---
title: "Sandbox: test the Linkbreakers API without touching live data"
description: "Create a Linkbreakers sandbox workspace with its own lb_test_ API token. Build and test an integration or an AI agent against real endpoints, with separate data, separate caps, no billing and automatic deletion after 30 days."
canonical: "https://linkbreakers.com/help/article/sandbox-test-environment"
last-updated: 2026-10-10
---

# Sandbox: test the Linkbreakers API without touching live data

> Create a Linkbreakers sandbox workspace with its own lb_test_ API token. Build and test an integration or an AI agent against real endpoints, with separate data, separate caps, no billing and automatic deletion after 30 days.

## Short answer

A **sandbox** is a separate, empty Linkbreakers workspace for testing. You create it from your live workspace, and it comes with its own API token that starts with `lb_test_`. Everything the API, the SDKs, the CLI and the MCP server can do works there, against the real production endpoints, but nothing you create touches your live links, visitors or analytics, and none of it is billed. A sandbox and everything in it is deleted automatically 30 days after it was created.

## Quick summary

- Create one with `POST https://api.linkbreakers.com/v1/sandboxes` or from **Dashboard → API Tokens → Sandboxes**
- Its token starts with `lb_test_` and acts only on the sandbox. The API refuses a `lb_test_` prefix on a live token, so the two can never be confused
- The token gets the same scopes as the credential that created the sandbox
- Never billed, never counted toward your plan. A sandbox has its own monthly caps: 1,000 API calls, 500 counted scans and credits for 50 links
- No custom domains, no team members and no credit top-ups in a sandbox
- Links resolve and webhooks fire normally. A scan of a sandbox link answers with `X-Linkbreakers-Sandbox: true` and `X-Robots-Tag: noindex`
- Up to 3 sandboxes per workspace, each deleted 30 days after creation, or earlier with `DELETE /v1/sandboxes/{id}`

## Create a sandbox with the API

Call the endpoint with a token of your **live** workspace that holds the `tokens:write` scope (a full-access token works):

```bash
curl -X POST https://api.linkbreakers.com/v1/sandboxes \
  -H "Authorization: Bearer $LINKBREAKERS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "CI integration tests"}'
```

The response holds the sandbox, its token metadata and the secret, shown only once:

```json
{
  "sandbox": {
    "id": "5b1e4d42-c0d3-4afe-a6fd-0c5f5c3962d0",
    "name": "CI integration tests",
    "createdAt": "2026-10-10T18:05:47Z",
    "expiresAt": "2026-11-09T18:05:47Z"
  },
  "token": { "id": "...", "fullAccess": true },
  "accessToken": "lb_test_eyJhbGciOi..."
}
```

Use `accessToken` exactly like any other token:

```bash
curl -X POST https://api.linkbreakers.com/v1/links \
  -H "Authorization: Bearer lb_test_eyJhbGciOi..." \
  -H "Content-Type: application/json" \
  -d '{"destination": "https://example.com/test"}'
```

`GET /v1/sandboxes` lists your sandboxes with their expiry, and `DELETE /v1/sandboxes/{id}` deletes one now. A sandbox cannot create sandboxes: call these endpoints with a live token.

## Create a sandbox in the dashboard

1. Open [**Dashboard → API Tokens**](https://app.linkbreakers.com/workspace/dashboard/api-tokens)
2. In **Sandboxes**, click **Create sandbox** and optionally name it
3. Copy the `lb_test_` token. It is shown only once

The list shows when each sandbox expires, and the bin icon deletes one ahead of time.

## Use a sandbox with an AI agent or the MCP server

Give the agent the `lb_test_` token instead of a live one. With the [MCP server](/help/article/mcp-server-setup), configure it as the bearer token: every tool then acts on the sandbox. An agent that registered itself anonymously can create a sandbox the same way, with the token it received.

## What is different in a sandbox

| | Live workspace | Sandbox |
| --- | --- | --- |
| Token prefix | none | `lb_test_` |
| Billing | your plan | never billed |
| API calls per month | your plan | 1,000 |
| Counted scans per month | your plan | 500 |
| Links per month | your plan's credits | credits for 50 links |
| Custom domains, members, credit top-ups | your plan | none |
| Webhooks | fire | fire |
| Scan responses | normal | `X-Linkbreakers-Sandbox: true`, `X-Robots-Tag: noindex` |
| Lifetime | permanent | deleted 30 days after creation |

Sandboxes are kept out of Linkbreakers' internal sign-up, activity and lead metrics, and can never be published to the public template gallery.

## Frequently asked questions

### Does a sandbox share any data with my live workspace?

No. It is a separate workspace that starts empty. Its token cannot read or change anything in your live workspace, and a live token cannot read the sandbox.

### Can I keep a sandbox longer than 30 days?

No. Each sandbox is deleted, with its links, visitors, events and tokens, 30 days after it was created. Create a new one when you need it; you can hold up to 3 at a time.

### Do sandbox links really redirect?

Yes. Links resolve, QR codes scan and webhooks fire as in a live workspace, so you can test the whole flow. Scan responses carry `X-Linkbreakers-Sandbox: true` so your tests can assert they hit a sandbox, and `X-Robots-Tag: noindex` so search engines skip them.

### How do I tell a sandbox token from a live one in code?

Sandbox tokens always start with `lb_test_`. The prefix is checked on every request, together with a signed claim inside the token, so it cannot be added to or removed from a token to change what it reaches.

### What happens when a sandbox reaches a cap?

The same thing as on a plan: past the API call cap, calls answer `429` with `MAX_PUBLIC_API_QUERIED_REACHED`, and past the link credits, creating a link is refused with a credits error, until the next month. Delete the sandbox and create a new one if you need a fresh allowance sooner.
