Differences between sandbox and production
Checklist before switching to production
- Confirm account-specific quotas (rate limit, max payload size, simultaneous-running-plans threshold) against the published defaults; contact customer.success@kardinal.ai if your account’s values differ from the defaults.
- Re-run your integration against production with real data volumes. If your production order/resource counts are meaningfully larger than what you tested in sandbox, re-check your
maxOptimizationDurationsizing — see Handling large volumes rather than assuming sandbox-derived durations still apply. - Re-verify geocoding. The API does not geocode addresses (see Positions and geocoding); confirm the same geocoding provider and pipeline used in sandbox testing is wired up for production data before go-live.
- Rotate to your production API token everywhere, including any long-lived config or secrets manager entries — see the next section.
Managing your long-term API token per environment
Each agency has its own long-term API token, obtained via the Console, once per agency — not a separate username/password pair (see Authentication and API keys). For production:- Store the
sandboxandproductiontokens as separate secrets, scoped to their respective deployment environments, so a staging deploy can never accidentally authenticate against production (or vice versa). - Confirm which agency a given long-term token was issued for before debugging a request that behaves unexpectedly — a token always authenticates successfully against its own agency, so using the wrong one doesn’t fail: it silently succeeds against that agency’s data instead. Check the
agencyIdfield in the response to confirm which agency you actually hit. - Regenerating a token replaces the previous one for that agency immediately — roll the new value out everywhere before discarding the old one (see Token lifetime).
See also
- Authentication and API keys — obtaining, rotating, and storing your long-term API token.
- Limits and quotas — rate limits, payload size, and SLA, and how to confirm the values for your account.
- Handling large volumes — sizing
maxOptimizationDurationand paginating for production-scale data.

