Sandbox & environments
| Sandbox | Agency deployment | |
|---|---|---|
| Base URL | https://dev.ironbrick.us/sandbox/<api>/v1 | https://<agency-gateway>/<api>/v1 |
| Data | Synthetic examples from the specifications. No personal data. | Your systems of record |
| Identity | Iron Brick sandbox OAuth | Agency IdP (PIV/CAC, Login.gov, Okta, Entra ID) |
| Writes | Validated and acknowledged, not stored | Persisted with audit |
| Limits | By plan, see Plans | Set by the agency gateway |
The sandbox enforces the same authentication, scopes, required headers (If-Match on updates), JSON validation, and quotas as production, so client code moves over unchanged. Do not send real personal information to the sandbox.