Sandbox access
The sandbox is a company of its own on Slflo, Nile Fresh (sandbox), holding the Nile Fresh day: a distributor’s day played through the real console and phone, so every document in it was made the way your customers’ documents will be. It runs in ERP mode API, and has one integration client, Sandbox, holding every scope.
Its token is an ordinary token of that company: it starts with sfi_live_, like every token the
console issues. “Sandbox” is the company, not the token — nothing in it is a real customer’s.
What’s in it
Section titled “What’s in it”One day, Africa/Cairo time, for four shops on one van round (Omar’s, REP-03, VAN-03). Two shops are visited; the other two stops are skipped at the end of the day.
| Feed | Documents |
|---|---|
/orders |
SO-000001 — Nile Market, van sale, 1,368.00, DELIVERED. SO-000002 — Delta Kiosk, pre-sale held over its credit limit, approved by the supervisor and delivered from the warehouse, 456.00, DELIVERED. |
/invoices |
INV-000001 (seq 1) for SO-000001, 1,368.00. INV-000002 (seq 2) for SO-000002, 456.00. |
/payments |
RC-000001 — 700.00 cash from Nile Market. RC-000002 — a post-dated cheque of 300.00 (Banque Misr, no. 100245), handed to the office. |
/returns |
RET-000001 — two Water 6-packs back from Nile Market against INV-000001, 114.00. |
All amounts are EGP, with VAT at 14% added to prices. The company sells two products, JUICE-1L
at 100.00 and WATER-6PK at 50.00, by the piece (unit PCS) or the carton of 12 (CTN), to four
shops: Nile Market, Delta Kiosk, Zamalek Corner and Garden City Grocer. Its company code is
t-sandbox (after a reset, t-sandbox-2 and so on); GET /me shows it in data.company.code.
The day was played before the company was switched to ERP mode API, so both orders are already
delivered and none waits for an ack: filter[ack]=pending answers no orders, and acking SO-000001
or SO-000002 answers 409 ORDER_NOT_AWAITING_ACK. The two invoices, two payments and the return
are there to ack. To try an order ack, ask us for a new order on the sandbox and pull it from
your cursor.
Getting a token
Section titled “Getting a token”Email hello@slflo.com with your company, the ERP you’re connecting, and who will build the connector. There’s no form on purpose: a person reads every request and approves it, because the token opens a company that other developers share.
We send the token once, by a separate channel from the email. Treat it like a password: keep it in your ERP’s encrypted settings or a secret store, never in source control.
What you can do with it
Section titled “What you can do with it”- Pull orders, invoices, payments and returns, and ack them.
- Push customers, branches, units, products, price lists, prices and balances.
- Run the whole go-live checklist.
What needs us
Section titled “What needs us”You hold an integration token, not a console sign-in. Anything that happens in the console or on a rep’s phone, we do for you on request at hello@slflo.com:
- a new pre-sale order that waits for your ERP (
ERP_PENDING), to try an order ack; - Send to ERP again on an order you refused;
- reversing a payment or bouncing a cheque, to see a document come back as pending.
Acks are shared like everything else: once another developer has acked INV-000001, a different
answer from you is 409 ALREADY_ACKNOWLEDGED, and it no longer appears in filter[ack]=pending.
If you need documents nobody has answered, ask us for fresh ones.
Check your token
Section titled “Check your token”export SLFLO_TOKEN='sfi_live_…' SLFLO_BASE='https://api.slflo.com/api/integration/v1'curl -s "$SLFLO_BASE/me" -H "Authorization: Bearer $SLFLO_TOKEN"curl -sg "$SLFLO_BASE/invoices?filter[seq_after]=0" -H "Authorization: Bearer $SLFLO_TOKEN"The first names the client Sandbox and the company t-sandbox; the second lists INV-000001
and INV-000002 with seq 1 and 2.
Running Slflo yourself
Section titled “Running Slflo yourself”If you run your own copy of Slflo for development, seeding the demo company (the seed profile)
registers a sandbox client and writes its token to build/sandbox-integration-token, readable
only by you; it is never printed to the log. That self-run token starts with sfi_test_. Set
SFA_SEED_SANDBOX_TOKEN=sfi_test_… to keep the same token across re-seeds; otherwise each seed
issues a new one and revokes the previous.

