# Sandbox

The sandbox lets you run a full integration without creating real bookings. It is not a separate URL. It is a property of your credential.

## How it works

- Highstar Travel marks a credential as test. You ask your account manager for one. See [Support](/developers/guides/support).
- You use the same base URL, the same endpoints and the same request format as in production.
- You cannot switch test mode on or off from a request. The `X-Test-Mode` header is ignored.
- Reads are real. Catalogs, searches and prices return real data, because asking for a price books nothing.
- Only the write calls change: confirmations and cancellations.
- Rate limits are the same as in production.
- If you are not sure that a credential is a test credential, ask before you send a confirmation. On a production credential every confirmation is a real booking.

A response from a test credential carries `"test_mode": true` on confirmations and cancellations. Errors have the same shape as in production and do not include `test_mode`.

## What each product does in test mode

| Product | Confirmation | Cancellation | Voucher |
|---|---|---|---|
| Transfers | Runs every real validation, including the price check. The booking is not created. You get an `id_order`. You can cancel that booking and download its voucher. | Cancels the test booking. | `GET /transfer/pdf` returns a PDF marked as a test. |
| Hotels | Runs the real validations. The supplier is not asked to book. You get a test `id_orden`. | Cancels the test booking without calling the supplier. | `pdf_voucher` is not returned in the confirmation. |
| Universal | Creates an order, marked as a test. No ticket is issued with the supplier. Ticket identifiers start with `TEST`. | Simulated, on a test order. | The voucher is generated with the test identifiers. |
| Disney | The booking is made for real in the supplier's test environment. It issues no tickets and charges nothing. The lead name gets the prefix `[TEST]`. | Runs against the same test environment. | `GET /disney/pdf` can answer `409` for a while because the test environment is slower. Retry. |

### Transfers

The booking is built as if it were real and then discarded, so every check that applies in production applies here too: capacity, lead time, blocked dates, passenger data and `total_amount`. A test credential never sees a production order, and a production credential never sees a test order.

- `transferConfirm` returns `test_mode: true` and a `pdf_voucher` that points to `GET /api/v1/transfer/pdf?order_id=...`. That URL needs your Bearer credential.
- `transferCancelation` works on the test order. An order from another account, an unknown order, or one already cancelled gives the same `400` as in production.
- `GET /transfer/pdf` returns `410` for a test order that was cancelled.
- `external_reference` is ignored, so you can repeat the same request.

### Hotels

After `bookingConfirm` you can follow the whole post-sale flow with the test `id_orden`:

1. `bookingDetail` returns the booking with `status: confirmed` and `test_mode: true`.
2. `bookingHcn` returns `hcn_status: available` with a made-up confirmation number for each room.
3. `bookingCancelation` cancels it. After that, `bookingDetail` returns `status: cancelled`, and a second cancellation returns `400 No active reservation found.`.

An `id_orden` that is neither a test order nor yours returns `404`. A test credential cannot cancel real bookings.

### Universal

`id_order` is a real order in the test credential's account. What is fake is the ticket. Repeating a confirmation with the same `external_reference` returns the same order, as in production.

### Disney

Because the test environment belongs to the supplier, it depends on their availability. A test booking can fail for reasons that do not happen in production, such as a slow voucher.

## What the sandbox does not do

- You cannot force a supplier failure on demand. Test your retry and backoff logic with your own tooling.
- There are no webhooks to test.

## Before you go to production

Ask your account manager to move you to production. The code, the URLs and the requests stay the same. The credential is what changes: a production credential makes real bookings.

## Next

- [Quickstart](/developers/guides/quickstart) shows a full test booking.
- [Errors](/developers/guides/errors) explains how to read a failed call.
