Any qxk_test_… API key targets the sandbox. No real funds move. All providers (Stripe, Bridge, Compose, Monerium) are mocked deterministically.
Base URL & auth
BASE_URL=https://ecmxmvrimionqhpbjguc.supabase.co/functions/v1
AUTH=Authorization: Bearer qxk_test_...
Test cards
| Number | Outcome | Error code |
|---|---|---|
4242 4242 4242 4242 | Success | — |
4000 0000 0000 0002 | Declined | payment_declined |
4000 0000 0000 9995 | Insufficient funds | insufficient_funds |
4000 0025 0000 3155 | 3-D Secure required | — |
4100 0000 0000 0019 | Fraud / AML block | aml_blocked |
4000 0000 0000 0069 | Expired card | invalid_parameter |
Use any future expiry, any 3-digit CVC, any postal code.
Test IBANs & wallets
| Value | Outcome |
|---|---|
DE89 3704 0044 0532 0130 00 | SEPA success |
DE00 0000 0000 0000 0000 99 | SEPA return (R01) |
GB82 WEST 1234 5698 7654 32 | SWIFT success |
0x000000000000000000000000000000000000dEaD | USDC/USDT success (any chain) |
0x0000000000000000000000000000000000000BAD | On-chain revert |
Forcing outcomes
The sandbox endpoint accepts an outcome parameter that overrides any card/IBAN heuristics:
POST /functions/v1/api-v1-sandbox/payments
{
"amount_minor": 1000,
"currency": "USD",
"outcome": "success" | "declined" | "pending" | "refunded" | "chargeback"
}
Advance a payment through its lifecycle without waiting:
POST /functions/v1/api-v1-sandbox/payments/{id}/advance
{ "to": "completed" }
Simulating webhooks
Trigger any event against a registered endpoint on demand:
POST /functions/v1/api-v1-sandbox/webhooks/trigger
{
"endpoint_id": "whe_01HR2X8...",
"event": "payment.completed",
"payment_id": "pay_01HR2X8..."
}
Deliveries are signed with the endpoint's real HMAC secret so your verification code exercises the production path.
Reset
Sandbox data is retained for 30 days. To wipe every payment, ledger entry, and webhook delivery under a test key:
POST /functions/v1/api-v1-sandbox/reset
Never point live traffic at /api-v1-sandbox. It refuses qxk_live_… keys.