Sandbox
Break things safely.
The sandbox works exactly like live TujuPay, but with test banks and no real money. Use it to try every path your customers might take before you go live.
◷ Sandbox opens to waitlist developers first. Live keys follow once TujuPay is licensed.
How the sandbox differs from live
- Keys
- sk_test_ and whsec_ test secrets. Live keys never work here
- Money
- None. Payments, refunds and payouts are simulated
- Banks
- Test banks that return the result you choose
- Payouts
- Run every 10 minutes instead of once a working day
- Data
- Kept for 90 days, then cleared
Test banks
At sandbox checkout, choose one of these banks to get a specific outcome.
- ✓
Test Bank ApproveThe payment succeeds straight away - ✕
Test Bank DeclineThe bank declines the payment - ✕
Test Bank InsufficientDeclined for insufficient funds - ◷
Test Bank SlowStays processing for 2 minutes, then succeeds - ◷
Test Bank TimeoutThe customer leaves at the bank page; the payment expires
Test DuitNow QR
Sandbox QR codes cannot be paid with a real banking app. Instead, open the payment in the dashboard and press Simulate scan, or call the simulate endpoint.
curl
curl https://api.tujupay.com/v1/test/payments/pay_3Kx9LmQ2/simulate_scan \ -u sk_test_51HxQ2...: \ -d outcome=succeeded
Trigger test webhooks
Every sandbox action sends real webhooks to your endpoint. You can also send any event type on demand from the dashboard, which is handy for testing payout.held and other rare events.
curl
curl https://api.tujupay.com/v1/test/webhook_events \ -u sk_test_51HxQ2...: \ -d type=payout.held
Limits
- Up to 25 requests per second per account.
- Test payments up to RM 50,000 each.
- Sandbox and live data are completely separate.
Moving to live
- Run through every test bank and confirm your code handles each result.
- Check your webhook endpoint rejects bad signatures.
- Swap test keys for live keys and point your webhook to production.