# Quick Start Guide
source: https://developer.mastercard.com/commercial-event-notifications/documentation/quick-start-guide/index.md

## Overview {#overview}

Use this guide to go from account setup to your first successful Sandbox request for Commercial Event Notifications. You will create a project, generate credentials, make a test call, and prepare the same project for Production access.

Tip: If you want the fastest path to a working Sandbox request, start with the [Postman Collections](https://developer.mastercard.com/commercial-event-notifications/documentation/developer-tools/postman-collection/index.md). It lets you test Sandbox and Production flows without writing code first.

<br />

### Before you begin {#before-you-begin}

* Create a [Mastercard Developers](https://developer.mastercard.com/) account.
* Have a secure place to store downloaded OAuth and encryption keys.
* Decide how you want to test: Postman, Insomnia, the reference application, or your own client.
* Have an OAuth 1.0a signing method ready, such as a Mastercard OAuth library or a configured Postman or Insomnia workspace.

### Sandbox checklist {#sandbox-checklist}

| # |      Step      |                                                                                                           What to do                                                                                                            |
|---|----------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | Access         | Get access to Commercial Event Notifications and create your Mastercard Developers project.                                                                                                                                     |
| 2 | Credentials    | Generate your Sandbox OAuth credentials and record your consumer key.                                                                                                                                                           |
| 3 | Environment    | Confirm that you are using the Sandbox base URL and that your project is still in Sandbox mode.                                                                                                                                 |
| 4 | Authentication | Configure OAuth 1.0a signing for the first request and confirm which consumer key and private key pair you will use.                                                                                                            |
| 5 | First call     | Send your first Sandbox request using the Sandbox base URL and OAuth 1.0a signing.                                                                                                                                              |
| 6 | Validation     | Use the sample response and [Integration and Testing](https://developer.mastercard.com/commercial-event-notifications/documentation/integration-and-testing/index.md) page to validate positive, negative, and follow-on flows. |

## Step 1: Get access to the API {#step-1-get-access-to-the-api}

1. Go to [Mastercard Developers](https://developer.mastercard.com/) and create an account.
2. Activate your account by opening the link sent to your email address, and log in.
3. Open your [My Projects](https://developer.mastercard.com/dashboard) page and start a new project. Sandbox access is open, so you can begin testing as soon as your project credentials are generated.

## Step 2: Create a project and generate Sandbox credentials {#step-2-create-a-project-and-generate-sandbox-credentials}

Create a Mastercard Developers project to generate your Sandbox credentials. Sandbox gives you mocked data so you can validate your integration before requesting Production access.

### Project Details {#project-details}

1. Click **Create new project** on your [My Projects](https://developer.mastercard.com/dashboard) page. ![Project Details](https://static.developer.mastercard.com/content/commercial-event-notifications/uploads/project-details.png)
2. Enter a project name.
3. If prompted, indicate whether you are creating the project on behalf of a client.
4. In the **Select at least one API** field, choose **Commercial Event Notifications**.

### Project Credentials {#project-credentials}

5. Create a key alias and keystore password for your OAuth keys, record them securely, and click **Create Project** . ![Oauth](https://static.developer.mastercard.com/content/commercial-event-notifications/uploads/project-cred.png)

### Save the values you will need {#save-the-values-you-will-need}

6. On the project dashboard, record the following values:

* Consumer key and download the PKCS#12 keystore/private key
* Sandbox and Production status
* Authentication client ID

![Project dashboard showing Sandbox and Production status and credentials](https://static.developer.mastercard.com/content/commercial-event-notifications/uploads/summary-mtf.png)

## Step 3: Confirm Sandbox configuration and make your first request {#step-3-confirm-sandbox-configuration-and-make-your-first-request}

Once you have Sandbox credentials, confirm the environment and configuration, then make a simple `Get /fieldmapping` request to verify that your project is set up correctly.

### Sandbox environment and configuration {#sandbox-environment-and-configuration}

* Use the Sandbox base URL for the first call: `https://sandbox.api.mastercard.com/commercial-event-notifications/fieldmappings`.
* Configure OAuth 1.0a signing for every request to this service.

<br />

Before you run the request, make sure you have:

* Your Sandbox consumer key.
* The private key used to sign OAuth requests.
* A Mastercard OAuth library or signer that generates `oauth_timestamp`, `oauth_nonce`, and `oauth_signature`.

This first-call example uses `Get /fieldmapping`, so you can verify access, OAuth signing, and the Sandbox base URL before moving on to encrypted flows.

**Example Request (cURL):**

```bash
curl --request GET \
  --url https://sandbox.api.mastercard.com/commercial-event-notifications/fieldmappings \
  --header 'Authorization: OAuth oauth_consumer_key="YOUR_CONSUMER_KEY",oauth_nonce="a1b2c3d4e5f6",oauth_signature_method="RSA-SHA256",oauth_timestamp="1709596800",oauth_version="1.0",oauth_signature="YOUR_COMPUTED_SIGNATURE"' \
```

> This example shows the required OAuth 1.0a header fields explicitly, but uses placeholders for sensitive values.
> Replace `YOUR_CONSUMER_KEY` with the consumer key from your project and generate `oauth_signature` with a Mastercard OAuth library. The library also handles `oauth_timestamp` and `oauth_nonce` for you.

**Expected Response:**

```json
[
   {
      "id": "2F96BA577A68B9F4E06368459E0AE0C0",
      "name": "issuerGuid",
      "displayName": "Issuer Guid",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577A69B9F4E06368459E0AE0C0",
      "name": "corpGuid",
      "displayName": "Corp Guid",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577A6BB9F4E06368459E0AE0C0",
      "name": "processor.isMatched",
      "displayName": "Processor IsMatched",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577A73B9F4E06368459E0AE0C0",
      "name": "realPaymentCard.accountGuid",
      "displayName": "Real Payment Card Account Guid",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577A74B9F4E06368459E0AE0C0",
      "name": "virtualPaymentCard.number",
      "displayName": "Virtual Payment Card Number",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577A76B9F4E06368459E0AE0C0",
      "name": "virtualPaymentCard.accountGuid",
      "displayName": "Virtual Payment Card Account Guid",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577A7DB9F4E06368459E0AE0C0",
      "name": "acceptor.merchantCategoryCode",
      "displayName": "Acceptor Merchant Category Code",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577AA0B9F4E06368459E0AE0C0",
      "name": "clearing.type",
      "displayName": "Clearing Type",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   },
   {
      "id": "2F96BA577AA6B9F4E06368459E0AE0C0",
      "name": "fundingSource.fundingSourceGuid",
      "displayName": "Funding Source Guid",
      "subjectType": "BPC_CLEARING",
      "contentType": "TEXT"
   }
]
```

### What success looks like {#what-success-looks-like}

* The request returns `200 OK`.
* The response body includes an array with at least one event field mapping record.
* Each returned record includes an `id`, `name`, `displayName`, `subjectType`, and `contentType`.

## Step 4: Choose how you want to test and integrate {#step-4-choose-how-you-want-to-test-and-integrate}

After the first Sandbox request succeeds, pick the integration path that matches your workflow:

* **Postman or Insomnia:** Use the [Postman Collection](https://developer.mastercard.com/commercial-event-notifications/documentation/developer-tools/postman-collection/index.md) or [Insomnia Collection](https://developer.mastercard.com/commercial-event-notifications/documentation/developer-tools/index.md#3-insomnia) page for setup.
* **Reference Application:** Use the [Reference Application](https://developer.mastercard.com/commercial-event-notifications/documentation/developer-tools/reference_application_tutorial/index.md) page.
* **curl or a custom client:** Use the [Integration and Testing](https://developer.mastercard.com/commercial-event-notifications/documentation/integration-and-testing/index.md) page for test cases and additional examples.

## Step 5: Promote the same project to Production {#step-5-promote-the-same-project-to-production}

Once your project is working in Sandbox, request Production access for that same project.

### Transition your project from Sandbox to Production {#transition-your-project-from-sandbox-to-production}

1. **Open your project in Mastercard Developers**
   Go to your [My Projects](https://developer.mastercard.com/dashboard) page and open the Commercial Event Notifications project you used for Sandbox testing.

2. **Provide commercial countries for your project**
   In the project dashboard, select the commercial countries where you intend to use the service. This information is required for Mastercard to process your Production access request.

3. **Request Production access for that project**
   In the project dashboard, select **Request Production Access** . Your Sandbox and Production statuses are shown separately on the project page, so you can track when Production moves from `Not Requested` to an enabled `Ready` state.

4. **Generate or download your Production keys**
   After Production access is approved, download the Production OAuth and encryption keys for the same project. Keep the Production key material separate from your Sandbox keys.

5. **Update your application configuration**
   Switch the base URL from Sandbox to Production:

   * Sandbox: `https://sandbox.api.mastercard.com/commercial-event-notifications/`
   * Production: `https://api.mastercard.com/commercial-event-notifications/`

   Update your application to use the Production consumer key, signing key, and encryption certificates.

Note: OAuth 1.0a authentication and JWE payload encryption work the same way in Sandbox and Production. The main changes are the Production key set, the Production approval state, and the Production base URL.

If you need the full onboarding process, including contract, MTF, SLA, and escalation details, see the [Onboarding Checklist](https://developer.mastercard.com/commercial-event-notifications/documentation/onboarding-checklist/index.md).

## Next Steps {#next-steps}

Continue with the documentation that matches your next task:

* [API Reference](https://developer.mastercard.com/commercial-event-notifications/documentation/parameters/index.md) for endpoint details.
* [API Basics](https://developer.mastercard.com/commercial-event-notifications/documentation/api-basics/index.md) for authentication, encryption, and client configuration.
* [Integration and Testing](https://developer.mastercard.com/commercial-event-notifications/documentation/integration-and-testing/index.md) for additional request scenarios.
* If you run into issues, visit [Support](https://developer.mastercard.com/commercial-event-notifications/documentation/support/index.md) for FAQs and troubleshooting guidance.
