# Environments

The Payments API runs in two environments. **Sandbox** is where you build and test your integration; **Production**
is where real people and businesses are onboarded and real money moves. Each has its own base URL and its own API
keys, and nothing created in one exists in the other.

## Sandbox

Build against the sandbox first. It accepts the same requests as production, but nothing you send reaches a real
financial institution, so you can exercise the full flow — onboarding, bank accounts, transactions and ACH
processing — end to end.

* `Base URL` - `https://api-sandbox.grailpay.com/api/v3`
* `Version` - v3

The sandbox reserves routing numbers and accepts test Social Security Numbers for exactly this purpose. The values
are listed under [Testing](/docs/technical/overview#testing) on the Payments Platform Overview, and the routing
numbers that return each bank account validation outcome are on
[Validate Bank Accounts](/docs/technical/bank-accounts/validate-bank-accounts#testing).

## Production

When your integration is tested, point it at production and switch to your production API key. Requests here onboard
real people and businesses, move real funds, and count against your
[origination limit](/docs/technical/overview#origination-limit).

* `Base URL` - `https://api.grailpay.com/api/v3`
* `Version` - v3

:::caution
Do not use sandbox credentials in production or vice versa. Each environment requires its own API key.
:::

## Request conventions

The following apply in both environments.

### API Headers

* `API Key` - The bearer auth token [as described here](/docs/technical/authentication)
* `Content-Type` - application/json
* `Accept` - application/json

### API Date & Time Format

All dates and times must be requested and responded to in the following format

* `date` - yyyy-mm-dd
* `time` - hh:ii
* `datetime` - yyyy-mm-dd hh:ii:ss

### API Money Format

All amounts and fees are requested and responded in cents.