# Testing
source: https://developer.mastercard.com/mastercard-processing-mastercard/documentation/testing/index.md

### Ready to begin testing? {#ready-to-begin-testing}

Tip: We recommend that you begin testing in the Sandbox environment.

Once you have created a project on Mastercard Developers, generated sandbox credentials and received approvals, you can begin testing.
> **You can follow this page to learn:**
>
> * The testing workflow
> * Scenario guidance (positive and negative, read/write/delete, Sandbox versus Production)
> * Copy-paste cURL test cases for each endpoint family

## Testing workflow {#testing-workflow}

1. **Set up your environment:** Ensure that you have your Sandbox credentials and the base URL:   
   <https://sandbox.api.mastercard.com/global-processing/mastercard-services/cards/searches>   
   Configure your API client (for example, Postman) with your OAuth 1.0a keys.
2. **Execute test calls:** Run the sample test cases provided in the following sections.
3. **Validate responses:** Verify the HTTP response codes, such as `201 Created` or `200 OK` and confirm that the response payloads match the expected results.

### Testing with Postman {#testing-with-postman}

If you prefer a GUI-based testing tool instead of cURL, we provide ready-to-use Postman collections with pre-configured OAuth 1.0a authentication.

For a comparison of supported tools, see the [Developer Tools](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/developer-tools/index.md) page. Then follow the setup instructions in the [Postman Collection Guide](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/developer-tools/index.md#ready-to-begin-testing) to get started.

## Authentication header reference {#authentication-header-reference}

All cURL examples on this page require the following headers:

* An OAuth 1.0a Authorization
* A `Client-Encryption-Key` header  

The first example in the following section shows the complete header configuration. For readability, subsequent examples use truncated values, such as `Authorization: OAuth ...` and `Client-Encryption-Key: MIIE...`.

Use the [Mastercard OAuth library](https://github.com/Mastercard/oauth1-signer-java) to generate the `oauth_timestamp`, `oauth_nonce`, `oauth_body_hash`, and `oauth_signature` values automatically.

    Authorization: OAuth oauth_consumer_key="YOUR_CONSUMER_KEY",
        oauth_signature_method="RSA-SHA256",
        oauth_timestamp="GENERATED",
        oauth_nonce="GENERATED",
        oauth_version="1.0",
        oauth_body_hash="GENERATED",
        oauth_signature="GENERATED"

## Sample test cases {#sample-test-cases}

Warning: The cURL test cases show an unencrypted request and response body. In practice, all operations require end-to-end JWE payload encryption. Refer to [Encryption](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/api-basics/index.md#transport-encryption) for more information.

### 1. Generate payload for card registration in the Carbon Calculator program {#1-generate-payload-for-card-registration-in-the-carbon-calculator-program}

```shell
curl -X POST "https://sandbox.api.mastercard.com/global-processing/mastercard-services/cards/searches" \
  -H "Content-Type: application/json;charset=UTF-8" \
  -H "Authorization: OAuth oauth_consumer_key=\"YOUR_CONSUMER_KEY\", \
oauth_signature_method=\"RSA-SHA256\", \
oauth_timestamp=\"GENERATED\", \
oauth_nonce=\"GENERATED\", \
oauth_version=\"1.0\", \
oauth_body_hash=\"GENERATED\", \
oauth_signature=\"GENERATED\"" \
  -H "Client-Encryption-Key: MIIEZDCCA0ygAwIBAgIQQUmirRSB0Og8AbLmOXxo/DANBgkqhkiG9w0BAQUFADCBrjETMBEGCgmSJomT8ixkARkWA2NvbTEaMBgGCgmSJomT8ixkARkWCm1hc3RlcmNhcmQxHTAbBgNVBAoTFE1hc3RlckNhcmQgV29ybGRXaWRlMSQwIgYDVQQLExtHbG9iYWwgSW5mb3JtYXRpb24gU2VjdXJpdHkxNjA0BgNVBAMTLVBSRCBNQyBQcm9kdWN0aW9uIE5ldHdvcmsgQXBwbGljYXRpb25zIHN1YiBDQTAeFw0xNjAxMDUwODEwMzJaFw0yMDAxMDMyMzA2MjBaMIHKMUcwRQYDVQQDEz5XcmFwcGluZyBLZXkgLSBUb2tlbml6YXRpb24gQVBJIFNhbmRib3ggRW5jcnlwdCAtIE1ERVMgRGVjcnlwdDETMBEGA1UECxMKTURFUyAtIE1URjE0MDIGA1UEChMrTWFzdGVyQ2FyZCBXb3JsZFdpZGUgLSBDb21tb24gUHJvZEluZnJhIFNTTDEUMBIGA1UEBxMLU2FpbnQgTG91aXMxETAPBgNVBAgTCE1pc3NvdXJpMQswCQYDVQQGEwJVUzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALMQmc1tg4Olwn15Zu20Ojxn10U5p/IwhM7oXZTC+p1LnCYlA0So+R1BOXaCRqCJvVxprJW2l1nBJ/mBcPP1B0V8OoQErYDFQoBzxnbf6aRdoJ7YL/OBb1GYOvFoDtE4+iGvW9sCHD0uYHiOhYFm5JsJ24Tq9qj0xEo/2qcqcpibBnzEEqxUaaIyurbzGSTctohq2fnuj8jLt87r9JBXlV5Jb1oKMK3sR7zRz6l6oip6bgfytHyonQAqbuxuhKj7IqFjE+UyEos5anhP+gKB+PUm59BDI9KKik9xiLhzOL8JSNYG1Vew0QFFr5dpjc4ZAEDgcp8g/fpgkbKHUzwIdhECAwEAAaNgMF4wHwYDVR0jBBgwFoAUPeXQ5iyKbL1ne56Kq3GEPOrclQUwDAYDVR0TBAUwAwIBADAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0OBBYEFOqIblm9zwz+xo1K9WzEZ0MI8asSMA0GCSqGSIb3DQEBBQUAA4IBAQCMcAHSlE8N4r0yvtNU4R2qhlmDltBjv63XADjNSRxYzdtkgq/4CbjgiLqNGKbkkba9hDsUcjRzTe86lnRL7HG1M5j0lV5b6i0nHaQEjDcdOfTwfOkCyP9aRD08POGA8tday45pBvegMLwNudDNZ5Rhc4LVbyHNxF0NNCIsXCzqpQoQ3FV6A3/8/fV7Fwj1vKxZVtvh7cjZwlArfE9BncDD2X5FBKdIUxYmhq8AeFHUZiLwBK0DLRpoE7nKUQ6KkgSG4YF3r7XuF+WTJAF4wdb2Opt7BY7kj/WHuxU+gps3qO1JwkvYcKrF2r2MYyNJqNB/esCUspOtA8vMNS/WmhB4" \
  -d '{
    "requestType": "CARBON_CALCULATOR",
    "carbonCalculatorProfiles": [
      {
        "id": "1c40daf6-69c9-4055-ab72-d46ed0a30ca5",
        "cardContractId": 70001,
        "currency": "EUR"
      }
    ]
  }'
```

##### Expected response (200 OK) {#expected-response-200-ok}

```json
{
    "requestType": "CARBON_CALCULATOR",
    "carbonCalculatorPayload": {
        "encryptedData": "604d111e835bbd88c3850d350c334c4fa8cee0ea4c2c852c9c8a803de2ed18f35a936ecf973247dd3792610c5e098c7636bfe9c3021978dabc02fa79c9425815f80cc712084991ac9cdc4e7f1342e022c2d0e53e71d2786d55fb6dc92b1324fd",
        "publicKeyFingerprint": "3e3ff1c50fd4046b9a80c39d3d077f7313b92ea01462744bfe50b62769dbef68",
        "encryptedKey": "4f49e1c7a5a16ad54ae690e2a30926b9970260683e4b7f26384f8f8360300464081bb897d9f46701d410b33b11b186cea9bba959cce3e772cd69da501fe4045b8af957dd93091061af7cd80cb32bbb9b49b12a2f7f53695824d6ded5aa77da4d11527afb9f8367aae0d3832e9e176b8686a03a142a4c10927448cce73bd201f6c7cfd5010ee00769ac11fc02eba83552b907c4f4f0f4a95fb6f748ef748ba8f0cacb393b770666832ffa3ff2e00bf85255c04258fe8d59c329cdbbec96dcf0161a844b8b5c5b956a91f98bfb3a79dd1f71fc20a2bf18e0d16435356447346edb95bf374e0f34a1657501a82409f5c15568ab91231716a78c3cc8efbff068c448",
        "oaepHashingAlgorithm": "SHA256",
        "iv": "b008db942ff2f5fb6ec58c409f6d1d77"
   }
}
```

```shell
curl -X POST "https://sandbox.api.mastercard.com/global-processing/mastercard-services/cards/searches" \
  -H "Content-Type: application/json;charset=UTF-8" \
  -H "Authorization: OAuth ..." \
  -H "Client-Encryption-Key: MIIE..." \
  -d '{
    "requestType": "CARBON_CALCULATOR",
    "carbonCalculatorProfiles": [
      {
        "id": "2c40dff6-69c9-4055-ab72-d46ed0a30bb9",
        "cardContractId": 70001,
        "currency": "EUR"
      },
      {
        "id": "1c40gaf6-69c9-4077-ab72-d47ed0a30ca5",
        "cardContractId": 10001,
        "currency": "EUR"
      }
    ]
  }'
```

##### Expected response (200 OK) {#expected-response-200-ok}

```json
{
    "requestType": "CARBON_CALCULATOR",
    "carbonCalculatorPayload": {
        "encryptedData": "604d111e835bbd88c3850d350c334c4fa8cee0ea4c2c852c9c8a803de2ed18f35a936ecf973247dd3792610c5e098c7636bfe9c3021978dabc02fa79c9425815f80cc712084991ac9cdc4e7f1342e022c2d0e53e71d2786d55fb6dc92b1324fd",
        "publicKeyFingerprint": "3e3ff1c50fd4046b9a80c39d3d077f7313b92ea01462744bfe50b62769dbef68",
        "encryptedKey": "4f49e1c7a5a16ad54ae690e2a30926b9970260683e4b7f26384f8f8360300464081bb897d9f46701d410b33b11b186cea9bba959cce3e772cd69da501fe4045b8af957dd93091061af7cd80cb32bbb9b49b12a2f7f53695824d6ded5aa77da4d11527afb9f8367aae0d3832e9e176b8686a03a142a4c10927448cce73bd201f6c7cfd5010ee00769ac11fc02eba83552b907c4f4f0f4a95fb6f748ef748ba8f0cacb393b770666832ffa3ff2e00bf85255c04258fe8d59c329cdbbec96dcf0161a844b8b5c5b956a91f98bfb3a79dd1f71fc20a2bf18e0d16435356447346edb95bf374e0f34a1657501a82409f5c15568ab91231716a78c3cc8efbff068c448",
        "oaepHashingAlgorithm": "SHA256",
        "iv": "b008db942ff2f5fb6ec58c409f6d1d77"
    },
  "failedCards": [
    {
      "cardContractId": 10001,
      "reasonCode": "CARD_CONTRACT_DOES_NOT_EXIST",
      "description": "Card contract with id 10001 not found."
    }
  ]
}
```

For this test case, use the following information in the request:

|     Field      | Available value |
|----------------|-----------------|
| cardContractId | 10001           |

```shell
curl -X POST "https://sandbox.api.mastercard.com/global-processing/mastercard-services/cards/searches" \
  -H "Content-Type: application/json;charset=UTF-8" \
  -H "Authorization: OAuth ..." \
  -H "Client-Encryption-Key: MIIE..." \
  -d '{
    "requestType": "CARBON_CALCULATOR",
    "carbonCalculatorProfiles": [
      {
        "id": "1c40daf6-69c9-4055-ab72-d46ed0a30ca5",
        "cardContractId": 10001,
        "currency": "EUR"
      }
    ]
  }'
```

##### Expected response (404 Not Found) {#expected-response-404-not-found}

```json
{
  "Errors": {
    "Error": [
      {
        "Source": "MASTERCARD PROCESSING",
        "ReasonCode": "CARD_CONTRACT_DOES_NOT_EXIST",
        "Description": "Card contract with id 10001 not found.",
        "Recoverable": false
      }
    ]
  }
}
```

## Next steps {#next-steps}

* Proceed to the [Developer Tools](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/developer-tools/index.md) section to download the Postman Collections and start making API calls.
* Download our Spring Boot [Reference Application](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/developer-tools/reference-app/index.md) to see a typical implementation of the Mastercard Processing API.
* Review the [Codes and Formats](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/code-and-formats/index.md) section to understand supported error codes and response formats.
