Production checklist
Verify these items before switching base to https://signal-partners.newunivers.ai/v1 and using a nsp_live_ key. Each item links to its reference.
Licensing and access
- Active license agreement — cover every title, territory, and episode you will serve with an
ACTIVEagreement whoseproduction_api_enabled: trueflag is set (License API). - Production API key — create it with least-privilege scopes only (04, 03).
- Administrative-key isolation — keep
api_keys:writeonly on a vault-held operations key, never on playback or event runtime keys. - Secret storage — put the Production key secret in a secrets manager when it is shown once.
Hardening
- Configure
allowed_origins— every playbackoriginyou send must be registered; token issuance rejects all others. - Configure
allowed_ipswhere applicable — allow the Production server IPs or CIDRs. - Use keys only on the server — never embed them in a browser or mobile app (Security best practices).
Reliability
- Event idempotency — use a stable
event_idper real-world event so retries deduplicate asduplicate_event_id(Event API). - Use
X-NU-Request-Idfor idempotent POSTs that create playback tokens or license requests. Events deduplicate with a stableevent_id. - Handle errors by
error.code— branch on stable codes and exposerequest_idin logs (Error codes). - Handle rate limits — honor
Retry-After, back off with jitter, batch events, and throttle proactively usingX-RateLimit-Remaining(Rate limits).
Playback
viewer_id_hash— SHA-256 with a partner-held salt and no raw PII (Playback API).- Token TTL — reissue on expiry and never cache manifest URLs beyond
expires_at.
Monitoring and operations
- Monitoring and alerts — track error rate, p95 latency, 429 responses, and settlement-reconciliation variance.
- Key rotation plan — document the overlap-and-revoke procedure.
- Settlement reconciliation — compare line-item amounts (
nu_share,partner_share,rights_holder_share) with your own figures and understand the dispute flow (Settlement API).
After every item is checked, switch the base URL and run a Production smoke test: catalog → token → playback → event.