Purpose
The sandbox provides synthetic test data and predefined fixtures for testing the published SMBC XS2A scenarios.
It supports only the test values and responses in Sandbox Mock Data. See Limitations and related guidance for what sandbox testing does not confirm.
Before connecting
Use the published Sandbox endpoint for the selected institution and only the fixtures documented for that endpoint. See APIs and endpoints in Technical reference for the applicable URLs.
The sandbox uses the same TPP certificate model as production. A connecting TPP must use its own applicable real certificates:
- UK Open Banking certificates for SMBC Bank International plc, London; and
- eIDAS certificates for Frankfurt, Paris, Düsseldorf and Brussels.
The certificate must represent the connecting TPP and contain or support validation of the regulated role required for the operation. SMBC does not issue or publish sandbox test certificates.
Institution and resource scope
Each supported SMBC institution has a separate sandbox endpoint.
Use each published fixture and identifier only through its stated institution endpoint.
Do not derive endpoints, add branch codes or construct resource identifiers.
How sandbox fixtures work
Published sandbox results depend on the documented institution, role, PSU, consent, resource and operation values.
Use each fixture only for its published input and expected response.
Do not assume that an operation changes, resets or consumes a fixture unless Sandbox Mock Data explicitly states that behaviour.
Test personas
Sandbox Mock Data defines published PSU persona types and their simulated capabilities. PSU IDs are fixture values used to select predefined responses. SMBC does not provide customer passwords, activation data or mobile authentication credentials for the sandbox.
The sandbox does not provide a working SCA journey. Where a sandbox response