{"slug": "show-hn-free-public-api-lab", "title": "Show HN: Free Public API Lab", "summary": "LockFlare launched Free Public API Lab, a set of seven mock APIs covering e-commerce, IoT, banking, social, helpdesk, flights and a company directory, backed by 78,076 related records and served over REST, GraphQL, OData, gRPC-Web, SOAP, JSON-RPC, XML-RPC, Socket.IO, WebSocket, Server-Sent Events, MQTT and MCP, with SAML, SCIM and OAuth on top. The service requires no keys, accounts or database, and includes a Model Context Protocol test server over Streamable HTTP plus sandboxes that imitate Stripe, Twilio, SendGrid, Authorize.net, OpenAI, Anthropic and six secrets managers so official SDKs work against them with the host swapped. LockFlare built the lab as the playground for its LockFlare Sonda tool.", "body_md": "# Free mock APIs that answer like real ones.\n\nSeven complete fake APIs — e-commerce, IoT, banking, social, helpdesk, flights and a company directory — with 78,076 related records, over REST, GraphQL, OData, gRPC-Web, SOAP, JSON-RPC, XML-RPC, Socket.IO, WebSocket, Server-Sent Events, MQTT and MCP, with SAML, SCIM and OAuth on top — and a [FHIR R4 server](https://sondahub.com/fhir-test-server/) over a synthetic clinic. No keys, no accounts, no database — and still, what you write is there when you read it back, because the state travels with you. Built as the playground for [LockFlare Sonda](https://lockflare.com/sonda).\n\n## The mock APIs\n\nEach one is a small world with thousands of related records, ids that never change, and behaviour a real backend has: a transfer checks the funds and writes a transaction on each side, a ticket refuses an impossible status, a booking gets a seat.\n\n### Store API\n\nAn online shop: products, customers, orders, reviews and stock.\n\n### Fleet API\n\nAn IoT fleet: sites, devices, telemetry and alerts — the MQTT one.\n\n### Bank API\n\nRetail banking: customers, accounts, cards, nearly eight thousand transactions, transfers and FX rates.\n\n### Social API\n\nA social network: users, posts, comments, likes and follows — the GraphQL one.\n\n### Helpdesk API\n\nA support desk: tickets, messages, agents, customers, SLAs — the state-machine one.\n\n### Flights API\n\nAirports, airlines, two and a half thousand scheduled flights and their bookings — the live-board one.\n\n### Identity API\n\nA company directory: people, groups and memberships — behind SCIM 2.0, SAML and OpenID Connect.\n\n### MCP test server\n\nThe same seven worlds as a Model Context Protocol server over Streamable HTTP — data tools, domain tools, resources, prompts and completions — plus tools built to test an MCP client: progress, errors, images, every content type.\n\n### HTTP test endpoints\n\nEcho, any status code, delays, redirects, cookies, gzip, streams, uploads — and every auth scheme, checked for real: Basic, Digest, API key, Bearer, AWS SigV4, OAuth 2 with PKCE, JWT.\n\n## Testing tools\n\nThe things a real backend does to a client — and the things a client has to do to a real backend. One page each, with examples that run from the page.\n\n## Every protocol\n\nThe same data, whichever way your client talks.\n\n## Sandboxes for the APIs you integrate\n\nStand-ins for Stripe, Twilio, SendGrid, Authorize.net, OpenAI and Anthropic — and for the secrets managers: AWS Secrets Manager, Azure Key Vault, Google Secret Manager, 1Password Connect, Doppler and Infisical — that the official SDKs work against with the host swapped and the session token carried: the vendors’ test cards and magic numbers, bounces and opens, settlement, a scripted model that answers the same way every time, secret versions, rotation and sign-ins, and callbacks signed their way. Independent imitations, not affiliated with any of these companies.\n\n### Stripe sandbox\n\nA Stripe mock API the official SDK works against: test cards, 3D Secure, refunds, Checkout, signed webhooks.\n\n### Twilio sandbox\n\nA Twilio mock API: SMS, calls, Verify and Lookups, magic numbers, signed status callbacks.\n\n### SendGrid sandbox\n\nA SendGrid mock API: Mail Send with real validation, templates rendered, bounces and opens, signed Event Webhooks.\n\n### Authorize.net sandbox\n\nAn Authorize.net mock API: XML and JSON checked like the real one, test triggers, settlement every minute, profiles, subscriptions, signed webhooks.\n\n### OpenAI sandbox\n\nAn OpenAI mock API with a scripted model: chat completions, the Responses API, streaming, tool calls, structured outputs, embeddings, errors on cue.\n\n### Anthropic sandbox\n\nA Claude API mock with a scripted model: messages, streaming, tool use, signed thinking blocks, prompt caching, batches, errors on cue.\n\n### AWS Secrets Manager sandbox\n\nAn AWS Secrets Manager mock for boto3 and the SDKs: all 23 actions, SigV4 checked, versions and labels, rotation, deletion windows, replicas.\n\n### Azure Key Vault sandbox\n\nAn Azure Key Vault mock the Azure SDK signs in to: the bearer challenge, an Entra ID token endpoint, versions, soft delete, recover, purge, backup.\n\n### Google Secret Manager sandbox\n\nA Google Secret Manager mock for the client libraries over REST: versions, aliases, CRC32C checks, delayed destruction, IAM, a service account.\n\n### 1Password Connect sandbox\n\nA 1Password Connect server mock: vaults, items, generated passwords, one-time codes, files, JSON Patch, activity.\n\n### Doppler sandbox\n\nA Doppler API mock: configs and branch inheritance, references resolved, every download format for doppler run, logs and rollback, service tokens.\n\n### Infisical sandbox\n\nAn Infisical API mock: Universal Auth, raw secrets v3 and v4, references expanded, folders, imports, versions, personal overrides.\n\n[How the sandboxes work](https://sondahub.com/sandboxes/): same paths, errors and behaviour as the real API; your data in a session token; webhooks your SDK’s own signature check accepts. No account to open.\n\n## Writes that stick, with no database\n\nsondahub keeps nothing — there is no database behind it, only files and code. Yet a POST you send is there on your next GET. Every write is validated, run through the real rules and answered as a real server would, and the answer carries a token holding everything you have changed so far. Send it back and the next request starts from your world instead of the seed:\n\n```\nPOST  /v1/store/orders  {\"customer_id\":1,\"items\":[…]}\n      → 201 Created, order 3001, priced\n        X-Sondahub-Session: s1.…\n\nGET   /v1/store/orders/3001             X-Sondahub-Session: s1.…\n      → 200, the order you just placed\nPATCH /v1/store/orders/3001  {\"status\":\"shipped\"}\n      → 200, stamped shipped_at and a tracking number\nGET   /v1/store/orders?sort=-id\n      → yours first, the total one higher\n```\n\nNobody else sees your writes and nobody can break your tests; drop the token and the world is the seed again. The examples on every page share one session until you reload. [How the session works.](https://sondahub.com/mock-api-with-persistence/)\n\n## Three steps in Sonda\n\nEverything an API here offers can be loaded into Sonda without typing a request by hand.\n\n### Import an API\n\nEvery API publishes an OpenAPI document. Import → From a URL, paste `https://api.sondahub.com/v1/store/openapi.json`, and the whole project appears with example bodies.\n\n### Send things\n\nLists with filters, a record by id, a POST that gets validated and priced, a PATCH that moves a status. Wrong bodies come back as 422 with every field named.\n\n### Go live\n\nA WebSocket or SSE request on `/v1/fleet/ws` or `/v1/fleet/events` streams the world's own activity. The MQTT pane connects to `wss://api.sondahub.com/mqtt`.\n\n## Questions people ask\n\n### Is sondahub free? Do I need an API key?\n\nFree, with no account, no key and no signup. Every endpoint answers anyone over HTTPS. The [auth test endpoints](https://sondahub.com/auth-test-endpoints/) use playground credentials printed on the page — public on purpose, so a client can prove a flow works.\n\n### How much data is there, and does it behave like a real backend?\n\nsondahub serves 78,076 related records in 37 collections, ids that never change, filters, sorting, search and relations — and the behaviour of a real backend: a bank transfer checks the funds and writes a transaction on each side, a ticket refuses an impossible status change, a flight booking picks a free seat, and a wrong body gets a 422 naming every field.\n\n### Do POST, PUT, PATCH and DELETE work? Do they persist?\n\nYes, and yes — for you. A write is validated, run through the real rules and answered with the status, headers and body a real server would send. The answer also carries an `X-Sondahub-Session` token holding everything you have changed; send it back on the next request and that request sees your writes: POST an order, GET it, PATCH it, list it. There is no database — the state travels with you, so nobody else sees it and nobody can break your tests. [How the session works.](https://sondahub.com/mock-api-with-persistence/)\n\n### Can I call it from a browser, a frontend demo or a mobile app?\n\nYes. CORS is open to every origin and preflight requests are answered, so `fetch()` from any page works, and so do the WebSocket and SSE streams. The raw [JSON data files](https://sondahub.com/data-files/) are open to every origin too.\n\n### Which protocols are there?\n\n[REST](https://sondahub.com/fake-rest-api/) with OpenAPI 3 documents, [GraphQL](https://sondahub.com/public-graphql-api/) with introspection, [OData 4](https://sondahub.com/odata-test-server/) with $metadata and $batch, [FHIR R4](https://sondahub.com/fhir-test-server/) over a synthetic clinic, [gRPC-Web and Connect](https://sondahub.com/grpc-web-test-server/) with .proto files, [SOAP 1.1 and 1.2](https://sondahub.com/soap-test-server/) with a WSDL per API (and WS-Security), [JSON-RPC 2.0 and XML-RPC](https://sondahub.com/json-rpc-test-server/), [Socket.IO](https://sondahub.com/socket-io-test-server/), [WebSocket](https://sondahub.com/websocket-test-server/), [Server-Sent Events](https://sondahub.com/sse-test-server/), [MQTT 3.1.1 and 5 over WebSocket](https://sondahub.com/public-mqtt-broker/), an [MCP server](https://sondahub.com/mcp-server/) for AI agents (and an [OAuth-protected one](https://sondahub.com/mcp-oauth-test-server/)), [SCIM 2.0](https://sondahub.com/scim-test-server/), [SAML 2.0](https://sondahub.com/saml-test-idp/), and [HTTP test endpoints](https://sondahub.com/utilities/) with every auth scheme including an [OAuth 2.0 / OpenID Connect server](https://sondahub.com/oauth2-test-server/).\n\n### Can I test single sign-on and user provisioning?\n\nYes — against a whole company. The [Identity API](https://sondahub.com/apis/identity/) is a directory of 300 people in 40 groups, and the same people sign in through the [SAML IdP](https://sondahub.com/saml-test-idp/) and the [OIDC server](https://sondahub.com/oauth2-test-server/) and are provisioned through the [SCIM 2.0 server](https://sondahub.com/scim-test-server/). Point Okta, Entra ID or your own SP at it; the test SP checks what your IdP sends, signature by signature.\n\n### Can I test a Stripe, Twilio, SendGrid or Authorize.net integration without an account?\n\nYes, against the [sandboxes](https://sondahub.com/sandboxes/): a [Stripe mock API](https://sondahub.com/sandboxes/stripe/), a [Twilio mock API](https://sondahub.com/sandboxes/twilio/), a [SendGrid mock API](https://sondahub.com/sandboxes/sendgrid/) and an [Authorize.net mock API](https://sondahub.com/sandboxes/authorizenet/) that the official SDKs work against with the host swapped and the session token carried — Stripe’s test cards and 3D Secure, Twilio’s magic numbers and delivery receipts, SendGrid’s validation, templates, bounces and opens, Authorize.net’s schema checks, test triggers and settlement, and webhooks signed so the vendor’s own library or recipe verifies them. They are independent imitations, not the vendors’ own test modes.\n\n### Can I test code that calls OpenAI or Claude without paying for tokens?\n\nYes: the [OpenAI mock API](https://sondahub.com/sandboxes/openai/) and the [Claude API mock](https://sondahub.com/sandboxes/anthropic/) answer the official SDKs with a scripted model — chat completions and the Responses API, messages, streaming, tool calls, structured outputs, thinking blocks, embeddings, batches — the same answer for the same request, checked like the real API. Set the SDK’s base URL to the sandbox and any key will do; a phrase in the message such as `[[tool]]`, `[[refuse]]` or `[[error:429]]` picks the outcome your code has to handle.\n\n### Can I test code that reads secrets from AWS Secrets Manager, Key Vault, Doppler or 1Password?\n\nYes: the [AWS Secrets Manager](https://sondahub.com/sandboxes/aws-secrets-manager/), [Azure Key Vault](https://sondahub.com/sandboxes/azure-key-vault/), [Google Secret Manager](https://sondahub.com/sandboxes/google-secret-manager/), [1Password Connect](https://sondahub.com/sandboxes/1password-connect/), [Doppler](https://sondahub.com/sandboxes/doppler/) and [Infisical](https://sondahub.com/sandboxes/infisical/) mocks answer the official SDKs with a seed of fake secrets — versions and labels, rotation, soft delete, references resolved, the vendors’ sign-ins and errors — so the code that loads your configuration at boot, rotates a password or rolls a value back can be tested without an account. Never send them a real secret: they are public playgrounds.\n\n### Can I mock my own API?\n\nYes: give the [OpenAPI mock server](https://sondahub.com/openapi-mock-server/) the address of any OpenAPI 3 or Swagger 2 file and it serves that API — routes matched, requests validated against the spec, answers from your examples or generated from your schemas, the same answer for the same request. And any endpoint here takes [latency, failures, rate limits](https://sondahub.com/api-chaos-testing/) and [signed webhooks](https://sondahub.com/webhook-tester/) on request.\n\n### Is there an OpenAPI spec I can import?\n\nEvery API publishes an OpenAPI 3.0.3 document at `https://api.sondahub.com/v1/{api}/openapi.json`, with schemas and example bodies. Import it into [Sonda](https://lockflare.com/sonda) or any client or code generator that reads OpenAPI.\n\n### Can AI agents and LLMs use it?\n\nYes. The [MCP server](https://sondahub.com/mcp-server/) gives an agent 26 tools over the same data; [the OAuth-protected one](https://sondahub.com/mcp-oauth-test-server/) walks a client through the MCP authorization flow — protected-resource metadata, dynamic client registration, PKCE, audience and scopes. [llms.txt](https://sondahub.com/llms.txt) and [llms-full.txt](https://sondahub.com/llms-full.txt) describe every endpoint in one plain-text file.\n\n### Is any of the data real?\n\nNo. Every person, order, account, card and booking is generated from a fixed seed — emails use reserved example domains and card numbers are masked. The airports are real airports; the airlines are invented. The patients of the [FHIR clinic](https://sondahub.com/fhir-test-server/) are synthetic too, every resource tagged as test data, with real LOINC, SNOMED CT and RxNorm codes. Same rows on every build, so ids in your tests stay valid.\n\n### Can I run it myself?\n\nA curated version of the hub is open source under the MIT License ([on GitHub](https://github.com/lockflare/sondahub-core)). It is not everything sondahub.com runs, but it serves on localhost on plain Node, which suits a CI run that should not depend on a public service.", "url": "https://wpnews.pro/news/show-hn-free-public-api-lab", "canonical_source": "https://sondahub.com/", "published_at": "2026-10-05 20:58:21+00:00", "updated_at": "2026-10-05 21:20:45.085846+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools", "agent-protocols", "ai-agents"], "entities": ["LockFlare", "Free Public API Lab", "LockFlare Sonda", "Model Context Protocol", "Stripe", "Twilio", "SendGrid", "OpenAI"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-free-public-api-lab", "markdown": "https://wpnews.pro/news/show-hn-free-public-api-lab.md", "text": "https://wpnews.pro/news/show-hn-free-public-api-lab.txt", "jsonld": "https://wpnews.pro/news/show-hn-free-public-api-lab.jsonld"}}