---
title: "Get Mandatory Training sandbox"
canonical: "https://getmandatorytraining.com/sandbox"
---

# Get Mandatory Training sandbox

How to rehearse the Get Mandatory Training API's calls with side effects, against the live site, without emailing anyone or storing anything. There's no separate test environment: the test mode below is the sandbox.

## Reads need no sandbox

Reading the catalogue changes nothing, so call the live API: it's free, with no key, sign-up or approval.

```
curl 'https://getmandatorytraining.com/agent/courses?country=US'
curl 'https://getmandatorytraining.com/agent/courses/cpr-aed'
curl 'https://getmandatorytraining.com/agent/acceptance?country=US'
```

## Test addresses

Two calls have side effects: registering for a learner and enrolling, which each send an email. Both have a test mode. Use an email address at a reserved test domain, which can never belong to a person:

- `example.com`, exactly;
- `example.net`, exactly;
- `example.org`, exactly;
- any domain ending `.test`.

A test request is checked exactly like a real one and counts against the same limits, but nothing is sent and nothing is stored: no account, enrolment, app or connection. Its answer is the usual one plus `"test": true`.

## Rehearse registration

Register for a test address. The answer has a `client_id`, a `claim_token` and `"test": true`:

```
curl -X POST https://getmandatorytraining.com/agent/auth -H 'Content-Type: application/json' \
  -d '{"name":"Sandbox rehearsal","email":"agent@example.com","scope":"account.read certificates.read"}'
```

Poll the token endpoint with the `claim_token`, no faster than every `interval` (5) seconds. The first poll answers `authorization_pending`; the next returns test tokens, with no person involved:

```
curl -X POST https://getmandatorytraining.com/oauth/token -d grant_type=urn:workos:agent-auth:grant-type:claim \
  -d client_id=<client_id> -d claim_token=<claim_token>   # authorization_pending
sleep 5
curl -X POST https://getmandatorytraining.com/oauth/token -d grant_type=urn:workos:agent-auth:grant-type:claim \
  -d client_id=<client_id> -d claim_token=<claim_token>   # access_token and refresh_token
```

Test tokens start `gmt_test_`, last as long as real ones, and refresh and revoke the same way. On the account MCP server they only ever read a made-up **sample learner**: two sample courses and one sample certificate, every result marked `"sample": true`. A test token can never read a real account, and a real token never sees the sample.

```
curl -X POST https://getmandatorytraining.com/mcp/account -H 'Authorization: Bearer <access_token>' \
  -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"my_account","arguments":{}}}'
```

Revoke the tokens when you're done:

```
curl -X POST https://getmandatorytraining.com/oauth/revoke -d client_id=<client_id> -d token=<refresh_token>
```

## Rehearse enrolment

The enrolment call behind our in-page tools takes a test address too. Get a form token first, and wait at least its `min_wait_ms` before using it:

```
curl https://getmandatorytraining.com/agent/enrol-token
curl -X POST https://getmandatorytraining.com/agent/courses/cpr-aed/enrol -H 'Origin: https://getmandatorytraining.com' \
  -d name='Test Learner' -d email=learner@example.org -d country=US -d state_us=NY -d ft=<token>
```

It answers `{"result":"email_sent","test":true,…}`, and no email is sent.

## The real thing

Real enrolling, and allowing an assistant to read an account, are always done by the person themselves, on the site. See [the API docs](https://getmandatorytraining.com/agent/docs#sandbox), [auth.md](https://getmandatorytraining.com/auth.md) and [the developer portal](https://getmandatorytraining.com/developers) for the rest.

Mandatory Training is an independent training provider, not affiliated with or endorsed by the American Heart Association®, the Red Cross®, the Heart and Stroke Foundation of Canada, the Canadian Red Cross, Resuscitation Council UK, the British Red Cross, St John Ambulance, the New Zealand Resuscitation Council, ANZCOR, St John New Zealand, New Zealand Red Cross or any government body. Course content is based on published AHA/ECC and ILCOR guidelines. Fully online training does not include a hands-on skills assessment, and some employers and licensing bodies require one, so check with yours before you rely on it.
