Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousPassword Recovery Loop
NextGraphiQL IDE
Auth & Security

Dual-Mode Session Sandboxing

Playground API supports dual session isolation modes: automatic browser cookies for interactive web apps, and explicit X-Playground-Identity headers for headless CI/CD test runners. Seamlessly bridge anonymous session data with authenticated user personas.

Interactive Identity Mode Tester

Select an isolation mode below to test header precedence and session overlay routing:

Execute: CI/CD Worker Identity Header

GET
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

Identity Resolution Precedence Hierarchy

How the API determines session routing when multiple identifiers are present:

Priority 1 (Highest)
X-Playground-Identity

Explicit header passed by CI/CD runners or headless scripts. Overrides all cookies.

Priority 2
?_sandbox=uuid

Query parameter for QR code mobile syncing, manual browser debugging, and bookmarkable sandboxes.

Priority 3
pg_identity (Cookie)

Cryptographically signed HttpOnly cookie automatically issued to standard browser clients.

Priority 4 (Fallback)
Auto-Provisioning

If no identity is detected, the server automatically provisions a fresh sandbox and sets the cookie.

Testing & CI/CD Integration Recipes

How to configure parallel test runners with isolated sandbox states:

sandboxClient.ts
1
// Playwright E2E Parallel Worker Fixture (Zero Test Pollution)
2
import { test as base, expect } from '@playwright/test';
3
4
// Extend base test to inject a unique sandbox identity per test worker
5
export const test = base.extend<{ sandboxId: string }>({
6
sandboxId: async ({}, use, testInfo) => {
7
// Unique identity per worker and test title
8
const id = e2e-${testInfo.workerIndex}-${testInfo.testId};
9
await use(id);
10
},
11
12
// Automatically attach X-Playground-Identity to all page requests
13
page: async ({ page, sandboxId }, use) => {
14
await page.setExtraHTTPHeaders({
15
'X-Playground-Identity': sandboxId,
16
});
17
await use(page);
18
},
19
});
20
21
test('isolated user creation and mutation', async ({ page }) => {
22
await page.goto('/dashboard');
23
// Mutations execute inside this worker's private overlay
24
});