Sandbox mode lets you test the Limitguard API without calling real data sources, making USDC payments, or spending a prepaid balance.
How to Activate
Sandbox mode is decided by the key, never by a header: a request is a sandbox request when its X-API-Key is a sandbox key (lg_sandbox_...).
- Create a free sandbox key. No wallet, no payment:
- Send it on any endpoint:
There is no sandbox header. An X-Limitguard-Mode: sandbox header is ignored, so a request that sends it with a live key is a normal, paid call. Keys starting with lg_test_ are refused in production with 401 Test keys not accepted in production.
POST /v1/reports/entity (and the MCP get_compliance_report tool) refuses sandbox keys with 403: reports are built only from real checks.
Sandbox Behavior
Mock Data Examples
/v1/entity/check (sandbox)
The signal echoes the entity_name you sent. sandbox: true marks every mock response.
/v1/risk/score (sandbox)
Rate Limit Response
When the sandbox rate limit is exceeded:
The response includes a Retry-After: 60 header.
Use Cases
Middleware Execution Order
Sandbox detection runs before x402 payment verification, so a sandbox request never reaches the payment check and is never charged.
Transitioning to Production
When ready to use real data, replace the lg_sandbox_ key with an lg_live_ key from the dashboard or POST /v1/keys/create, or pay per call with x402.
No other code changes required. The same endpoints, request format, and response structure apply in both modes.