Sandbox and test data
How to build against Tourical before you touch live bookings — and what a test token really is.
There is no separate sandbox host today. Every /v1/* call goes to https://app.tourical.com. Tokens minted there carry the tk_live_ prefix; tk_test_ tokens are issued only by non-production deployments of the platform (GET /v1/me reports the same value in env). A hosted sandbox with seeded fixtures is under evaluation — the changelog will announce it.
Recommended setup
- Create a dedicated integration tenant (a normal operator account) that holds no customer data. Mint its tokens with the smallest scope set you need.
- Create one or two trips and publish them. Reads (
GET /v1/trips,GET /v1/me,GET /v1/webhooks) and CRM writes (POST /v1/clients) are safe to exercise freely there. - Produce webhook traffic without money moving:
POST /v1/webhooks/testdelivers awebhook.testevent so you can verify signatures.- Publishing / unpublishing a trip emits
trip.published/trip.unpublished. - Creating a client emits
client.created.
- Booking, payment and dispute events require a real checkout on the integration tenant. Use the smallest deposit the trip allows and refund it from the dashboard afterwards — that also gives you
booking.refundedandbooking.cancelled.
Exercising webhooks without a public host
- Expose a local receiver with a tunnel (Cloudflare Tunnel, ngrok, …); the subscription URL must be HTTPS and resolve to a public IP.
- Use
GET /v1/webhooks/{id}/deliveriesto see what we sent and what your endpoint answered, andredeliverto replay a row after you fix a bug. - Every payload example in the event catalog is generated from the runtime schema, so you can unit-test your handler against those bodies before any real traffic.
Guarding production
Refuse to run with a token whose GET /v1/me env differs from the environment your integration believes it is in. Refuse tokens with more scopes than you need — scopes is in the same response.
Status
Platform incidents and maintenance windows are announced at status.tourical.com. Webhook deliveries queued during an incident are delivered afterwards on the normal cascade — nothing is dropped.

