# sondahub > Free, public mock APIs for testing API clients, apps and agents: 7 populated fake APIs (e-commerce, IoT fleet, banking, social network, helpdesk, flight booking, company directory) with 78,076 related records in 37 collections, over REST, GraphQL, gRPC-Web / Connect, WebSocket, Server-Sent Events, MQTT over WebSocket and a Model Context Protocol (MCP) server — plus SAML 2.0, SCIM 2.0, OAuth 2.0 / OIDC with dynamic client registration, an OpenAPI mock server, signed webhooks, chaos and rate-limit controls, and httpbin-style test endpoints. No API key, no signup, CORS open. Writes (POST, PUT, PATCH, DELETE, GraphQL mutations, gRPC, SCIM, MCP write tools) are validated, run through real rules and answered as a real server would — 201 with the record and a Location header, 422 naming every wrong field. Nothing is stored on the server: the answer carries an `X-Sondahub-Session` token holding the client's changes, and a request that sends it back (header, or `?_session=`) sees them — the record comes back on GET, in lists and in totals. Ids never change, so examples stay valid. - API base: https://api.sondahub.com/v1 (a JSON index of everything) - MCP server: https://api.sondahub.com/mcp (Streamable HTTP, stateless, no auth); OAuth-protected: https://api.sondahub.com/mcp/secure - gRPC-Web / Connect: https://api.sondahub.com/grpc/sondahub.{api}.v1.{Api}Service/{Method}; .proto at https://api.sondahub.com/v1/{api}/{api}.proto - SCIM 2.0: https://api.sondahub.com/scim/v2 (Bearer sonda-scim-token) · SAML IdP metadata: https://api.sondahub.com/saml/metadata · test SP: https://api.sondahub.com/saml/sp - OpenAPI mock: https://api.sondahub.com/v1/mock?spec={url} - MQTT broker: wss://api.sondahub.com/mqtt (WebSocket only, MQTT 3.1.1 and 5) - Raw data: https://api.sondahub.com/data/{api}/{collection}.json - Built as the playground for LockFlare Sonda, an API client: https://lockflare.com/sonda ## APIs - [Store — fake e-commerce API](https://sondahub.com/apis/store/): An online shop: products, customers, orders, reviews and stock. 20,730 records. OpenAPI: https://api.sondahub.com/v1/store/openapi.json · GraphQL: https://api.sondahub.com/v1/store/graphql - [Fleet — fake IoT API](https://sondahub.com/apis/fleet/): An IoT fleet: sites, devices, telemetry and alerts — the MQTT one. 6,248 records. OpenAPI: https://api.sondahub.com/v1/fleet/openapi.json · GraphQL: https://api.sondahub.com/v1/fleet/graphql - [Bank — fake banking API](https://sondahub.com/apis/bank/): Retail banking: customers, accounts, cards, nearly eight thousand transactions, transfers and FX rates. 10,047 records. OpenAPI: https://api.sondahub.com/v1/bank/openapi.json · GraphQL: https://api.sondahub.com/v1/bank/graphql - [Social — fake social media API](https://sondahub.com/apis/social/): A social network: users, posts, comments, likes and follows — the GraphQL one. 25,800 records. OpenAPI: https://api.sondahub.com/v1/social/openapi.json · GraphQL: https://api.sondahub.com/v1/social/graphql - [Helpdesk — fake helpdesk API](https://sondahub.com/apis/helpdesk/): A support desk: tickets, messages, agents, customers, SLAs — the state-machine one. 7,398 records. OpenAPI: https://api.sondahub.com/v1/helpdesk/openapi.json · GraphQL: https://api.sondahub.com/v1/helpdesk/graphql - [Flights — fake flight booking API](https://sondahub.com/apis/flights/): Airports, airlines, two and a half thousand scheduled flights and their bookings — the live-board one. 6,056 records. OpenAPI: https://api.sondahub.com/v1/flights/openapi.json · GraphQL: https://api.sondahub.com/v1/flights/graphql - [Identity — fake user directory API](https://sondahub.com/apis/identity/): A company directory: people, groups and memberships — behind SCIM 2.0, SAML and OpenID Connect. 1,797 records. OpenAPI: https://api.sondahub.com/v1/identity/openapi.json · GraphQL: https://api.sondahub.com/v1/identity/graphql ## Guides - [Fake REST API](https://sondahub.com/fake-rest-api/): CRUD over 37 collections with paging, filters, sorting, search and relations. - [Public GraphQL API](https://sondahub.com/public-graphql-api/): Seven schemas with introspection, nested relations and mutations. - [gRPC-Web & Connect](https://sondahub.com/grpc-web-test-server/): Every API as a protobuf service, unary and streaming, .proto files included. - [WebSocket test server](https://sondahub.com/websocket-test-server/): An echo socket and live JSON event streams. - [SSE test server](https://sondahub.com/sse-test-server/): Server-Sent Events with ids, named events and resumption. - [Public MQTT broker](https://sondahub.com/public-mqtt-broker/): MQTT 3.1.1 and 5 over WebSocket with live IoT telemetry. - [MCP test server](https://sondahub.com/mcp-server/): A Model Context Protocol server over Streamable HTTP. - [MCP OAuth test server](https://sondahub.com/mcp-oauth-test-server/): The MCP authorization flow end to end: metadata, DCR, PKCE, audience. - [Writes that persist](https://sondahub.com/mock-api-with-persistence/): POST, then GET it back — with no database: the state travels with you. - [OpenAPI mock server](https://sondahub.com/openapi-mock-server/): Point it at any OpenAPI or Swagger file and get a working mock. - [Webhook tester](https://sondahub.com/webhook-tester/): Signed webhooks to your endpoint: Standard Webhooks, Stripe or GitHub style. - [Chaos and rate limits](https://sondahub.com/api-chaos-testing/): Latency, failures, 429s, idempotency keys, cursors, CSV and XML on any endpoint. - [SAML test IdP and SP](https://sondahub.com/saml-test-idp/): Sign in with SAML, or check what your IdP sends — signatures and all. - [SCIM 2.0 test server](https://sondahub.com/scim-test-server/): Users and Groups with filters, PATCH, Bulk and discovery. - [OAuth 2.0 test server](https://sondahub.com/oauth2-test-server/): Authorization code with PKCE, client credentials, OIDC, dynamic registration. - [Auth test endpoints](https://sondahub.com/auth-test-endpoints/): Basic, Digest, API key, Bearer, JWT and AWS SigV4, checked for real. - [HTTP test endpoints](https://sondahub.com/utilities/): Echo, status codes, delays, redirects, cookies, gzip, uploads. - [Fake JSON data](https://sondahub.com/data-files/): 37 downloadable datasets, 78,076 rows. - [JSONPlaceholder alternative](https://sondahub.com/jsonplaceholder-alternative/): When six small resources are not enough. - [Stripe sandbox](https://sondahub.com/sandboxes/stripe/): A Stripe mock API the official SDK works against: test cards, 3D Secure, refunds, Checkout, signed webhooks. - [Twilio sandbox](https://sondahub.com/sandboxes/twilio/): A Twilio mock API: SMS, calls, Verify and Lookups, magic numbers, signed status callbacks. ## Sandboxes (independent imitations of vendor APIs, not affiliated with the vendors) - [Stripe sandbox](https://sondahub.com/sandboxes/stripe/): Stripe's API at https://api.sondahub.com/v1 (customers, payment_methods, payment_intents, charges, refunds, products, prices, checkout/sessions, events, webhook_endpoints, balance) — any sk_test_ key, Stripe's test cards, signed webhooks; OpenAPI https://api.sondahub.com/sandbox/stripe/openapi.json - [Twilio sandbox](https://sondahub.com/sandboxes/twilio/): Twilio's API at https://api.sondahub.com/2010-04-01, https://api.sondahub.com/verify/v2 and https://api.sondahub.com/lookups/v2 — any Account SID, magic numbers, signed status callbacks; OpenAPI https://api.sondahub.com/sandbox/twilio/openapi.json ## Optional - [Full reference in one file](https://sondahub.com/llms-full.txt): every collection, field, endpoint, tool and utility - [Connect from Sonda or any client](https://sondahub.com/connect/)