---
title: "Sandboxes API Reference"
description: "Sandbox workspaces for testing an integration without touching live data. A sandbox is a separate, API-only workspace created from your live workspace. Its tokens start with `lb_test_`, and the API refuses a `lb_test_` prefix on a live token. Sandbox usage is never billed and does not count toward your plan: a sandbox has its own monthly caps (1,000 API calls, 500 counted scans and credits for 50 links) and allows no custom domains, members or credit top-ups. Links resolve and webhooks fire normally; a scan of a sandbox link answers with `X-Linkbreakers-Sandbox: true` and `X-Robots-Tag: noindex`. A sandbox and everything in it is deleted 30 days after it was created. A workspace holds at most 3 sandboxes."
canonical: "https://linkbreakers.com/help/api/sandboxes"
---

# Sandboxes

Sandbox workspaces for testing an integration without touching live data. A sandbox is a separate, API-only workspace created from your live workspace. Its tokens start with \`lb\_test\_\`, and the API refuses a \`lb\_test\_\` prefix on a live token. Sandbox usage is never billed and does not count toward your plan: a sandbox has its own monthly caps (1,000 API calls, 500 counted scans and credits for 50 links) and allows no custom domains, members or credit top-ups. Links resolve and webhooks fire normally; a scan of a sandbox link answers with \`X-Linkbreakers-Sandbox: true\` and \`X-Robots-Tag: noindex\`. A sandbox and everything in it is deleted 30 days after it was created. A workspace holds at most 3 sandboxes.

## Sandboxes

## [#](#sandboxes-object)The Sandbox object

A sandbox workspace for testing, empty when created, reachable only through its own lb\_test\_ API tokens, and purged at expires\_at.

createdAt

string (date-time)

expiresAt

string (date-time)

When the sandbox and everything in it is deleted.

id

string

The sandbox workspace id (UUID). Its tokens act on this workspace.

name

string

Example object

```json
{
  "createdAt": "2026-10-10T19:14:44.045Z",
  "expiresAt": "2026-10-10T19:14:44.045Z",
  "id": "5b1e4d42-c0d3-4afe-a6fd-0c5f5c3962d0",
  "name": "CI integration tests"
}
```

GET

`/v1/sandboxes`

Requires auth

## [#](#list-sandboxes)List sandboxes

List the sandbox workspaces this workspace created, newest first, with when each one expires. Requires the \`tokens:read\` scope.

### [#](#list-sandboxes-parameters)Parameters

This endpoint does not accept any parameters.

### [#](#list-sandboxes-response)Response

200

Everything worked as expected.

sandboxes

array<object>

totalCount

string (int64)

How many sandboxes the workspace holds.

### [#](#list-sandboxes-error)Error response

400-599

All endpoints may return an unexpected error payload when a request cannot be processed.

error

object

Required

Wrapped error response.

Example request (cURL)

```bash
curl -X GET "https://api.linkbreakers.com/v1/sandboxes" \
  -H "Authorization: Bearer YOUR_TOKEN"
```

Typical response

```json
{
  "sandboxes": [
    {
      "createdAt": "2026-10-10T19:14:44.044Z",
      "expiresAt": "2026-10-10T19:14:44.044Z",
      "id": "5b1e4d42-c0d3-4afe-a6fd-0c5f5c3962d0",
      "name": "CI integration tests"
    }
  ],
  "totalCount": "string"
}
```

Base URL: `https://api.linkbreakers.com`

POST

`/v1/sandboxes`

Requires auth

## [#](#create-a-sandbox)Create a sandbox

Create an API-only sandbox workspace and return its first token. The token starts with \`lb\_test\_\`, holds the scopes of the credential that created it, and is shown only once. Call this with a live workspace credential; a sandbox cannot create sandboxes. Requires the \`tokens:write\` scope.

### [#](#create-a-sandbox-parameters)Parameters

#### header parameters

Idempotency-Key

string

header

Makes retrying this request safe. See components.parameters.IdempotencyKey.

### [#](#create-a-sandbox-request)Request body

name

string

Optional name, at most 80 characters. Defaults to "Sandbox" and the creation time.

### [#](#create-a-sandbox-response)Response

200

Everything worked as expected.

accessToken

string

The secret, starting with lb\_test\_. Returned only once.

sandbox

object

A sandbox workspace for testing, empty when created, reachable only through its own lb\_test\_ API tokens, and purged at expires\_at.

token

object

Describes a long-lived credential Linkbreakers issues so back-end integrations can call workspace APIs without a human session, while keeping auditing metadata for security reviews.

### [#](#create-a-sandbox-error)Error response

400-599

All endpoints may return an unexpected error payload when a request cannot be processed.

error

object

Required

Wrapped error response.

Example request (cURL)

```bash
curl -X POST "https://api.linkbreakers.com/v1/sandboxes" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Idempotency-Key: string" \
  -H "Content-Type: application/json" \
  --data '{"name":"string"}'
```

Sample payload (application/json)

```json
{
  "name": "string"
}
```

Typical response

```json
{
  "accessToken": "string",
  "sandbox": {
    "createdAt": "2026-10-10T19:14:44.045Z",
    "expiresAt": "2026-10-10T19:14:44.045Z",
    "id": "5b1e4d42-c0d3-4afe-a6fd-0c5f5c3962d0",
    "name": "CI integration tests"
  },
  "token": {
    "createdAt": "2026-10-10T19:14:44.045Z",
    "createdBy": "123e4567-e89b-12d3-a456-426614174000",
    "fullAccess": false,
    "id": "d22f7bf1-83a9-4f3a-9b37-9a3a21b6ac11",
    "keyType": "WORKSPACE_TOKEN_KEY_TYPE_UNSPECIFIED",
    "lastUsedAt": "2026-10-10T19:14:44.045Z",
    "name": "Production token",
    "scopes": [
      "API_SCOPE_UNSPECIFIED"
    ],
    "updatedAt": "2026-10-10T19:14:44.045Z",
    "workspaceId": "c0d3cafe-5b1e-4d42-a6fd-0c5f5c3962d0"
  }
}
```

Base URL: `https://api.linkbreakers.com`

DELETE

`/v1/sandboxes/{id}`

Requires auth

## [#](#delete-a-sandbox)Delete a sandbox

Delete a sandbox workspace now, with its links, visitors, events and tokens. Sandboxes are also deleted automatically 30 days after creation. Requires the \`tokens:write\` scope.

### [#](#delete-a-sandbox-parameters)Parameters

#### path parameters

id

string

Required

path

The sandbox to delete (UUID), with everything in it.

### [#](#delete-a-sandbox-response)Response

200

Everything worked as expected.

No structured schema available for this section.

### [#](#delete-a-sandbox-error)Error response

400-599

All endpoints may return an unexpected error payload when a request cannot be processed.

error

object

Required

Wrapped error response.

Example request (cURL)

```bash
curl -X DELETE "https://api.linkbreakers.com/v1/sandboxes/{id}" \
  -H "Authorization: Bearer YOUR_TOKEN"
```

Typical response

```json
{}
```

Base URL: `https://api.linkbreakers.com`

---

Source: https://linkbreakers.com/help/api/sandboxes
