Testing
Your sandbox organization is test mode. Its keys start sk_test_ and pk_test_, and nothing it does reaches a real person or makes a valid signature.
What is different in test mode
Section titled “What is different in test mode”| Test mode | |
|---|---|
| SMS | Never sent. |
| The code | Always 424242. session.code.test_code says so. |
| Certificates | Issued at once by the ePahichan test authority. They say “Test certificate, not valid for signing” and no verifier accepts them. |
| The signature | Made exactly as in live mode, with “Test signature, not valid” in its appearance. |
| Phone numbers | Any Nepali mobile number works, and nothing is sent to it. The reserved range +977 9800000000 to +977 9800000099 is safe to use in shared test data. |
A signer is known by phone number within a mode: the first request for a number issues a test certificate, and later requests for the same number reuse it. Use a new number to test a first-time signer again.
Outcomes to test
Section titled “Outcomes to test”| Outcome | How |
|---|---|
| Signed | Accept, then confirm with 424242. |
| Wrong code | Confirm with any other 6 digits: code_incorrect, with the tries left. |
| Too many wrong codes | Five wrong codes: the request fails with code_attempts_exhausted. |
| Code expired | Wait 10 minutes after accepting, then confirm: code_expired. Resend and confirm. |
| Declined | POST …/decline with a reason. |
| Canceled | POST …/cancel from your server before the signer confirms. |
| Expired | Create a request with "expires_in": 300 and leave it for five minutes. |
| A retry | Send the same create twice with one Idempotency-Key: one request, the same answer twice. |
| A first-time signer without the form | Leave out the certificate_application document: certificate_application_required. |
| A certified signer with the form | Send the form for a number that has signed before: signer_already_certified. |
| Your webhook | Send test under Signing → Webhooks sends a ping event. |
Every call appears under Signing → Logs with its result and error code, and every event under Signing → Events with where it was delivered.