UnifyIDDeveloper

Start here · Step 7

Complete the Sandbox checklist

Validate success, denial, expiry, replay protection, webhook handling, and data minimisation before requesting Production access.

Required journey tests

Test scenarioRequired result
Successful authorizationReturn only the information approved by the person.
Consent deniedReturn no authorization grant.
State missing or modifiedReject the callback.
Redirect URI unregisteredReject the authorization request.
Code expired or reusedReject the token exchange.
PKCE verifier incorrectReject the token exchange.
Approved claim unavailableOmit the claim safely.
Webhook event duplicatedCreate no duplicate side effect.

Operational readiness

Confirm credential ownership, webhook monitoring, support contacts, privacy and retention behaviour, usage limits, failure handling, and incident escalation.

Production request

Complete application details, configure at least one active credential and webhook, resolve all test failures, and submit any restricted document-field access for review.

Was this page helpful?
UnifyID Developer Documentation · Version V.1 · Updated July 2026