POST/api/sandbox/policy/new
Issues a sandbox policy against a plan returned by plan search. EDME-GO generates the traveller identity: the public sandbox never accepts personal data of any kind.
| Field | Type | Required | Notes |
|---|---|---|---|
| plan_id | string | Yes | A plan_id returned by /plans/search. |
| trip | object | Yes | Same shape as plan search. |
| travellers | array of { age: integer } | Yes | Ages only — identity is generated server-side. |
| partner_reference | string | No | Your own booking reference, echoed back on the policy. |
Request
POST /api/sandbox/policy/new
Content-Type: application/json
{
"plan_id": "edme_plan_standard",
"partner_reference": "BKG-88213",
"trip": {
"origin_country": "IN",
"destination_country": "AE",
"start_date": "2026-11-04",
"end_date": "2026-11-14"
},
"travellers": [{ "age": 34 }]
}Response
{
"ok": true,
"mode": "uat_gateway",
"request_id": "req_ab41f0d2",
"data": {
"policy_ref": "pol_sbx_9f42kq",
"edme_insurance_id": "edme_sbx_9f42kq",
"status": "issued",
"plan_id": "edme_plan_standard",
"partner_reference": "BKG-88213",
"travellers_count": 1,
"documents": [{ "type": "policy_certificate", "state": "ready", "format": "pdf" }],
"traveller_identity": "synthetic (generated by EDME-GO)"
},
"meta": { "sandbox": true }
}- Any personal-data field (names, email, phone, passport, date of birth, addresses, nominee details) is rejected with pii_not_allowed.
- policy_ref is an EDME-GO reference scoped to your sandbox session. It is the only identifier you should store.
- Every response uses the EDME envelope: ok, mode, request_id, data or error, and meta (session expiry and fair-use counters).