HEIRLO SANDBOX · FICTIONAL DATA ONLY

Test Your Heirlo Integration

Build with sample contacts, matters, tasks, and notes in a separate testing environment. Never enter real client information here.

Your Sample Firms

Request access from support@heirlolaw.com. Each integration receives its own pair of fictional firms, with separate read-only and read/write keys. Sample contacts, matters, tasks, and notes are already linked. Access expires after 30 days.

Sandbox keys start with hik_sandbox_. They cannot access production. Production keys cannot access this sandbox. Keys determine firm ownership; changing firm or user headers does not change access.

Make Your First Request

curl 'https://sandbox.heirlolaw.com/api/v1/contacts' \
  -H "X-API-Key: $HEIRLO_SANDBOX_KEY"

Use the IDs from the response to create related matters, tasks, or notes. Send a new UUID in Idempotency-Key with POST and PATCH. Retry identical requests with the same UUID. PATCH also requires the latest updatedAt; stale edits return 409.

curl 'https://sandbox.heirlolaw.com/api/v1/contacts' \
  -H "X-API-Key: $HEIRLO_SANDBOX_KEY" \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: 6873c72d-122b-4df8-8a18-8afcf070bf2f' \
  --data '{"firstName":"Sample","lastName":"Client","email":"sample@example.invalid"}'

What to Verify

Sandbox Boundaries

This is the core-record API, with the same validation, permissions, retry behavior, and limits as production. Lists support limit (up to 100), after, and overlapping updatedSince polling. They are not a snapshot or deletion feed.

No real email, SMS, billing, AI processing, court filing, or automatic estate workflows are available. Staff login, public registration, document transfers, and provider callbacks are disabled. This sandbox does not test those workflows.

Limits are 120 requests per minute per key, 600 per firm, and 300 per source address; concurrency is 4 per key and 12 per firm. JSON bodies are limited to 32 KiB. Respect Retry-After on 429 and 503. Sample workspaces allow approximately 1,000 records per resource (concurrent creates may briefly exceed this). The SANDBOX_RECORD_LIMIT error means you should request a fresh workspace.

Sample records persist between requests but may be reset by arrangement with support. There is no production-data copy or promotion. Request a fresh pair of firms to restart testing; previously issued keys can be revoked by support. Keep keys on your server, never in browser code or URLs.

Endpoint Reference

Download the Sandbox OpenAPI Specification

Loading API reference…

Moving to Production

Create separate production keys in Heirlo Settings → Integrations → Developer API, select the required permissions, and change your integration’s base URL. Do not copy fictional records into a real firm. Review field mappings and permissions before enabling production writes.

When requesting help, include the response’s X-Request-ID and identify the sandbox. Never send your secret API key.