Developer platform
Sandbox Keys
Create scoped sandbox API keys, control one-time secret custody, review allowlists, and export audit evidence.
Developer workspace
APPROVEDSandbox credential workspace
Scoped key creation, IP allowlists, secret reveal, owner acknowledgement, and audit evidence stay visible before production access changes.
Live workload
How this works
The sandbox key journey keeps request, scope review, one-time reveal, and custody evidence in one auditable sequence.
- 1
Request key
Capture the application, owner, environment, scopes, and expected network allowlist before creation.
- 2
Validate access
Review least-privilege scopes, sandbox-only rail use, owner contact, and callback readiness.
- 3
Reveal secret once
Show the key once, require secure storage acknowledgement, and mask it after the custody step.
- 4
Record outcome
Attach request ID, actor, scope, allowlist, and timestamp to the audit drawer and export.
Key request
Capture scope and custody details before changing sandbox credentials or access review state.
One-time secret
Sandbox API keys are shown once, then masked after the developer confirms secure storage.
pm_sandbox_sk_7f3...92aAudit drawer
Actor, role, application, scope, IP allowlist, request ID, decision, outcome, and timestamp attach to every key action.
Sandbox key inventory
Sandbox keys, webhook tests, SDK handoffs, rate limits, and rotation actions are filtered from one custody queue.
| Reference | API asset or event | Status | Scope | Next action |
|---|---|---|---|---|
| School fees integration Sandbox application | APPROVED | checkout.write, webhooks.write | Secret shown once | |
| Municipal rates sandbox Awaiting owner approval | PENDING | biller.read | Review allowlist | |
| Payroll test client Scope rejected | FAILED | payouts.write requested | Reduce scope | |
| bill.created test HTTP 401 | OVERDUE | Signature mismatch | Rotate signing label | |
| Node SDK download v1.4.2 | PAID | Hosted checkout | Checksum ready |