Developer platform

Sandbox Keys

Create scoped sandbox API keys, control one-time secret custody, review allowlists, and export audit evidence.

Developer workspace

APPROVED

Sandbox credential workspace

Scoped key creation, IP allowlists, secret reveal, owner acknowledgement, and audit evidence stay visible before production access changes.

Live workload

4Active API keysScoped
18Webhook retriesSigned
v1Stable API versionCurrent
OnlineSandbox rail stateMonitored

How this works

The sandbox key journey keeps request, scope review, one-time reveal, and custody evidence in one auditable sequence.

  1. 1

    Request key

    Capture the application, owner, environment, scopes, and expected network allowlist before creation.

  2. 2

    Validate access

    Review least-privilege scopes, sandbox-only rail use, owner contact, and callback readiness.

  3. 3

    Reveal secret once

    Show the key once, require secure storage acknowledgement, and mask it after the custody step.

  4. 4

    Record outcome

    Attach request ID, actor, scope, allowlist, and timestamp to the audit drawer and export.

Key request

Capture scope and custody details before changing sandbox credentials or access review state.

One-time secret

Sandbox API keys are shown once, then masked after the developer confirms secure storage.

pm_sandbox_sk_7f3...92a

Audit drawer

Actor, role, application, scope, IP allowlist, request ID, decision, outcome, and timestamp attach to every key action.

Sandbox key inventory

Sandbox keys, webhook tests, SDK handoffs, rate limits, and rotation actions are filtered from one custody queue.

Sandbox key inventory with references, API assets, statuses, scopes, and next actions
ReferenceAPI asset or eventStatusScopeNext action
School fees integration
Sandbox application
APPROVEDcheckout.write, webhooks.writeSecret shown once
Municipal rates sandbox
Awaiting owner approval
PENDINGbiller.readReview allowlist
Payroll test client
Scope rejected
FAILEDpayouts.write requestedReduce scope
bill.created test
HTTP 401
OVERDUESignature mismatchRotate signing label
Node SDK download
v1.4.2
PAIDHosted checkoutChecksum ready