Legal
Terms of service
Short sections, plain English, and no claim about the service that is not true of the code. If something here reads as vague where it matters to you, write to us and we will tighten it.
Effective 2026-09-12Last updated 2026-09-12team@sandboxapis.dev
Who we are
SandboxAPIs is operated by Driftwork LLC, a company registered in Arizona, United States (“we”, “us”). These terms are the agreement between Driftwork LLC and you, and they apply whenever you use sandboxapis.dev, any sandbox host we serve, or our MCP server.
Reach a human at team@sandboxapis.dev. For coverage requests, bugs and anything about the data set, the feedback form gets to the same place and needs no account.
What the service is
We serve read-only, API-compatible replicas of developer tools’ APIs, preloaded with one simulated data set. The paths, JSON shapes, headers and status codes are built to match the real providers so that adopting us is a base-URL change in your own client.
Nothing real is connected. There is no tenant of yours behind our hosts, no credential of yours in play, and no data of any real person or company in the responses — the organization, people, repositories, tickets and conversations you read are generated. You cannot reach your own systems through us, and we cannot reach them either.
It is read-only. Every write — a REST write verb, a GraphQL mutation — is refused in the shape the provider you are imitating would use, and the refusal says so. There is no endpoint here that changes anything, on any plan.
It is a beta, and Free, Founding and Solo carry no uptime commitment. We run it carefully and we will tell you when something is wrong, but there is no SLA on the self-serve plans and no credit scheme. Scale and Enterprise terms — including anything about availability, support response or data handling — exist only where we have agreed them with you in writing, and a written agreement overrides this page for that customer.
Accounts and API keys
An account is one person and one mailbox; sign-in is passwordless, by a link and a six-digit code sent to that address. Keep your keys secret — anyone holding one can spend your allowance. You can create and revoke keys from your dashboard, and a revoked key stops lifting limits immediately.
We never see the key itself after we show it to you. We store a one-way hash of it, plus a display prefix and its last four characters so you can tell your keys apart, and we recognize a key by re-hashing what you present and matching the hash.
Do not send us real third-party credentials. Our hosts accept whatever token your client sends, in whatever slot that provider’s convention uses — that is what makes an existing client work unchanged. Accepting a token is not recognizing one: only a key we issued lifts your rate limit, and anything else is treated as an anonymous request. A real GitHub token pointed at our GitHub host is a secret you have sent somewhere it does not belong, so point your test config at a throwaway value or at one of our keys.
Rate limits and fair use
The limits are published on /pricing and explained in the keys and limits docs: anonymous access at 60 req/hour per address, a free key at 600 req/hour, and more on the paid rungs. Anonymous access stays open without a key. Those pages are the current figures; we may change them, and we will not change them silently.
Using the service means agreeing not to:
- work around a rate limit — rotating keys or addresses to multiply an allowance, or sharing one key across a user base;
- scan or enumerate the service or the data set wholesale: crawling our hosts for everything they hold, probing for endpoints we do not serve at volume, or scraping the universe to republish it;
- resell access, or put our responses behind a service that sells them as its own sandbox;
- attack the service or the people using it — load that degrades it for others, attempts to reach another account’s data, or anything aimed at our control plane rather than at the sandbox.
If your legitimate use needs more headroom than a published plan gives, ask us. We would rather raise a limit than argue about one.
The founding offer
The first 1,000 accounts get a founding key: standard rate limits (currently 6,000 req/hour), free for one year from your first API call. The year starts at your first API call, not at signup, so a claimed key that has never been used has not started its clock.
At expiry the key falls back to the free limits of the day — it keeps working, and is never revoked.
It is not a trial with a card behind it. Nothing is collected to claim a founding slot, there is no automatic charge at the end of the year, and the fallback is the free limits rather than an invoice. Slots are one per mailbox — sub-addressed and dotted spellings of one inbox count as one person.
Paid plans
Solo is $5/month, or $50/year, taken through Stripe Checkout. Payment details go to Stripe and never to us; what we keep is described on /privacy.
You can cancel anytime, you keep access to the end of the paid period, and we do not give refunds. Cancel from the billing portal, reachable as “Manage billing” on your dashboard — the same place you change a plan or update a card. Cancelling stops the next renewal; the plan you have already paid for runs to the end of its period. When it ends, your keys keep working at the free limits. We do not revoke a key for non-payment and we do not start returning 401s at you: a downgrade is a limit change.
If a renewal payment fails, your key keeps working at the paid limits while Stripe retries. It drops to the free limits when Stripe gives up on the subscription.
We may change prices. Existing subscribers get notice before a change affects a renewal, and you can cancel instead. Scale and Enterprise are priced and invoiced by agreement; the numbers on /pricing are what we intend to charge, and what we serve at those rungs is what we have agreed in writing.
The simulated data set
The generated universe — its organization, people, repositories, issues, pull requests, messages and metrics — is ours. You may use the responses you get freely: in your tests, fixtures, CI, demos, tutorials, evaluation harnesses and products. You do not need our permission to keep a recorded response in your repository, and we ask nothing in return.
What you may not do is take the data set as a whole and ship it as a competing corpus: bulk-extract the universe to redistribute it, or resell it as your own sandbox. The line we care about is wholesale copying, not use.
We are independent, and nobody here endorses us. Provider names, logos and API names belong to their owners. GitHub, Atlassian, Slack, Salesforce, HubSpot, Zendesk, PagerDuty, Sentry, OpenAI, Anthropic and every other provider we mirror are trademarks of their respective owners; we are not affiliated with, sponsored by, or endorsed by any of them. We use their names only to say which API a host is compatible with, which is what those names are for. The full list of what we mirror is on /providers.
Acceptable use
Do not use the service to break the law, to attack anyone, or to build something that does. Do not use it to stage fraud — a sandbox response dressed up as a real provider’s record is a forgery, and that is on you, not on us. Do not attempt to identify, contact or impersonate other users of the service. We can suspend access that is doing any of this, and where we have a choice we will write to you first.
Availability and changes to the service
Coverage is published and it moves. What we serve is recorded in the coverage manifest behind /coverage, endpoint by endpoint. Anything not covered answers with an explicit, provider-shaped error that names the manifest — we do not invent a plausible response, and we do not return a silent null. We add coverage continuously, so the manifest is the current answer and this page is not.
When a provider retires an endpoint, our live hosts retire it too. A live host then refuses it the way the provider does. Pinned snapshots frozen before that date keep serving it, because a pin’s whole purpose is that its bytes never change — which is what makes a pin the right target for a test you need to still pass next year.
We may change, add or withdraw hosts, endpoints, snapshots and plans. We may take the service down for maintenance. On the self-serve plans none of that comes with notice we have promised you, which is the honest description of a beta; a written agreement can and does change that.
Disclaimer and limitation of liability
The service is provided as is, without warranties of any kind — express or implied, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that it will be uninterrupted, that a response will match its real provider in every field, or that the coverage manifest is complete. It is a simulated environment for development and testing. Do not use it as a source of truth for a production decision, and do not treat its responses as facts about any real person, company or system.
To the fullest extent the law allows, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue or data. Our total liability for any claim relating to the service is capped at the fees you paid us in the twelve months before the claim — which, if you have never paid us, is nothing. Nothing here limits liability that cannot be limited by law.
Termination
You can stop using the service at any time; revoke your keys and, if you want your account and data gone, email us and we will delete it. We can suspend or close an account that breaks these terms, and we can discontinue the service — if we shut it down we will say so publicly and email anyone on a paid plan before their next renewal. Sections 7 (the data set), 10 (disclaimer and liability) and 12 (governing law) survive termination.
Governing law
These terms are governed by the laws of Arizona, United States, without regard to its conflict-of-laws rules, and the courts of Arizona, United States are where any dispute arising from them is heard. If you are a consumer somewhere whose law gives you rights you cannot waive, this clause does not take them away.
Changes to these terms
We will update this page when the service or the company changes, and the effective date at the top moves with it. For a change that materially reduces what you get on a paid plan, we will email account holders before it takes effect. Continuing to use the service after a change means accepting the updated terms; if you do not accept them, cancel and stop using the service.
Not legal advice
This page is written by the people who built the service, in the same voice as the rest of the site. It describes our intent accurately. It is not legal advice to you, and it does not create rights beyond what the law and any written agreement between us give you.