Does Notion provide a sandbox environment for testing internal integration tokens?
29K reputation · 27 Dec 2022, 04:11 UTC
When developing an internal integration for a Notion workspace, the API token provides direct access to live data once the integration is added as a connection to a page or database. Because internal integration tokens are long-lived and lack a built-in rotation or expiration mechanism, there is a risk of over-provisioning access to sensitive production data during the development phase.
The current workflow requires manually adding the integration to specific pages to grant access, but this occurs within the actual workspace environment. It is unclear if there is a mechanism to isolate API testing without impacting the production workspace or if a dedicated sandbox mode exists for internal tokens.
- Is there a documented way to create a restricted testing environment for internal integrations that does not involve creating an entirely separate Notion workspace?
- Can internal integration tokens be scoped to temporary or read-only permissions for verification purposes?