Sandbox Testing

Build and test your integration against the sandbox before you use a live key. Sandbox applications are kept separate from production and no credit bureau is called.

The sandbox server

Send sandbox requests to https://staging.api.ratematch.ai/api/partner/v1 with your rm_sandbox_ key. The API is the same as live, at https://api.ratematch.ai/api/partner/v1 with your rm_live_ key; switching over means changing the base URL and the key. Each key is refused by the other server (WRONG_ENVIRONMENT), so a test can't reach live by mistake.

Simulating credit results

In the sandbox, the credit check (step 5) never calls Equifax. Add X-Sandbox-Score to choose the simulated profile; without it you get mid. An unknown profile is a 400. Live ignores the header.

Credit check with a simulated profile
curl -X POST https://staging.api.ratematch.ai/api/partner/v1/applications/APPLICATION_ID/credit-check \
  -H "Authorization: Bearer rm_sandbox_your_key" \
  -H "X-Sandbox-Score: defaults" \
  -H "Content-Type: application/json" \
  -d '{ "data": { ...applicant details..., "consentCreditCheck": true } }'
X-Sandbox-ScoreSimulated scoreUse it to test
high780Low risk; qualifies for the best offers
mid680Medium risk; qualifies for some offers (the default)
low520High risk; most lenders decline
defaults650Has unpaid defaults on file
bankrupt600Current bankruptcy on file

Same rules as production

  • Every step is validated exactly as in production, so field errors you see in sandbox are real.
  • The credit check still requires the applicant's consent flag.
  • Matching runs on the sandbox's offers, using the simulated credit result.
  • Sandbox data may be reset from time to time; don't rely on an application staying there.
  • Use made-up applicant details in sandbox, never a real person's.