Skip to main content
POST
cURL
Use this public endpoint to get a sandbox key before creating a live credential. The sandbox provides example responses for documented operations, so you can build your client without production data. Send no request body. The response includes the sandbox URLs and the URLs for obtaining live access.

Key response fields

Nothing is stored. The key cannot be listed or revoked, it does not expire, and every call returns a different one. Register again whenever you want a new key.

Example

Then send data.api_key as an Authorization: Bearer header to sandbox.first_request_url.

What it does not do

  • Reach production data. The live API answers a sandbox key with 401, error.code invalid_api_key, and error.reason sandbox_api_key.
  • Require the key on the sandbox. The key is optional there: a well-formed key gets an X-Oxi-Sandbox-Key: valid response header, and a malformed one gets the same 401 production would give.
  • Read a request body. Send nothing.
  • Issue a live key. That needs an account with an active Pro or Max subscription, and then either an oxi_sk_live_ key or an OAuth access token. Every URL for both paths is in live_access.

Headers

X-Query-Validation
enum<string>

Opt into strict query-name validation. The default is compatible: unknown names are ignored and reported in X-Query-Ignored. With strict, an unknown name returns 400 bad_request with error.reason unknown_query_parameter before the handler runs, including when its percent escape is incomplete.

Available options:
strict

Response

A new sandbox key. Every call returns a different key, with Cache-Control: private, no-store.

object
string
required
Allowed value: "agent_registration"
data
object
required

A sandbox key and the path to live access (#13959). Nothing is stored: the key cannot be listed or revoked and does not expire. Register again for a new one.

meta
object
required