Testing in the Sandbox
The Sandbox screen runs Plugin SDK requests and webhook tests against isolated data, so you can exercise your integration without touching a real restaurant.
What a sandbox is — how it is provisioned, what data it is seeded with, when it resets and when it expires — is Sandboxes. This page is about using the screen.
Open it from the nav, or from a project's Open sandbox link, which selects that project for you.
Three tabs
| Tab | What it does |
|---|---|
| Sandbox | The sandbox itself — status and setup |
| API Explorer | Send Plugin SDK requests against sandbox data |
| Webhook Tester | Send a signed test event to your webhook endpoint |
API Explorer
Browse the Plugin SDK operations SSP publishes and run them against your sandbox, so you can see real request and response shapes before writing a line of code.
The endpoints themselves are documented in Plugin Data API and API Reference.
Webhook Tester
This sends a genuinely signed test webhook for the event you choose to your plugin's configured webhook endpoint, then polls the delivery log and reports what happened.
What it sends
The same envelope and headers as production, so anything that works here works in the wild:
X-SSP-Event: <the event you selected>
X-SSP-Signature: hex(hmac_sha256(raw_json_body, webhook_secret))
Content-Type: application/json
The signature is computed over the raw JSON bytes. Re-serialising the parsed body before hashing it — a very common mistake — produces a different digest and rejects valid requests. The Hello World tutorial shows the correct pattern.
The event list is filtered to your plugin
You can only send events your plugin actually subscribes to. If the event you want is missing, add it in the plugin's Webhooks step — see Building your plugin.
Delivery outcomes
After sending, the tester polls the delivery log and shows one of:
| Outcome | Means |
|---|---|
| Delivered | Your endpoint accepted it |
| Queued | Still in flight |
| Failed | Your endpoint rejected it or could not be reached |
| Skipped | SSP did not deliver it — usually endpoint or subscription configuration |
Polling gives up after a short window. A test that is still queued when polling stops has not necessarily failed — delivery may simply still be processing, and the delivery log entry is named on screen so you can check it.
If the tester tells you to complete plugin setup before sending, the plugin is missing its webhook endpoint or its event subscriptions. The sandbox cannot change plugin-wide delivery settings — fix them on the plugin page, then come back.
Next
Mint a key for CI, or write the receiver with the Hello World tutorial.