Skip to main content
Sandbox and production are two agencies of the same builder account — not separate hosts or separate logins. You sign up once; that single account gives you a long-term API token for each agency, and nothing you create in one agency is visible from the other. Moving to production is mostly a matter of pointing your integration at your production token and re-validating what you already tested, rather than a code change or a host change.

Differences between sandbox and production

Checklist before switching to production

  1. Confirm account-specific quotas (rate limit, max payload size, simultaneous-running-plans threshold) against the published defaults; contact customer.success@kardinal.ai if your account’s values differ from the defaults.
  2. Re-run your integration against production with real data volumes. If your production order/resource counts are meaningfully larger than what you tested in sandbox, re-check your maxOptimizationDuration sizing — see Handling large volumes rather than assuming sandbox-derived durations still apply.
  3. Re-verify geocoding. The API does not geocode addresses (see Positions and geocoding); confirm the same geocoding provider and pipeline used in sandbox testing is wired up for production data before go-live.
  4. Rotate to your production API token everywhere, including any long-lived config or secrets manager entries — see the next section.

Managing your long-term API token per environment

Each agency has its own long-term API token, obtained via the Console, once per agency — not a separate username/password pair (see Authentication and API keys). For production:
  • Store the sandbox and production tokens as separate secrets, scoped to their respective deployment environments, so a staging deploy can never accidentally authenticate against production (or vice versa).
  • Confirm which agency a given long-term token was issued for before debugging a request that behaves unexpectedly — a token always authenticates successfully against its own agency, so using the wrong one doesn’t fail: it silently succeeds against that agency’s data instead. Check the agencyId field in the response to confirm which agency you actually hit.
  • Regenerating a token replaces the previous one for that agency immediately — roll the new value out everywhere before discarding the old one (see Token lifetime).

See also