# Testing in sandbox

The [sandbox](https://sandbox.intasend.com) is a full copy of IntaSend that moves no real money.
Sign up there, copy your `_test_` keys from **Settings → API Keys**, and use them exactly as you would
live keys. See [Getting started](https://developers.intasend.com/getting-started/#2-choose-an-environment) for how keys pick the environment.

When you're ready to go live, sign up on [payment.intasend.com](https://payment.intasend.com/account/signup/)
and swap in your `_live_` keys. Nothing else in your integration changes.

## Test cards

Use any future expiry date and any 3-digit CVC.

| Card number |
|---|
| `4456 5300 0000 1096` |
| `4456 5300 0000 3134` |
| `4242 4242 4242 4242` |
| `5200 0000 0000 1096` |
| `5200 0000 0000 3092` |

## M-Pesa

- **Collections (STK Push):** use your own Safaricom number. Sandbox requests go through the
  M-Pesa developer platform, which reverses test amounts within 48 hours.
- **Payouts (B2C):** send to `254708374149`.

## Callbacks and webhooks

Your `redirect_url`, `callback_url` and [webhook](https://developers.intasend.com/guides/webhooks/) endpoints must use HTTPS, in sandbox as well as live.
