generated: '2026-09-06' method: searched source: >- https://dev.dotcms.com/getting-started/setup/demo-instance, https://dev.dotcms.com/docs/demo-site, https://demo.dotcms.com/ description: >- dotCMS's sandbox is not a test MODE inside a production account — the usual SaaS shape — it is a whole disposable instance the company runs at demo.dotcms.com, preloaded with a sample site, sample content types and admin access, with published credentials. There is no test/live key separation to record because there are no shared keys: every dotCMS deployment is its own tenant, so "test vs live" at dotCMS is "which instance URL did you point at". That is why this file records an instance and a reset schedule where a payments provider would record card numbers. type: shared-demo-instance separation_model: per-instance # There is no test-mode key prefix. Isolation is by DOTCMS_URL / baseURL, not by credential. instance: url: https://demo.dotcms.com admin_console: https://demo.dotcms.com/dotAdmin api_base: https://demo.dotcms.com/api openapi: https://demo.dotcms.com/api/openapi.json graphql: https://demo.dotcms.com/api/v1/graphql contents: Preconfigured demo instance including sample content, APIs and admin access. published_credentials: username: admin@dotcms.com password: admin source: https://dev.dotcms.com/docs/demo-site note: >- Published by dotCMS in its own documentation for the shared demo instance. Recorded verbatim because they are public documentation values, not a secret — but they are shared and resettable by anyone, and dotCMS says so: "It is possible for another user to login to the Demo Site and change the login credentials." reset: schedule: 12:00 and 00:00 EST (GMT-5), daily downtime: 5-15 minutes after each reset data_loss: >- "All work done on the site will be lost each time the site resets." Treat every write against demo.dotcms.com as ephemeral with a horizon of at most twelve hours. recovery: >- If the published credentials stop working because another user changed them, dotCMS advises waiting for the automatic reset or contacting info@dotcms.com. anonymous_access: verified: '2026-09-06' probes: - url: https://demo.dotcms.com/api/openapi.json status: 200 note: full 754-operation OpenAPI, no credentials required - url: https://demo.dotcms.com/api/v1/appconfiguration status: 200 note: instance configuration, no credentials required - url: https://demo.dotcms.com/api/v1/graphql status: 200 note: 'POST {"query":"{__typename}"} answers anonymously; __schema introspection is disabled' note: >- Useful for agents: the demo instance answers the discovery surface without any token at all, so an agent can read the contract and shape a call before it has credentials for anything. local_alternative: name: Run locally docs: https://dev.dotcms.com/docs/getting-started/setup/run-locally developer_instance: https://dev.dotcms.com/docs/dotcms-developer-instance note: >- The durable sandbox is a local instance (Docker) or a dotCMS Developer Instance — the demo site is for reading and for one-shot experiments, not for building against. test_values: published: false note: >- dotCMS publishes no magic test identifiers, test cards, test clocks or fixture triggers. There is nothing of that shape to capture, and none was invented. The sample content that ships with the demo starter is the fixture set.