Build on Sri Lanka’s Digital Public Infrastructure
One gateway to national identity, data exchange, payments, verifiable credentials and digital signatures. Register an application, get an isolated playground seeded with synthetic data, and test real user journeys end to end, without ever touching a production system.
API Catalog Identity Attributes
Identity Attributes
Explore all Digital Public Infrastructure building blocks available in Sri Lanka’s DPI ecosystem.
Important requirements
- User consent must be obtained before each verification
- Audit logs are maintained for 7 years for compliance
- Results are cached for 24 hours for repeat verifications
- All testing uses synthetic data in the sandbox environment
Use Cases
- Financial institutions for KYC compliance
- E-commerce platforms for age verification
- Government portals for citizen authentication
- HR systems for employee verification
Base URL
https://api.sandbox.dpi.gov.lk/v1
All building blocks. One integration surface.
Every API in the catalog belongs to one of Sri Lanka’s DPI components. Learn one authentication model and one request pattern, then compose across all five.
SLUDI: Unique Digital Identity
Authenticate users, run identity and eligibility checks and capture explicit consent before your application touches protected data.
National Data Exchange
A secure data exchange platform that enables seamless API-based data sharing and interoperability across both state and corporate sectors.
Digital Payments
A secure, interoperable payment layer for government services, built to replace cash and manual collection at the counter.
Verifiable Credentials
Issue and verify digital certificates that prove a claim about a person or entity: independently checkable, without calling the issuer every single time.
Digital Signatures
Bind a signer to a document or message so authenticity and integrity hold up as trusted electronic approval under Sri Lanka’s legal framework.
From sign-in to a working integration, without a procurement cycle.
The sandbox is self-service end to end. Nothing here requires an email to an agency or a signed agreement before you can write code.
01
Sign in
Federated sign-in with your GitHub or Google identity. You land straight in your Workspace: no account request form.
02
Explore the catalog
Browse by DPI building block. Read the endpoints, request formats and auth model before you commit to anything.
03
Register an application
Register an app and select the APIs it needs. Sandbox credentials are issued and scoped to that application alone.
04
Test in a playground
Supported APIs provision an isolated playground seeded with synthetic data. The rest route straight upstream: same console either way.
05
Watch the numbers
Calls, latency, error breakdowns and point consumption in real time. Upgrade a tier when you outgrow the free limits.
Two ways to test. One console.
How you test depends on the API, never on your tooling. Both paths run through the same “Try Out” console, the same sandbox credentials and the same metrics.
Playground APIs
Selecting a supported API provisions a private playground seeded with synthetic data. You can run a complete user journey (verify an identity, issue a credential, sign it, take a payment) without a single real record in play.
- Provisioned automatically per application
- Seeded with synthetic identities and records
- Mirrors production API behaviour
- Reset and re-run as often as you need
Upstream APIs
Some APIs have no synthetic twin. For those the “Try Out” console routes your call straight to the upstream sandbox environment: same request builder, same sandbox-scoped credentials, same metrics coming back.
- No playground provisioning step
- Sandbox-scoped credentials only, always
- Identical request and response tooling
- Counted against the same API points
Predefined test scenarios, not just the happy path
Every playground ships with scenarios covering success, error, consent-denied, rate-limit and 404 responses, so you can prove your error handling before anyone else has to.
- success
- error
- consent-denied
- rate-limit
- 404
Everything you need, in three places.
The portal is organised around what you are actually doing at the time: building something, watching how it behaves, or getting unstuck.
Where you build
Workspace
Search the catalog, register applications, provision playgrounds and fire requests. Official DPI APIs come pre-installed, so there is no setup tax before your first call.
- API Catalog
- My Applications
- Playgrounds
- SDKs & Libraries
- Try Out console
Where you watch
Observability
Total calls, successful and failed requests and average response time, with hourly traffic and a per-API breakdown of what is slow or erroring, alongside your point balance and tier.
- Metrics Dashboard
- Support & Incidents
- Platform Status
- Subscription & Billing
- Compliance
Where you get unstuck
Learn
Hands-on walkthroughs across tech stacks on the government-maintained channel, plus AI tools that answer in plain language and rewrite examples into the language you actually ship in.
- Academy
- Video tutorials
- Instant Code Translation
- Smart Search
- Reference docs
Start free. Prove it works. Then scale.
All three tiers reach the same sandbox APIs. What changes is how much you can call, and what governance comes with it.
Free
Default for every developer
No cost
Generous API point limits so you can explore every sandbox API, build prototypes and throw work away without asking anyone first.
- Every sandbox API
- Isolated playgrounds
- Metrics dashboard
- Community support
- Instant self-service sign-up
Extended Sandbox
Most requestedFor serious builders
Free · Given upon request
Higher point limits for MVPs, hackathons and pilots. Access is granted through project verification, not payment.
- Everything in Free
- Raised API point ceilings
- Project-based approval
- Priority incident routing
- Extended metrics retention
No real citizen data. No production reach.
The sandbox is a non-production system by construction, not by policy note. These are the guarantees you can safely design against.
Synthetic data only
Every playground runs on synthetic or anonymised records. No live system and no real citizen data is reachable from inside the sandbox.
Sandbox-scoped credentials
Keys issued here work only here. There is no path from a sandbox credential to a production endpoint, by design rather than by convention.
Classified by sensitivity
Every API carries a classification (Public, Internal, Confidential, Restricted or Top Secret) so the handling rules are clear before you call it.
Vetted before graduation
Moving toward production means security and privacy self-assessments, consent-flow verification and administrative review against a published checklist.
Before you sign up
The things developers ask us first, answered without the policy language.
No. Sign in with GitHub or Google and you land on the Free tier immediately, with access to every sandbox API. Approval only enters the picture when you request a higher tier or start the graduation pathway toward production.
Ready to plug in?
Create an account, register your first application and have a playground answering requests in minutes. Free tier, no card, no procurement cycle.
Sandbox environment · Synthetic data only · No production access