Sandbox
The sandbox is a full copy of the API that never touches a real payment provider. Use a key that starts with olp_test_.
What behaves differently#
- Business verification is not required. You can build and test before your business is verified.
- Payments never reach a card network. A payment link or QR code created with a sandbox key opens a sandbox confirmation page where you choose the outcome, Succeeded or Failed.
- Webhooks are real. Your endpoint receives the same signed events, so you can test verification, retries and duplicate handling for real.
- Refunds and cancellations work and do not need a second approver.
- Payouts are rejected with
400, because they would move real settlement funds. Test your payout code path against the response shapes and switch to a live key when ready. - Data is separate. Live and sandbox objects never mix.
A test plan#
Run each of these before going live:
- Create a payment link and pay it: you should receive
payment.succeeded. - Create another and fail it: you should receive
payment.failed. - Refund the first payment partly, then fully: you should receive
payment.refundedeach time andstatusshould move topartially_refunded, thenrefunded. - Send the same create request twice with the same
idempotencyKey: you should get the same link back. - Stop your webhook server, trigger an event, start it again: the event should be retried, and your handler must cope with seeing it more than once.
- Send a request with a revoked key: you should get
401. - Send requests fast enough to hit the rate limit and check that you back off.