Sandbox

Deterministic test environment with fake cards, IBANs, and on-demand webhook events.

Any qxk_test_… API key targets the sandbox. No real funds move. All providers (Stripe, Bridge, Compose, Monerium) are mocked deterministically.

Base URL & auth

BASE_URL=https://ecmxmvrimionqhpbjguc.supabase.co/functions/v1
AUTH=Authorization: Bearer qxk_test_...

Test cards

NumberOutcomeError code
4242 4242 4242 4242Success—
4000 0000 0000 0002Declinedpayment_declined
4000 0000 0000 9995Insufficient fundsinsufficient_funds
4000 0025 0000 31553-D Secure required—
4100 0000 0000 0019Fraud / AML blockaml_blocked
4000 0000 0000 0069Expired cardinvalid_parameter

Use any future expiry, any 3-digit CVC, any postal code.

Test IBANs & wallets

ValueOutcome
DE89 3704 0044 0532 0130 00SEPA success
DE00 0000 0000 0000 0000 99SEPA return (R01)
GB82 WEST 1234 5698 7654 32SWIFT success
0x000000000000000000000000000000000000dEaDUSDC/USDT success (any chain)
0x0000000000000000000000000000000000000BADOn-chain revert

Forcing outcomes

The sandbox endpoint accepts an outcome parameter that overrides any card/IBAN heuristics:

POST /functions/v1/api-v1-sandbox/payments
{
  "amount_minor": 1000,
  "currency": "USD",
  "outcome": "success" | "declined" | "pending" | "refunded" | "chargeback"
}

Advance a payment through its lifecycle without waiting:

POST /functions/v1/api-v1-sandbox/payments/{id}/advance
{ "to": "completed" }

Simulating webhooks

Trigger any event against a registered endpoint on demand:

POST /functions/v1/api-v1-sandbox/webhooks/trigger
{
  "endpoint_id": "whe_01HR2X8...",
  "event": "payment.completed",
  "payment_id": "pay_01HR2X8..."
}

Deliveries are signed with the endpoint's real HMAC secret so your verification code exercises the production path.

Reset

Sandbox data is retained for 30 days. To wipe every payment, ledger entry, and webhook delivery under a test key:

POST /functions/v1/api-v1-sandbox/reset

Never point live traffic at /api-v1-sandbox. It refuses qxk_live_… keys.