Skip to content
Sri Lanka FlagAn official website of The Government of Sri Lanka

Build on Sri Lanka’s Digital Public Infrastructure

One gateway to national identity, data exchange, payments, verifiable credentials and digital signatures. Register an application, get an isolated playground seeded with synthetic data, and test real user journeys end to end, without ever touching a production system.

Digital Integration SandboxDeveloper Portal

API Catalog Identity Attributes

Identity Attributes

Explore all Digital Public Infrastructure building blocks available in Sri Lanka’s DPI ecosystem.

v1.3Stable120ms avg latency98.3% uptime6 endpoints7,281 subscribers
OverviewDocumentationEndpointsAuthenticationSDKs

Important requirements

  • User consent must be obtained before each verification
  • Audit logs are maintained for 7 years for compliance
  • Results are cached for 24 hours for repeat verifications
  • All testing uses synthetic data in the sandbox environment

Use Cases

  • Financial institutions for KYC compliance
  • E-commerce platforms for age verification
  • Government portals for citizen authentication
  • HR systems for employee verification

Base URL

https://api.sandbox.dpi.gov.lk/v1

API Catalog

All building blocks. One integration surface.

Every API in the catalog belongs to one of Sri Lanka’s DPI components. Learn one authentication model and one request pattern, then compose across all five.

  • SLUDI: Unique Digital Identity

    Authenticate users, run identity and eligibility checks and capture explicit consent before your application touches protected data.

  • National Data Exchange

    A secure data exchange platform that enables seamless API-based data sharing and interoperability across both state and corporate sectors.

  • Digital Payments

    A secure, interoperable payment layer for government services, built to replace cash and manual collection at the counter.

  • Verifiable Credentials

    Issue and verify digital certificates that prove a claim about a person or entity: independently checkable, without calling the issuer every single time.

  • Digital Signatures

    Bind a signer to a document or message so authenticity and integrity hold up as trusted electronic approval under Sri Lanka’s legal framework.

How it works

From sign-in to a working integration, without a procurement cycle.

The sandbox is self-service end to end. Nothing here requires an email to an agency or a signed agreement before you can write code.

  1. 01

    Sign in

    Federated sign-in with your GitHub or Google identity. You land straight in your Workspace: no account request form.

  2. 02

    Explore the catalog

    Browse by DPI building block. Read the endpoints, request formats and auth model before you commit to anything.

  3. 03

    Register an application

    Register an app and select the APIs it needs. Sandbox credentials are issued and scoped to that application alone.

  4. 04

    Test in a playground

    Supported APIs provision an isolated playground seeded with synthetic data. The rest route straight upstream: same console either way.

  5. 05

    Watch the numbers

    Calls, latency, error breakdowns and point consumption in real time. Upgrade a tier when you outgrow the free limits.

Testing

Two ways to test. One console.

How you test depends on the API, never on your tooling. Both paths run through the same “Try Out” console, the same sandbox credentials and the same metrics.

Isolated

Playground APIs

Selecting a supported API provisions a private playground seeded with synthetic data. You can run a complete user journey (verify an identity, issue a credential, sign it, take a payment) without a single real record in play.

  • Provisioned automatically per application
  • Seeded with synthetic identities and records
  • Mirrors production API behaviour
  • Reset and re-run as often as you need
Direct routing

Upstream APIs

Some APIs have no synthetic twin. For those the “Try Out” console routes your call straight to the upstream sandbox environment: same request builder, same sandbox-scoped credentials, same metrics coming back.

  • No playground provisioning step
  • Sandbox-scoped credentials only, always
  • Identical request and response tooling
  • Counted against the same API points

Predefined test scenarios, not just the happy path

Every playground ships with scenarios covering success, error, consent-denied, rate-limit and 404 responses, so you can prove your error handling before anyone else has to.

  • success
  • error
  • consent-denied
  • rate-limit
  • 404
Inside the sandbox

Everything you need, in three places.

The portal is organised around what you are actually doing at the time: building something, watching how it behaves, or getting unstuck.

Where you build

Workspace

Search the catalog, register applications, provision playgrounds and fire requests. Official DPI APIs come pre-installed, so there is no setup tax before your first call.

  • API Catalog
  • My Applications
  • Playgrounds
  • SDKs & Libraries
  • Try Out console

Where you watch

Observability

Total calls, successful and failed requests and average response time, with hourly traffic and a per-API breakdown of what is slow or erroring, alongside your point balance and tier.

  • Metrics Dashboard
  • Support & Incidents
  • Platform Status
  • Subscription & Billing
  • Compliance

Where you get unstuck

Learn

Hands-on walkthroughs across tech stacks on the government-maintained channel, plus AI tools that answer in plain language and rewrite examples into the language you actually ship in.

  • Academy
  • Video tutorials
  • Instant Code Translation
  • Smart Search
  • Reference docs
Access tiers

Start free. Prove it works. Then scale.

All three tiers reach the same sandbox APIs. What changes is how much you can call, and what governance comes with it.

  • Free

    Default for every developer

    No cost

    Generous API point limits so you can explore every sandbox API, build prototypes and throw work away without asking anyone first.

    • Every sandbox API
    • Isolated playgrounds
    • Metrics dashboard
    • Community support
    • Instant self-service sign-up
    Start free, Free tier
  • Extended Sandbox

    Most requested

    For serious builders

    Free · Given upon request

    Higher point limits for MVPs, hackathons and pilots. Access is granted through project verification, not payment.

    • Everything in Free
    • Raised API point ceilings
    • Project-based approval
    • Priority incident routing
    • Extended metrics retention
    Request access, Extended Sandbox tier
Isolated by design

No real citizen data. No production reach.

The sandbox is a non-production system by construction, not by policy note. These are the guarantees you can safely design against.

  • Synthetic data only

    Every playground runs on synthetic or anonymised records. No live system and no real citizen data is reachable from inside the sandbox.

  • Sandbox-scoped credentials

    Keys issued here work only here. There is no path from a sandbox credential to a production endpoint, by design rather than by convention.

  • Classified by sensitivity

    Every API carries a classification (Public, Internal, Confidential, Restricted or Top Secret) so the handling rules are clear before you call it.

  • Vetted before graduation

    Moving toward production means security and privacy self-assessments, consent-flow verification and administrative review against a published checklist.

Questions

Before you sign up

The things developers ask us first, answered without the policy language.

No. Sign in with GitHub or Google and you land on the Free tier immediately, with access to every sandbox API. Approval only enters the picture when you request a higher tier or start the graduation pathway toward production.

Ready to plug in?

Create an account, register your first application and have a playground answering requests in minutes. Free tier, no card, no procurement cycle.

Sandbox environment · Synthetic data only · No production access