Sandbox
Sandbox credentials exercise the normal gateway and provider path against recorded fixtures. They do not call a live provider or consume live provider credentials.
The credential selects sandbox mode
Use the same host, paths, request schemas, and response schemas as live traffic.
A successful response carries dataSource = SANDBOX. That field is the response-side discriminator; never treat a sandbox result as a live conclusion.
Send the normal Authorization header. Do not add a sandbox query parameter or change the endpoint path.
Recorded requests only
The sandbox covers one synchronous address-screening request, one synchronous transaction-screening request, and one asynchronous address-batch lifecycle. Screening requests carry chain in the body. Job-result pagination sends cursor and receives nextCursor.
Use the issued fixture catalog
A recording is keyed by provider, capability, chain, subject, and the request fields that affect the provider call.
A single request with no matching recording returns 404 SANDBOX_ADDRESS_NOT_FOUND. Repeating it unchanged does not help.
Address-batch replay keys the complete request and address combination. If the combination is not recorded, the whole accepted batch fails and every accepted address carries SCREENING_JOB_ITEM_ERROR_REASON_SANDBOX_NOT_FOUND. Recorded single addresses do not compose into a recorded batch.