Skip to content
Developers

Access & limits

The public sandbox needs no signup, no API key and no personal data. Production integrations use partner credentials issued during onboarding.

Sandbox sessions

On your first sandbox call, EDME-GO issues an anonymous session and returns it as an HttpOnly cookie. The session lasts 60 minutes. Every reference you create belongs to that session, and references from other sessions are never resolvable.

Create a session explicitly

POST /api/sandbox/session

{
  "ok": true,
  "mode": "uat_gateway",
  "data": {
    "session_ref": "sbx_4f21ba90",
    "expires_at": "2026-11-01T11:02:19Z",
    "limits": { "requests": 30, "window_minutes": 10, "session_minutes": 60 }
  }
}

Fair use

30 requests per 10 minutes, per session and per network. Remaining allowance is returned on every response in meta.rate_limit. Exceeding it returns HTTP 429 with the rate_limited error code.

Response envelope

Envelope

{
  "ok": true,
  "mode": "uat_gateway",       // or "simulation"
  "request_id": "req_5f2a9c11",
  "data": { /* operation payload */ },
  "meta": {
    "sandbox": true,
    "session_expires_at": "2026-11-01T11:02:19Z",
    "rate_limit": { "limit": 30, "remaining": 28, "reset_at": "2026-11-01T10:12:00Z" }
  }
}

mode tells you what produced the response: uat_gateway when EDME-GO reached a test insurer environment on your behalf, simulation when deterministic sandbox data was returned. The contract is identical either way.

Production access

Production uses partner-specific credentials, a signed webhook secret and agreed servicing ownership. Nothing in the sandbox carries over: sandbox references, plans and documents are test artefacts only.