generated: '2026-08-30' method: searched source: >- https://developers.sandbox.game/api/ + https://developers.sandbox.game/what-is/ + https://developers.sandbox.game/unity/reference/ + https://docs.sandbox.game/en/about/terms-of-use-privacy-and-legal + https://github.com/thesandboxgame/sandbox-smart-contracts (package READMEs) + npm metadata for the @sandbox-smart-contracts scope summary: >- Cross-cutting standards conformance read from what The Sandbox actually publishes. The REST API declares OAuth 2.0 and ISO 8601 and nothing else; it is not OpenAPI-described in any reachable form, not RFC 9457, and carries no OIDC discovery. The company's genuine standards footprint is on the OTHER surface - the Ethereum/Polygon token contracts, which implement the ERC family for the NFT-gaming market and say so in their own package documentation. entries: - id: oauth2 name: OAuth 2.0 conforms: true evidence: - url: https://developers.sandbox.game/what-is/ quote: 'Authenticate users using our OAuth-based identity system.' - url: https://developers.sandbox.game/unity/reference/ quote: >- RequestAuthorization() starts the browser authentication flow; RequestToken(string code) requests a token using the provided code; OAuthSettings carries clientId, clientSecret, redirectUri. note: >- Authorization-code flow with refresh tokens. The RFC-level detail (endpoints, PKCE, scope names) is not published - the page that would carry it returned 503 on 2026-08-30. - id: oidc name: OpenID Connect conforms: false evidence: - url: https://developers.sandbox.game/.well-known/openid-configuration status: 404 - url: https://api.sandbox.game/.well-known/openid-configuration status: 404 note: No discovery document is served on any host. OAuth 2.0 only. - id: rfc8414 name: 'RFC 8414 OAuth 2.0 Authorization Server Metadata' conforms: false evidence: - url: https://developers.sandbox.game/.well-known/oauth-authorization-server status: 404 - url: https://api.sandbox.game/.well-known/oauth-authorization-server status: 404 - id: rfc9116 name: 'RFC 9116 security.txt' conforms: false evidence: - url: https://developers.sandbox.game/.well-known/security.txt status: 404 - url: https://api.sandbox.game/.well-known/security.txt status: 404 see: well-known/the-sand-box-well-known.yml - id: rfc9457 name: 'RFC 9457 Problem Details for HTTP APIs' conforms: false evidence: - url: https://developers.sandbox.game/api/ quote: >- The published error table is a code + message registry (invalid_json, invalid_request_url, invalid_request, unauthenticated, unauthorized, rate_limited); no application/problem+json media type is mentioned. see: errors/the-sand-box-problem-types.yml - id: iso8601 name: 'ISO 8601 date and time' conforms: true evidence: - url: https://developers.sandbox.game/api/ quote: 'Dates and timestamps follow ISO 8601: Datetime: 2020-08-12T02:12:33.231Z Date: 2020-08-12' - id: rfc4122 name: 'RFC 4122 UUID (version 4)' conforms: true evidence: - url: https://developers.sandbox.game/api/ quote: 'Top-level resources use a UUIDv4 "id" property.' - id: pagination name: Cursor pagination conforms: true evidence: - url: https://developers.sandbox.game/unity/reference/ quote: >- Asset listing calls take limit and searchAfter, an opaque forward cursor rather than an offset. note: Documented only through the SDK reference; the wire parameter spelling is unconfirmed. - id: idempotency name: Idempotent request replay conforms: false evidence: - url: https://developers.sandbox.game/api/ quote: >- The Conventions section covers HTTPS, JSON, ids, naming and dates and documents no idempotency key, and no request header of any kind is published. see: conventions/the-sand-box-conventions.yml - id: openapi name: OpenAPI description conforms: unknown evidence: - url: https://developers.sandbox.game/api/docs/ status: 503 note: >- The provider states a Swagger playground exists and is "Available" - "Swagger Playground - Try the API live with real data and schemas". Its route is served by the same backend that was returning nginx 503 on 2026-08-30, so the OpenAPI behind it could neither be fetched nor ruled out. Recorded as unknown, never as absent and never as present. - url: https://developers.sandbox.game/openapi.json status: 404 - url: https://developers.sandbox.game/swagger.json status: 404 - url: https://api.sandbox.game/openapi.json status: 404 - url: https://api.sandbox.game/swagger.json status: 404 - url: https://api.sandbox.game/docs status: 200 note: Returns a Cloudflare Access sign-in page, not a document. - id: graphql name: GraphQL conforms: false evidence: - url: https://api.sandbox.game/graphql status: 404 body: '{"error":"Page not found"}' - id: gdpr name: 'EU General Data Protection Regulation' conforms: true evidence: - url: https://docs.sandbox.game/en/about/terms-of-use-privacy-and-legal quote: 'Does The Sandbox adhere to GDPR? Yes, The Sandbox adheres to the EU General Data Protection Regulation (GDPR).' note: >- A self-declared regulatory posture in the company's own documentation, not a certification. NO `Compliance` pointer is emitted - The Sandbox publishes no trust center and names no audited certification (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) anywhere reachable. domain_standard: market: NFT / blockchain gaming (Ethereum + Polygon token standards) declared_in: smart-contract packages, NOT the REST contract conforms: true caveat: >- IMPORTANT read-me-first: this conformance belongs to The Sandbox's ON-CHAIN surface. The REST Developers API declares no domain standard of its own, and none should be inferred for it from the rows below. standards: - id: erc-721 name: 'ERC-721 Non-Fungible Token Standard' conforms: true evidence: url: https://github.com/thesandboxgame/sandbox-smart-contracts/blob/master/packages/land/README.md quote: >- 'Land - ERC721 contract handling the LAND tokens deployed on the ethereum network (L1)'; 'PolygonLand - ERC721 contract handling the LAND tokens deployed on the polygon network (L2)' package: '@sandbox-smart-contracts/land' - id: erc-1155 name: 'ERC-1155 Multi Token Standard' conforms: true evidence: url: https://github.com/thesandboxgame/sandbox-smart-contracts/blob/master/packages/asset/README.md quote: "Asset (ERC1155) L2 token. Asset's user-facing contracts: AssetCreate, AssetReveal. AuthSuperValidator. Catalyst (ERC1155) L2 token." package: '@sandbox-smart-contracts/asset' - id: erc-2771 name: 'ERC-2771 Secure Protocol for Native Meta Transactions' conforms: true evidence: url: https://registry.npmjs.org/@sandbox-smart-contracts/dependency-metatx quote: 'ERC2771 handler used to implement meta-tx' package: '@sandbox-smart-contracts/dependency-metatx' - id: opensea-operator-filter name: 'OpenSea Operator Filter Registry (marketplace royalty enforcement)' conforms: true evidence: url: https://registry.npmjs.org/@sandbox-smart-contracts/dependency-operator-filter quote: "Implementation for OpenSea's operator filter" package: '@sandbox-smart-contracts/dependency-operator-filter' note: >- A de facto market convention rather than a published standard; recorded because it is a real interoperability commitment declared by a first-party package. not_claimed: - id: erc-20 reason: >- SAND is widely described as an ERC-20 token, but no first-party package README reachable in this pass states it in those words, so it is left unasserted rather than assumed.