Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousQuickstart
NextRecipes & Cookbooks
Under the Hood

How Sandboxing Works

Playground API combines an immutable global seed catalog with high-performance Copy-on-Write (CoW) session overlays. Discover how thousands of concurrent developers mutate endpoints independently without collisions or database maintenance.

The 3-Layer Copy-on-Write (CoW) Architecture

Every read request dynamically executes a three-stage pipeline to construct your realistic view of the world:

3-Layer Copy-on-Write (CoW) Engine Pipeline
CoW Architecture
Playground API 3-Layer Copy-on-Write Sandbox Engine Architecture & Workflow
Click to expand full architecture
Requests split between immutable seed baselines and private session overlays, merging in memory in <1ms.Interactive High-Resolution Flowchart
1Layer 1: Read-Only

Immutable Baseline Seed

Global seed dataset (100 posts, 10 users, 500 comments) acts as read-only blueprint.

2Layer 2: Private Delta

Visitor Mutation Overlay

All POST, PUT, and DELETE operations are stored in private diffs keyed by session identity.

3Layer 3: Merged View

In-Memory Query Resolver

Merges Layer 1 + Layer 2 in memory in <1ms with conflict resolution and tombstones.

1Read-Only

Immutable Baseline Seed

Global seed database containing 100 posts, 10 users, 500 comments, and 200 todos. It serves as the baseline blueprint and is never modified by any visitor.

2Private Overlay

Visitor Mutation Delta

When you call POST, PUT, or DELETE, your changes are stored in a private diff dictionary keyed by your unique session identity hash.

3Merged View

Virtual Query Resolver

When querying GET /posts, the resolver merges Layer 1 + Layer 2 in memory. Deleted items are filtered out, updated records are patched, and newly created items are prepended in <1ms.

What Happens When You Mutate

Here are the concrete behavioral guarantees provided by your sandbox overlay:

Creating Records (POST)

Newly created items are assigned an auto-incremented ID and saved to your private delta overlay. They immediately appear in subsequent GET /posts queries and increase total pagination counts.

Updating Records (PUT / PATCH)

Modifying an existing seed item (e.g. changing title on post #1) stores only your field patch in your overlay. The baseline record remains untouched for everyone else in the world.

Deleting Records (DELETE)

Deleting an item masks its ID in your visitor overlay. Subsequent collection queries filter it out, and single-item requests to GET /posts/:id return a realistic 404 Not Found.

Pagination & Sorting Integrity

Filters (?userId=1), full-text search (?q=keyword), and sorting (?_sort=id&_order=desc) execute on the merged dataset seamlessly.

Visitor Identity Resolution

How does the server route mutations to your private overlay? The API inspects incoming requests using a deterministic waterfall:

1. Browser Cookie

For web browsers, an HMAC-signed pg_identity cookie is automatically assigned on the first HTTP handshake with credentials: 'include'.

2. CI / Mobile Header

Pass an X-Playground-Identity header to isolate parallel test runners or mobile apps without cookies.

View CI/CD testing guide
3. JWT Token Claims

Attaching Authorization: Bearer <token> routes requests to the authenticated user account sandbox with role-based permissions.

Sandbox Lifecycle & Data Retention

10-Day Sliding Inactivity Window

Visitor sandboxes are kept alive as long as they receive requests. If a sandbox remains untouched for 10 consecutive days, the overlay is automatically recycled to keep the cluster pristine.

Instant Atomic Reset

Whenever you want to restart your application state from zero, make a DELETE /session/reset call. The server discards the session delta in microseconds.

Want to inspect your current session state?

Check your current memory quota, active mutations count, and session age in the Sandbox Dashboard.

Open Sandbox Dashboard