Skip to main content
Sandbox lets you run the full Selfie Check (Beta) relying-party journey end-to-end — from your surface, through IDKit, into the sandbox World ID app, and back — without touching production identities or real proofs.
Selfie Check (Beta) must be enabled for your app before you can test it. To enable the feature flag, request access through your World point of contact.
New to Sandbox? Start with What is Sandbox? and How to get access before working through this guide.
In scope: the full relying-party journey — request handoff, consent, capture, enrollment and matching, proof generation, and delivery of the proof. Out of scope: production identity data and real-world uniqueness at scale. Sandbox accounts and proofs are for integration testing only, not load testing, security certification, or production sign-off.

Coverage

Testing is organized by entry surface and user state, using the same Hot, Cold, and Semi-cold states as the rest of World ID:
  • Hot — the user already has World ID installed. If they’re already Selfie Check enrolled, they go straight to face match; if not, World ID walks them through enrollment first, then match. (Selfie Check has no distinct Warm flow — enrollment happens inline within Hot, same as Verification Flows describes.)
  • Cold — a new user with no World ID app: the full funnel, including install, account creation, date of birth, invite code (iOS), enrollment, and Selfie Check.
  • Semi-cold — an existing user without World ID on this device: reinstall and account recovery, then Selfie Check.

Known limitations

  • Sandbox apps aren’t publicly listed in the app stores. Testers install through TestFlight on iOS or a private Google Play testing link on Android. Because those testing programs gate access, app-store acquisition can differ from a public production listing — see How to get access.
  • iOS Semi-cold is currently limited. The reinstall/login journey reliably works on Android today. On iOS, if the user taps “Sign in” instead of “Sign up” mid-flow, there’s no path to add the invite code — they have to restart from a fresh QR or deep link. Expect iOS Semi-cold to behave differently from Android until this is closed.
  • Invite-code handling in the Cold flow differs by platform. Confirm how invite codes are presented and redeemed on the platform you’re targeting — see invite-code mode.

Next step

Questions, or found a journey these scenarios don’t cover? Reach out to your World point of contact.