Sandbox and testing
The sandbox behaves like live but moves no real money. Use it to test every success and failure path before you ship.
What the sandbox is
- Base URL
https://sandbox-api.payder.ng/v1, with its own merchant (mch_test_…), API keys (pdr_test_sk_…) and webhook secret. - Open to every approved developer account. No identity checks and no real charges.
- Hosted checkout pages show a test-card form instead of a real card form.
- Webhooks are real: they are signed and retried exactly like live, so you can test your handler end to end.
Never enter a real card in the sandbox
Only the numbers below are accepted. Anything else is rejected with
invalid_test_card.Test cards
Use any future expiry date and any 3-digit CVV.
| Card number | Result | Webhook |
|---|---|---|
4242 4242 4242 4242 | Succeeds immediately | payment.succeeded |
4000 0000 0000 9995 | Fails: insufficient funds | payment.failed |
4000 0000 0000 0259 | Stays pending for about 60 seconds, then succeeds | Arrives late: payment.succeeded |
| Pay by bank transfer button | Succeeds immediately | payment.succeeded |
The delayed card is the one to test your "pending" screen with. Your order must stay unpaid until the late webhook arrives.
Mark a checkout by hand
In the console, each pending sandbox checkout has Mark paid and Mark failed buttons. They settle it and fire the matching webhook, which is handy when you want a result without clicking through the payment page.
Test payout accounts
| Account number | Result |
|---|---|
0123456789 | Succeeds after about 5 seconds: payout.succeeded |
0000000000 | Fails: payout.failed |
| Any other 10-digit number | Succeeds, like the first |
Test refunds
- A refund of a paid sandbox checkout settles after about 5 seconds with
refund.succeeded. - Send the
reasonsandbox_failto forcerefund.failed. - The real rules still apply: you cannot refund an unpaid checkout, or more than was paid.
A complete test plan
- Create a checkout and pay it with
4242…. Confirm your webhook endpoint receivespayment.succeededwith a valid signature and the rightamountMinor. - Pay another with
4000 0000 0000 9995. Confirmpayment.failedand that your order stays unpaid. - Pay another with
4000 0000 0000 0259. Confirm your order shows as processing, then completes when the late webhook arrives. - Refund part of a paid checkout, then try to refund more than what is left. Confirm you handle
422 refund_exceeds_paid. - Pay out to
0123456789and to0000000000. Confirm both webhooks are handled. - Send the same request twice with one
Idempotency-Key: the same response. Then with a changed body:409. - Make your endpoint return a 500, watch the retry in the delivery log, fix it, and press Resend.
- Tamper with a payload and confirm your endpoint rejects the bad signature.
- Revoke your key in the console and confirm requests now fail with
401 invalid_api_key.
When all of these pass, read Going live.