---
title: Environments
description: Sandbox and production hosts for OAuth2/Token and API.
canonical: https://developer.unico.io/developers/start/environments
locale: en
generated_by: markdown-export
---

- [/](/)
- [Start](/developers/start/)
- Environments

**On this page# Environments

### Hosts by contract​

ContractSandbox hostProduction host**OAuth2 / Token**`https://identityhomolog.acesso.io``https://identity.acesso.io`**API**`https://api.idcloud.uat.unico.app``https://api.idcloud.unico.app`
### When to use sandbox​

Development and integration tests before production go-live.
Validating new flows or capabilities your tenant is being enabled for.
Reproducing customer-facing issues without affecting real data.

Credentials are environment-specificSandbox and production use **different credentials** (Client ID, private key, API key). Mixing credentials between environments is one of the most common causes of `401` errors. See [Authentication > Common errors](/developers/start/authentication#error-codes).
### Behavior differences​

The two environments share the same API contract — same endpoints, same payloads. They differ in:
AspectSandboxProduction**Credentials**Sandbox-onlyProduction-only**Real biometric data**No (test data only)Yes**Webhook delivery**Real (to your sandbox endpoint)Real**Rate limits**LowerSee [Rate limits](/developers/start/rate-limits)**Persistence**Periodically resetPermanent
### Hosts to allowlist for go-live​

If your (or your client's) network requires an explicit firewall/proxy allowlist before going to production, request the following hosts:

`cadastro.unico.app`
`id.unico.io`
`retry.unico.io`
`ultimatum.unico.io`
`backend-sdk.prod.private.unico.run`

If your firewall supports domain-level (wildcard) rules and you prefer fewer entries, you can allow these domains instead of the individual hosts above:

`*.unico.app`
`*.unico.io`
`*.unico.run`

Beyond Unico's own domains, the following third-party hosts are essential to the product's
operation (feature-flag evaluation, error tracking, and performance monitoring) and must also be
allowlisted:

`app.launchdarkly.com`
`clientstream.launchdarkly.com`
`events.launchdarkly.com`
`o939397.ingest.sentry.io`
`js-agent.newrelic.com`
`bam.nr-data.net`

If your firewall supports domain-level (wildcard) rules, you can allow these domains instead:

`*.launchdarkly.com`
`*.sentry.io`
`*.newrelic.com`
`*.nr-data.net`
Last updated on Oct 8, 2026**