Keep environments separate
Use sandbox credentials only with sandbox endpoints and live credentials only after controlled production approval.
PayPal merchant configuration
Connect the right merchant app to the right environment, then prove the complete payment lifecycle.
PayPal REST applications issue a Client ID and Secret for sandbox or live use. CMS Max stores the configured client secret as a protected setting, but a production launch still requires a completed PayPal implementation, controlled testing, provider approval, and merchant acceptance.
Operating model
Treat the app, environment, secret, checkout flow, provider account, and merchant operation as one controlled system.
Use sandbox credentials only with sandbox endpoints and live credentials only after controlled production approval.
Never place the secret in public HTML, client-side code, tickets, chat, or unapproved messages. Restrict access and document rotation.
Prove approval, cancellation, capture, duplicate prevention, notification handling, refund, support lookup, and reconciliation.
Current CMS Max capability
The current application includes PayPal enablement, Client ID, and encrypted Client Secret settings. Merchant-specific checkout behavior must still be verified in the accepted implementation.
Use the merchant PayPal Developer Dashboard to create and own the application used by the website.
Exercise customer approval and server operations without creating real financial transactions.
Switch only through controlled change after account readiness, implementation acceptance, and owner sign-off.
CMS Max treats the PayPal Client Secret as encrypted configuration; operational access and rotation still matter.
Confirm the current tenant implementation creates, approves, captures, and records PayPal orders as scoped.
Map refunds, disputes, settlement, notifications, customer support, and accounting to named owners.
Step-by-step workflow
A saved Client ID and Secret do not prove that money, order state, and customer communication remain synchronized.
Sign in to the merchant PayPal Developer Dashboard and create a clearly named REST application.
Start in Sandbox and identify the matching test business and buyer accounts.
Copy the Client ID and reveal the Secret only for the approved secure configuration path.
Save matching credentials in CMS Max and exercise representative success and failure cases.
Create or select the live app, change credentials under control, run a small live test, reverse it, and verify settlement.
Practical reference
PayPal dashboard labels and product approval requirements can change. The merchant dashboard and current PayPal documentation are authoritative.


Current references
Interfaces, policies, plans, services, pricing, and requirements can change. Verify the current CMS Max configuration and official provider sources during implementation.
How to Retrieve PayPal API Credentials FAQ
Turn each answer into configuration, representative testing, monitoring, ownership, and a documented recovery path.
The Client ID identifies the app and may appear in approved client configuration. The Client Secret is private and must remain server-side and access-controlled.
No. Sandbox simulates PayPal behavior with test accounts. Production uses separate live credentials and endpoints.
No. Confirm the accepted CMS Max implementation, customer approval, server processing, final order state, notifications, refunds, and reconciliation.
The current CMS Max form payment model supports the configured card provider family and Paya ACH. Do not promise PayPal for forms without a separately completed implementation.
Use the approved secure onboarding or credential-management path. Do not send it in normal email, public forms, content, or chat.
Build for real operations
CMS Max can help map the merchant app, checkout implementation, testing, support, refund, and reconciliation requirements.
The world's fastest and most SEO friendly website code.