Sandbox versus production
New tenants default to sandbox and use Enable Bankingās test environment, including Mock ASPSP. Sandbox data and consent are simulated. Production is a separate tenant mode with separate provider configuration. A successful sandbox test does not prove production availability, support for a real bank, or readiness to process live financial data.
Browse documentation
Sandbox and production are separate banking modes on an Invunion tenant. The mode selects the corresponding Enable Banking application configuration when a bank connection starts. New tenants default to sandbox.
This article explains the implemented mode boundary; it does not announce production availability. Do not infer that live banking can be enabled for your tenant unless Invunion has explicitly confirmed the required configuration and access.
Prerequisites
- Access to the Invunion tenant you want to evaluate.
- Permission to open the connected-bank dialog.
- An agreed data-handling policy for test and live financial information.
- An administrator or support contact who can confirm tenant mode when the UI is unclear.
Steps
-
Identify the tenant. Make sure you are operating in the intended organization and tenant before adding invoices, connections, or transactions. Mode belongs to the tenant, not merely to your browser session.
-
Check the bank-connection dialog. In sandbox, the UI states that the institution list contains Enable Banking test institutions and can show Mock ASPSP. The dialog may also recommend Personal for sample transactions.
-
Use sandbox for guided evaluation. Select SI (Slovenia) and Personal, then connect Mock ASPSP. That combination exposes the verified sample account path. Initial synchronization requests the last 90 days of available test transactions.
-
Keep test and live data distinct. Use synthetic invoice numbers, customer names, addresses, and references in sandbox. The banking side is simulated, but any invoice or manually entered content is still data you supplied.
-
Interpret sandbox results narrowly. A successful redirect, account discovery, sync, invoice import, and match show that the current workflow operates with test data. They do not verify a real bank, production provider configuration, live consent, or your organizationās operational readiness.
-
Treat production as a separately approved environment. Production mode uses separate Enable Banking credentials and is intended for real provider connections only when configured. If a production-mode tenant reports that the provider is unavailable, stop; changing visible selections cannot supply missing production configuration.
-
Do not use real credentials in Mock ASPSP. The sandbox authorization is simulated. If a page unexpectedly asks for credentials you recognize as real, leave the flow and verify the tenant mode and destination before proceeding.
-
Document mode in support requests. When reporting a bank issue, state whether the connection dialog showed sandbox or production. Include the test institution only in sandbox reports and never send secret keys or real login credentials.
Expected result
You can determine whether a tenant is using the test or live provider configuration and choose data appropriate to that mode. In sandbox, Mock ASPSP connects without a real bank account and supplies its own synthetic account data. In a correctly configured production context, the sandbox-specific Mock ASPSP assumptions should not be used.
Edge cases and troubleshooting
- A new tenant does not appear to be sandbox: capture the visible mode or provider message and contact support. Do not repeatedly attempt connections while uncertain.
- The tenant says production but the provider is unavailable: production credentials or configuration are not available for that tenant. This is not fixed by choosing SI or Personal.
- Mock ASPSP is missing: first confirm sandbox mode, country SI, Personal user type, and that the picker loaded successfully.
- Sandbox shows no sample transactions: Business can expose a test account without transactions. Reconnect using Personal.
- Real data was uploaded to sandbox: follow your organizationās incident and deletion process. Disconnecting a bank does not delete transactions already imported.
- A sandbox demonstration worked: record it as a test result only. Do not represent it as evidence that production is generally available.
Security and sandbox notes
Mode separation reduces the risk of accidentally calling a live banking provider during a test, but it does not replace access control or data minimization. Tenant-scoped data can still be sensitive. Keep user membership current and share diagnostic details only through approved channels.
Do not infer any certification or assurance status from this article. Security reviews should rely on current contractual and technical documentation supplied for that purpose, not on a sandbox demonstration.
The interface, mode notices, and connection flow can change. Recheck this article after its review date before incorporating exact screen labels into internal procedures.
Next step
For a test run, continue with Connect a test bank. To understand what happens when replacing a connection, read Reconnect, sync, or disconnect a bank.
Updated
Was this article helpful?
Feedback helps us improve the next version of this guide.