ListBridge

Docs · Getting started

Sandbox

Build and test your integration end-to-end before touching a real marketplace account.

Test vs. live keys

  • lbk_test_… — sandbox mode, no marketplace call is ever made, nothing is billed.
  • lbk_live_… — production mode, real marketplace accounts and real listings.

Test and live traffic are fully isolated: separate accounts, separate listings, separate rate-limit quotas (see Rate limits), and no usage events are recorded for test-mode calls — sandbox testing never touches your bill.

Webhooks fire normally in sandbox: every envelope carries "mode": "test" so your handler can route or filter sandbox deliveries.

Magic identifiers

With a lbk_test_ key, POST /api/v1/accounts never contacts a real marketplace. The email you send picks a deterministic outcome so you can exercise every branch of the connection flow:

email local part `2fa` 202 pending_2fa · verification.type otp, verification.channel email
email local part `2fa-mobile` 202 pending_2fa · verification.type mobile_challenge, verification.channel mobile, with phone_hint
email local part `fail` 422 credentials_invalid
any other email 201 active — account connects immediately
2FA code `000000` 422 verification_invalid — retryable, resubmit any other code
any other 2FA code 200 — verification succeeds, account becomes active

The email local part is the part before @ — [email protected] and [email protected] both work.

Try it

Connect a sandbox account that requires 2FA, then complete verification with any code other than 000000.

POST /api/v1/accounts
TS=$(date +%s)
METHOD='POST'
REQUEST_PATH='/api/v1/accounts'
QUERY=''
IDEMPOTENCY_KEY=$(uuidgen)
BODY='{"marketplace":"leboncoin","credentials":{"email":"[email protected]","password":"anything"},"end_user_id":"customer-42"}'
BODY_SHA256=$(printf '%s' "$BODY" | openssl dgst -sha256 -hex | awk '{print $2}')
IDEMPOTENCY_SHA256=$(printf '%s' "$IDEMPOTENCY_KEY" | openssl dgst -sha256 -hex | awk '{print $2}')
CANONICAL=$(printf 'listbridge-hmac-v1\ntimestamp:%s\nmethod:%s\npath:%s\nquery:%s\nidempotency-key-sha256:%s\nbody-sha256:%s' \
  "$TS" "$METHOD" "$REQUEST_PATH" "$QUERY" "$IDEMPOTENCY_SHA256" "$BODY_SHA256")
SIG=$(printf '%s' "$CANONICAL" | openssl dgst -sha256 -hmac "$HMAC_SECRET" -hex | awk '{print $2}')

curl -X "$METHOD" "https://api.listbridge.io$REQUEST_PATH" \
  -H "Authorization: Bearer lbk_test_xxx" \
  -H "Idempotency-Key: $IDEMPOTENCY_KEY" \
  -H "X-Timestamp: $TS" \
  -H "X-Signature: v1=$SIG" \
  -H "Content-Type: application/json" \
  -d "$BODY"
# 202 Accepted · { "id": "...", "status": "pending_2fa", "verification": { "type": "otp", "channel": "email", ... } }
POST /api/v1/accounts/{account_id}/verify-2fa
curl -X POST "https://api.listbridge.io/api/v1/accounts/$ACCOUNT_ID/verify-2fa" \
  -H "Authorization: Bearer lbk_test_xxx" \
  -H "X-Timestamp: $TS" \
  -H "X-Signature: v1=$SIG" \
  -H "Content-Type: application/json" \
  -d '{"session_id":"test-2fa-session","code":"123456"}'
# 200 OK · account becomes active

See Authentication for the full signing recipe.

Going live

Generate an lbk_live_ key from your workspace dashboard once you're ready for real marketplace accounts. An active subscription is required for any live-mode call — without one, every request on a live key returns 402 subscription_required, including account connection and refresh.