Skip to content
  • There are no suggestions because the search field is empty.

Understanding the Sandbox

Learn more about the Authenticate Sandbox

What is the sandbox?

The Authenticate sandbox is an isolated testing environment where you run test verifications, try out features, and validate your integration before going live — without spending real verification credits or affecting your live company account. Third-party vendor checks aren't called in real time; they return mocked responses tied to a fixed set of test identities, so results are predictable and repeatable.

Who should use the sandbox, and why?

Anyone who needs to see how Authenticate behaves before real users and real credits are involved: developers integrating the API (build against predictable responses instead of live data), teams building Medallion™ workflows in the no-code portal, buyers still evaluating (see exactly what a clean result, a criminal record, or a failed match looks like), and operations or support teams training staff. The point is to remove risk from going live — confirm the outcome you expect on a known identity first, then switch to production with confidence.

How does the sandbox work?

The sandbox is a separate company from production, with its own data and its own credit balance, reached through an environment switch inside the production portal — there is no standalone login. Vendor checks return mocked responses mapped to pre-created test users. When your sandbox company is created, Authenticate applies $100 in testing credit automatically (no card required, fixed balance). Sandbox API keys are labeled as sandbox credentials, and an environment badge appears throughout the portal, on PDF reports, and in the Medallion UI. Sandbox data is purged periodically.

What does the sandbox return?

The same result objects as production, but the outcome is determined by which test user you run — not by live data. Each test user maps to one scenario (a clean identity, an identity with a criminal record, an identity that can't be found, and so on). Two rules make test runs pass reliably: OTP codes are always 111111, and for Knowledge-Based Authentication (KBA) you select Option 1 for all five questions.

What is not supported in the sandbox?

Not available: Financial Account Ownership Verification (FAOV), Professional License verification, Know Your Business (KYB), and STR integrations — STR-related checks can only be tested in production. Also unsupported: custom sender email (the sandbox always uses the default Authenticate sender), billing controls (no card, no manual top-up, no auto top-up — only the Authenticate team can add sandbox credit), "send link to phone" in the Medallion flow, and standalone sandbox login. The sandbox works only with the pre-defined test users — any other PII returns unreliable output — and data is purged periodically.