Runs are served only in the sandbox, because a deliberate fault must never reach a real trader.
Connect apps run in the sandbox today. Once production opens to them, your app’s Connect pass opens
its production, as Open production describes.
Before you start
- Your app works end to end in the sandbox: your server creates Connect links, your page opens hosted Connect on your website, and your backend reads your traders’ accounts and routes their orders. The Connect quickstart gets you there.
- Your backend holds your app’s sandbox API key, and you can sign in to the Connect dashboard as an owner or an editor of your app.
- Your white-label paper is on, or your Connect offers a provider you hold a sandbox login for, so a test trader can complete a connection.
- Use test traders, never real ones. While a run is open, requests made with your app’s API keys, and the Connect links they create, can receive deliberate errors. Outside a run the sandbox behaves normally.
1
Open a run
In the Connect dashboard, open Conformance and start a run. It’s graded under the
connect
ruleset at version 1.0, and it lists its rules, each with how to exercise it. A run stays open
for two hours, and you can have one open at a time.2
Use your app
Go through the journey your traders take, more than once. During the run, make sure your app
does all of this:
The run also answers some of your requests badly, once each, for your app to handle:
Every request the run sees answers with the header
x-trdrs-conformance-run, naming the run, and
each deliberate error also carries x-trdrs-conformance-fault. An expired Connect link looks
exactly as a real one does. Handle each the way you would in production.3
Read the tally
Check progress in Conformance at any time while the run is open. The grade lists each rule as
passed, failed or not exercised, with its counts and a note saying what to do next or what went
wrong. One failure fails its rule, and later successes don’t
erase it. A fault your app hasn’t answered yet counts only when the run closes.
4
Close the run
Close the run in Conformance to grade it. After the injected risk lock, wait at least ten
seconds first.The run closes passed only when every rule was exercised and passed. A rate limit, a dropped
stream or an expired link your app never answered fails its rule; a risk lock you left alone for
ten seconds passes. A passed run carries a certificate, twelve months on. Deliberate errors stop
the moment the run closes.
What a pass means
A pass measures how your app handled the journey and its faults on the wire. It earns a certificate that stays current for twelve months under the ruleset’s major version, and a new major version expires it at once. When it nears its end, run again: runs are free, and a passing one takes an afternoon. Nothing on your Connect shows that your app passed. From a current certificate, the sandbox signs a Connect pass addressed to production, for an app the Connect dashboard opened in both environments. The pass names that production app, the owner’s verified email, the run and when its certificate expires, and it opens your app’s production. A pass can’t see your screens. Check yourself that a money field that’snull shows as unknown,
never as zero.
Open production
Open your app’s production with its Connect pass, once a run has passed. An owner of your app opens it from Conformance in the Connect dashboard: the dashboard reads your app’s pass from the sandbox and hands it to production. Production checks that the sandbox signed it, for this app and for your own verified email, and records it. Your app’s production is open from then:- You create production API keys, which start
trdrs_ck_production_. - Each production website you add applies at once. It’s an exact
httpsorigin. - Your app is billed at $2 per active trader each month, from the month production records its first pass. Active traders says who counts.
Your app keeps running in production when its certificate expires: its API keys, websites and
traders work as before. A new API key needs a certificate that stands, so pass a fresh run and open
production again with its pass. A new major version of the ruleset expires every certificate at
once.
403 with one of these codes:
Until your app holds a pass, production answers its API key and website routes with
409
conformance_required. Once its certificate has expired, a new API key is answered with 409
conformance_expired.
When a run is refused
The routes this page calls
The Connect dashboard makes these calls with your team’s Connect sign-in:Next steps
Route your traders' orders
Fix what the run found in your order routing and streams.
Connect SDK
Handle
connect_unavailable and the other events on your page.Active traders
See how Connect is billed per active trader.
Rate limits
Read how a
429 and its Retry-After work.