Skip to main content
This is the most confusing thing about the API for a newcomer, so plainly:
  • A vsk_test_ key emails only addresses you have verified on Test recipients, plus the members of your organisation whose sign-in address has been verified. A send to anybody else is refused — it is not silently dropped.
  • It is never billed and never counts against your plan’s document allowance.
  • What it produces is a watermarked sandbox document that binds nobody. Nothing signed with a test key is legally valid. It is a real sealed PDF — so your verification code has something to run against — sealed by a certificate issued for the sandbox and for nothing else, and that certificate is what says the document binds no one.
  • A vsk_live_ key is the opposite of all three. The two are separate credentials; the environment is inside the hashed value, so a test secret cannot be re-presented under a live prefix.