> ## Documentation Index
> Fetch the complete documentation index at: https://developer.suki.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Wrong Staging vs Production Endpoints

> Align Partner Tokens, REST and WebSocket hosts, and SDK iframe origins to one environment

Many auth, streaming, and blank-iframe failures come from mixing environments: staging credentials on production hosts, or a production CSP that only allows the staging SDK origin.

Pick **one** environment per build. Align Partner Token, REST base URL, WebSocket host, SDK `environment`, and CSP `frame-src` to that environment.

## Hosts by environment

### Partner API REST and WebSocket

Use the **same base host** for REST and WebSocket in that environment. Your partnership team confirms which host and credentials apply.

| Environment | REST | WebSocket |
| :- | :- | :- |
| Staging | `https://sdp.suki-stage.com` | `wss://sdp.suki-stage.com` |
| Production | `https://sdp.suki.ai` | `wss://sdp.suki.ai` |

### Hosted SDK iframe origins (CSP `frame-src`)

Form filling and other hosted iframe SDKs load UI from Suki's SDK host. If CSP blocks that origin, the iframe never loads.

| Environment | Add to `frame-src` |
| :- | :- |
| Staging | `https://sdk.suki-stage.com` |
| Production | `https://sdk.suki.ai` |

<Note>
  SDK config uses `environment: "staging"` or `"production"` on `SukiAuthManager` and related clients. That value must match Partner ID, Partner Token, template IDs, and CSP host. Template IDs differ between staging and production.
</Note>

## Common causes

* REST, WebSocket, and SDK hosts come from different environment configs.
* Partner Token or Partner ID is for staging, but calls go to `sdp.suki.ai` (or the reverse).
* CSP allows only `https://sdk.suki.ai` while the app targets staging (`https://sdk.suki-stage.com`), or the reverse.
* Form filling `environment` is `staging` but form template IDs are production UUIDs (or the reverse).

## Fix

<Steps>
  <Step title="Choose One Environment per Build">
    Use staging for development unless you intentionally ship production. Keep URLs and credentials together in config.
  </Step>

  <Step title="Align Token, Partner ID, and API Host">
    Get the Partner Token for that environment. Call Register and Login on the matching REST host. Send the returned `sdp_suki_token` only to that same host.
  </Step>

  <Step title="Align the WebSocket Host">
    Open WebSockets on the matching `wss://` host (same base as REST).
  </Step>

  <Step title="Align SDK Environment and CSP">
    Set SDK `environment` to `staging` or `production`. Allow the matching origin in CSP `frame-src`. Redeploy or refresh the policy, then hard-reload.
  </Step>
</Steps>

<Warning>
  Environment mix-ups often look like bad credentials or a blank iframe. Check host, token, `partnerId` / `partner_id`, and CSP together before you rotate secrets.
</Warning>

## Next steps

<Icon icon="file-lines" iconType="solid" /> **[Streaming architecture](/documentation/how-to/audio-streaming/streaming-architecture)** - Same REST and WebSocket base host per environment

<Icon icon="file-lines" iconType="solid" /> **[Form filling SDK error handling](/form-filling-sdk/guides/error-handling)** - CSP hosts and partner credential checks

<Icon icon="file-lines" iconType="solid" /> **[CSP blocks the SDK iframe](/documentation/troubleshooting/csp-blocks-sdk-iframe)** - Allow the correct `frame-src` origin

<Icon icon="file-lines" iconType="solid" /> **[401 Unauthorized or invalid Partner Token](/documentation/troubleshooting/invalid-partner-token-401)** - Token validation vs wrong-host symptoms

<Icon icon="file-lines" iconType="solid" /> **[InvalidPartnerDetails during sign-in or registration](/documentation/troubleshooting/invalid-partner-details)** - SDK credential and environment mismatches
