and the agreed file format are enabled;
- the webhook HTTPS endpoint is reachable and signature verification is active;
- duplicate webhook delivery is handled idempotently;
- a Plaid sandbox file has passed through the schema validation webhook; and
- catalog synchronization preserves offer UUIDs and offer immutability.


## Escalating missing validation results

The Plaid validation webhook is generated after Percents detects and downloads the uploaded object. If it does not arrive, contact Percents with the environment, exact filename, upload timestamp and time zone, and issuer name. Do not include secrets or raw card data in an ordinary support message.