Sandbox
Build against a sandbox organization first. It is a normal Lojiq organization that places no real calls and sends no real texts, so you can exercise every endpoint, every webhook and every error without risk.
Status
Sandbox organizations are provisioned by Lojiq on request while self-serve sandbox creation is being built. Write to support@lojiq.ai with your organization name and the email of the Owner/Admin who should hold the sandbox keys. The behaviour described below is the target for the sandbox; the section What is true today says what is already in place.
How the sandbox works#
| Area | Sandbox behaviour |
|---|---|
| Host | Same host, https://api.lojiq.ai/v1. The key decides the organization, so there is nothing else to switch. |
| Keys | Created the same way, in the sandbox organization's Developer → API keys, and recognisable at a glance: they start with lojiq_test_. They cannot read or write anything outside the sandbox organization. GET /account answers sandbox: true and key_mode: "test", so your code can refuse to run against the wrong organization. |
| Leads, campaigns, webhooks | Fully functional. Create leads, import CSVs, start and pause campaigns, subscribe webhooks — all real data, confined to the sandbox. |
| Calls and texts | The sandbox organization has no carrier numbers and voice is suspended: POST /calls and POST /agents/{id}/calls answer 403 voice_suspended (or 409 no_did_available), GET /account reports voice_calls_allowed: false, and campaigns that are started place no calls. Nobody is ever dialed from a sandbox. |
| Webhooks | Deliver for real to your endpoint (lead.*, appointment.* as you create and cancel appointments, billing.low_balance if you trigger it). Call events cannot occur because no calls run. |
| Rate limits | Same defaults (60/min per key). |
| Billing | Nothing is charged. API requests are free everywhere; calls and texts cannot start. |
| Data | Yours to fill and wipe. Sandbox data is not retained beyond 90 days of inactivity. |
Suggested test plan#
- Auth:
GET /with the key →200; without →401 missing_api_key; with a key missingleads:write→403 insufficient_scopeonPOST /leads. - Leads: create, create again (expect
200, same id), patchstatus, list byphone_number, export CSV. - Bulk:
inspect-csvon a file with messy headers; import with the suggested mapping; check the counts; import again (everything becomesupdated). - Webhooks: subscribe a test endpoint, verify the signature, return
500on purpose and watchX-Lojiq-Delivery-Attemptclimb through the retry schedule, then return204and seeconsecutive_failuresreset inGET /webhooks. - Rate limit: fire 60+ requests in a minute and confirm your client honours
Retry-After. - Calls (negative path):
POST /agents/{id}/calls→403 voice_suspended; make sure your code treats it as "do not retry".
Going to production#
Create a key in your real organization with the same scopes, swap the key, and re-run steps 1 and 4. Nothing else changes.
What is true today#
- Keys are organization-bound and cannot cross organizations — that part is how the API works, not a sandbox feature.
- A sandbox is an ordinary organization flagged as a development organization, with voice suspended and no numbers; Lojiq creates it for you on request. Its keys are
lojiq_test_…andGET /accountreportssandbox: true. - Managed-agent dry runs (jobs that produce a synthetic outcome without touching a carrier) are part of the Managed Agents plan and do not exist yet.