Behaves exactly like the live API — same endpoints, same signed callbacks — but no real money moves. Payins return a hosted checkout page that auto-completes the payment and fires your webhook.
| Base URL | https://sandbox.chaopaopay.site/api/v1 |
| Merchant ID | M-SANDBOX |
| API Key | pk_test_demo1234567890ab |
| Secret Key | sk_test_demo1234567890ab |
payin/create with the demo credentials — you get back a payment_url.payment_url — a checkout page shows a processing animation, then auto-completes the payment.callback_url receives a signed POST. Verify with sha256(transaction_id + trx_id + status + secret_key) — identical to live.return_url with trx_id, transaction_id and status.curl -X POST https://sandbox.chaopaopay.site/api/v1/payin/create.php \
-H "Content-Type: application/json" \
-H "X-API-Key: pk_test_demo1234567890ab" \
-H "X-Merchant-ID: M-SANDBOX" \
-d '{
"trx_id": "ORDER-1001",
"amount": 500,
"method_code": 101,
"customer_name": "Test User",
"callback_url": "https://yourdomain.com/webhook.php",
"return_url": "https://yourdomain.com/return.php"
}'
simulate_url to auto-approve