What changes when you leave sandbox
There is no separate sandbox environment to graduate out of. A sandbox agent runs the exact same authorize gate, the same reason codes, the same enforcement as a production one — so nothing you tested against the sandbox behaves differently once you're not using it anymore.
What actually changes
- Your principal needs KYC/KYB verification to issue a mandate — and it's checked on every single authorize call after that too, not a one-time unlock
- You supply your own spend limits and merchant allow-list instead of the sandbox's fixed demo values
- The public sandbox endpoint is rate-limited to protect it from abuse; your own provisioning call isn't
What doesn't change
The guard code, the reason codes, the SOP/Standards molecule format, and the gate itself are identical. If a rule blocked or escalated an action in the sandbox, the same rule blocks or escalates it in production — there's no second policy engine waiting behind a flag.
How to move
Submit your organisation's KYC/KYB, then call the same one-call provisioning endpoint the sandbox scaffold used — this time authenticated, and with your own maxAmount, perTxnMax and merchants instead of the demo's. See the API reference for the exact request shape.
