> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apsio.io/llms.txt
> Use this file to discover all available pages before exploring further.

# A read-only token for the public sandbox

> A project token for the public sandbox (the Apsio Sandbox organization and its example project, synthetic data), without an account. It reads that one project through the read endpoints and nothing else; every write route refuses it. Short-lived and rate-limited per client. Send `Apsio-Sandbox: 1`.



## OpenAPI

````yaml /api-reference/openapi.json post /sandbox/token
openapi: 3.1.0
info:
  title: Apsio API
  version: 0.1.0
  description: >-
    Read API v0: your projects, release health and comparisons, missing symbols,
    issues, sessions, vitals, cohort comparisons, performance (app start,
    screens, hangs, MetricKit) and network endpoints and traces for one project.
    Authenticate with a project token as a bearer token, with an OAuth access
    token from Apsio's authorization server (MCP clients), or, from the console,
    with the session cookie of a member of the project's organization.
servers:
  - url: https://api.apsio.io/v1
security: []
paths:
  /sandbox/token:
    post:
      summary: A read-only token for the public sandbox
      description: >-
        A project token for the public sandbox (the Apsio Sandbox organization
        and its example project, synthetic data), without an account. It reads
        that one project through the read endpoints and nothing else; every
        write route refuses it. Short-lived and rate-limited per client. Send
        `Apsio-Sandbox: 1`.
      parameters:
        - schema:
            type: string
            enum:
              - '1'
            description: >-
              Must be `1`. A custom header, so a browser page on another site
              cannot mint without a CORS preflight.
          required: true
          description: >-
            Must be `1`. A custom header, so a browser page on another site
            cannot mint without a CORS preflight.
          name: apsio-sandbox
          in: header
      responses:
        '200':
          description: The token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SandboxToken'
        '400':
          description: The Apsio-Sandbox header is missing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: This deployment has no sandbox.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Too many tokens from this client; wait and try again.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: The sandbox is not available right now.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    SandboxToken:
      type: object
      properties:
        token:
          type: string
          description: 'Send as `Authorization: Bearer <token>`.'
        token_type:
          type: string
          enum:
            - Bearer
        expires_at:
          type: string
          description: RFC 3339.
        project_id:
          type: string
      required:
        - token
        - token_type
        - expires_at
        - project_id
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              example: invalid_request
            message:
              type: string
          required:
            - code
            - message
      required:
        - error

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.