Sandbox Testing
How to test the Poptin API safely using a dedicated subaccount, API key, Try It, and read-only calls first.
Poptin does not currently provide an isolated sandbox environment. The Poptin API has one environment: live. Every call you make hits https://api.popt.in/v1 and operates on real data in the account tied to your API key. This page explains how to explore the API safely under that constraint.
Recommended setup
Before you start experimenting, put three pieces in place:
- Use a dedicated test account or subaccount. If your organization has a subaccount you can dedicate to development, create your key there. Keep production accounts out of your test loop.
- Create a dedicated, revocable API key. In the Poptin app, go to My Account → API & Connections → API Keys and generate a fresh key. It starts with
pk_live_and is shown only once at creation - copy it immediately. When testing is done, revoke it. - Prefer the Try It explorer in the API Reference. Paste your key into the Authentication panel and run calls directly from the docs. Never commit keys to source control or paste them into client-side code.
What "live" means
Because there is no sandbox, writes have real consequences on the account you're authenticated against:
- Contacts can be created, updated, merged, or deleted.
- Custom properties you add persist on the account and appear in the app.
- Campaigns can be started, paused, or modified.
- Template emails you send are delivered to real inboxes and count against your sending reputation.
- Bulk jobs (imports, mass deletes, mass sends) run asynchronously and cannot be undone once started.
- Poptin configuration changes are reflected on live sites that embed those poptins.
Assume anything you do through the API is visible to your teammates and - for email and poptin changes - to your end users.
Safe practices
Follow these habits while you're learning the surface area:
- Start read-only. Exercise
listandretrieveoperations before anycreate,update, ordelete. - Avoid destructive experiments on production lists. Do not test imports, mass deletes, or mass sends against a real contact list - use a small, disposable list in a test account.
- Send email only to addresses you own. Template email sends bill against your account and affect deliverability.
- Respect rate limits. If you hit a
429, back off and retry with exponential delay. See Rate Limits for quotas and headers. - Rotate and revoke. When you finish a session or hand off a project, revoke keys you no longer need.
Next steps
Updated about 1 month ago
