Three things developers get stuck on in the sandbox (and how to get past them)
Authentication, webhooks, and scope selection — the three places sandbox exploration usually stalls.
- Product
- Nylas
- Sent from
- nylas.com
- Sent
No dark-mode styles — this email renders the same in a dark client.
Authentication, webhooks, and scope selection — the three places sandbox exploration usually stalls. Most sandbox friction comes from three places. Based on questions in our developer forums and support queue, here's where developers most often hit a wall — and what to do about each one. 1. Authentication confusion: sandbox vs. development apps The sandbox comes with pre-configured connectors for Google, Microsoft, iCloud, and IMAP — you connect accounts directly without setting up your own OAuth app. This is intentional: it lets you test the API before you deal with provider credential setup. But this also means you can't add custom OAuth credentials in the sandbox. When you're ready to test with your own Google Cloud or Azure app, create a new Development environment application in the dashboard. The key concepts to have clear before you go further: - Application — the container for your API keys, grants, and config - API key — authenticates your server-side requests as a Bearer token - Grant — represents one connected user account (one Gmail inbox, one Outlook calendar). You get a grant_id after OAuth and pass it in every user-data API call: /v3/grants/<GRANT_ID>/messages - Connector — stores your Google or Microsoft OAuth app credentials at the application level 2. Webhooks: why they matter and how to set them up Webhooks are how Nylas pushes real-time notifications to your app — new emails, calendar changes, contact updates, grant status changes — without you having to poll. For most production integrations, webhooks are how you keep your data in sync. The full webhook setup guide is here: developer.nylas.com/docs/v3/webhooks/ (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg88T3lcq-W7Y8-PT6lZ3l5W5fpVJy1ylP-4W41cGlp71HGcBN4FPxXc2ct57W7J81VL8ZH3ZVW78rqsZ5BywdHW50ZC5f62W5SCV5z7C16B_DzVW3ryJ-v2TS5H2W94-0pY232sX1N327jbBbgWVNW1ZNcHG35xpPXW1YGB1B7hgxSYW2b8T6w2vP7JdVJbs3V92Jm4pW716xlP7lWn-RMCqF1QRCbcdN6c9sXg-nxXrW5qDJ0j25MQ9gW43Wxs746mZyyW8QNkRk5NM_GhW7gBQZ48fD1_vW3vBLrq1WQP4XW6BYNJ06VnfBQVJ7J2S997kQrW53Q2hj8bk8C4W2V1yMG4qRhGqf1HKfd-04 ) A few things worth knowing before you start: - Nylas blocks ngrok URLs. Use the VS Code port forwarding tunnel, the Nylas CLI tunnel, or Hookdeck for local testing. - Your endpoint must be publicly reachable before you register it. - When you register a webhook, Nylas sends a challenge request your endpoint must respond to — the guide above walks through this step by step. 3. Scope selection: only request what you need All scopes are enabled by default in the sandbox connectors, which makes it easy to explore. But in a real application, you should only request the scopes your use case actually requires. A common example: if you're building a calendar-only integration, don't request email scopes. Keeping your scope request minimal reduces your OAuth consent screen footprint, simplifies Google's verification review if you go that route, and is just good practice. You can configure which scopes your application requests in the connector settings of your Nylas dashboard. Still stuck? The developer forums at forums.nylas.com are active and searchable — most sandbox questions have already been asked and answered. You can also reach the support team directly from the dashboard. BROWSE THE DEVELOPER FORUMS (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg88z3lcq-W7lCdLW6lZ3nCW7gyxH62_hYznW7M7y956DkbBSW3HHVNT2YjMPhW6XsNcN3SLwkvW3Rxwkt8KMYnBW3pNVZF4svSMMW6NL5Fp3YdJWhN5YbPk4jD3ShW2KrqFQ403G8VW4t72wm6xQJ91W6gmlCv36Y4Z5W6Qw8Ls4B-LTdW4DgBf02CKWT0N3hytPDpKLJ-W4t17nT4zw6WSW8xYFcG4nwQL2W1ZBQrJ4GG48LN4fP1Gs2r3Z9W6RP1LV5vtH-3W6jX4FY1LtQwVN3cNr_MKqvFZW2RfbVL4ljhzhVNJ4s725386CW90cqWn82mVXLf6qBh7F04 ) P.S. Nylas is now native in the coding agents you're already using. The Nylas CLI, Nylas skill, and Claude Code plugin are all live. One command connects whatever stack you're on to the full Nylas API. Read the 'get started' doc. (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg8983lcq-W8wLKSR6lZ3p-W4ddLnC29cFXdMDdNJx6ZBBYW2GDZnR4k_CcdW4TLLSP1BZTbdVdVVNF4FLcj2W3RZb_c6kM6_WW5cHx3r7C2mYQW2x68MJ9bV8DgW8yP2Zd50w2mKVpBrDQ74vGMCW1wMbrT7xqLV5VWczkc2JNl1JN2Ft1zWmz7SYW2-LJZD9jY0LPVcyvCq292j7vN5_KPkxfrsKtW8TMNwf4R0tmnV4gWWf3JsT9YW1LtKzv51bqrZW71QVnl8gC_z3W2knQ7G5gdsr1W8JJhgz8R-CtmW7GBKhg5XZ4v4W37s8MG45XRnXW8CjsDN2_PZ0VW2TZzx423y7B_W6kT49k7NT65GW6MVCG04BFr8RcMbhT04 ) LinkedIn (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg88T3lcq-W7Y8-PT6lZ3ptW3_x0KF7RzQS_W85PDzw67f42rW43TZGl2LNHPxW8W_2l-60xFQWW4BbQ9J6HfxstW7dWcDR6-2MsfW4hnX_18wFHtjW6lBzM_8NSVNYM-J4NfptCZsW8qbbVb6dT6ggW3Tqcts7xVs_HW6nnhJj6WdsYWN3PhnhllYwtWW7l9y_N5Fy10fW1R94LJ2PkCxWVYX6rp4yHYszW4-1GKx5V6tnHW2r5wS_9lhT58W6CV0bG7-fJx_W7bYMsk7btDmSW5gLb0d4tp6x6W6dHrkj3RV2LFW5CbGcv9cxfNrW85nwfx4ShfSTW3PDFst2RkZ8fW2LSc4Z4dk_k2f3Nr6Zg04 ) X (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg88z3lcq-W7lCdLW6lZ3pbW5MlDcn5KRbVzN1lbN5C6whb0N2b9sZTcvJcbW7qscNv5TDYdyN1_x7fm6VZ0hW2lDqwx9cfkKyVN8WQ87hdDWBW3j2Z8D4KBMvqN6YjNr9rC5PDW44j7402vS2JhN293XcjGnfc3W4ggcNn9j-vkSV_RvSv4dgtgyW8gwCZc4HV_T4W89_dg-1_nTZmW1jCd8J5YZK78W5_ZJlS7lZ8tpVpbGKp8K8gjJW2dR7sm4sYc3pVjKpX_8bwMgRW6t--jN6m1ryrW6WPxG04rCLMbW3YFBbl7RMQYfW6cWK0353g41SdJ5CT404 ) YouTube (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg88z3lcq-W7lCdLW6lZ3pCW847LQv5p74wDW6488n25CkGcyW76t3yy609MTjW90MX_l7x30M0W7Lff-w3VRdfYVwHy2s3ykl6RW9cqt156--fDYW4_4q7C4Mh2W6W1Cn6YT7LR2cQW8wBQHw7M5Fg8N2FDl7pK9BJXW1v29Fg1NMrTXW4Sh0f46-QgQLW13HlTM7TYXrrW8pDkJy9kvnHfW2g_GlJ8nnN4lN3lPyc0dCJvxW9jx71b117d1nW7_pSH21K24ZbN37VwGsLs9LDW7hYWBV1zwkWtW77qSPS8LgHLCVRR8C43Y3xs8VzGrk67cXwWdf6v-MH804 ) github (https://d5hYdz04.na1.hubspotlinks.com/Ctc/Y+113/d5hYdz04/VVTpvW19BB69W1bq4T26Nq85FW824bMN5TNyGwN3Lg88z3lcq-W7lCdLW6lZ3nNW6w5dBt7569RpW5Xq1K88jCP8KW27D5Fx8Jh9GlW5GG6ch7X22vvW4CWh9Z3LM0GMW3C91l37Vfs72N21v_mGsqfh8W7jMgPt9f9Z_-W4TpMym1NnnzhW8lCLYm6mtczSW6-9vjS8XHfvtW6pWPm71jh1j6N4ns5xDfbvmFVbCwYm3lfZ5kW37cRdz3hFCMdW6jsr5P6smjRfW4Lg5yp4XwtjYW5vn5PF8y9PBDW6Pk83T5qTn9dV6-_bw766h9PW4Df1rf7Vjz4qW6ZMNtG4HhYN1W28LR0p44W1cWW25tHKc7P11bvdxYJmv04 ) Nylas, 2100 Geng Rd. #210, Palo Alto, CA 94303, USA Unsubscribe (https://hs-45023718.s.hubspotemail.net/hs/preferences-center/en/direct?data=W2nXS-N30h-RTW3P2YHX45kg6jW3VHNgh1_5-HKW30B1T-3NGMdSW1X8ZQ92RlGSlW2Ry4XR3dkfNkW3g25Wf4hGpX-W2p7w9h45DT6jW3K3pWm4mcbTqW4hDdQL3jfVZ4W2KpqNs49lYQzW36wtpS4cGnh5W3S_bGv3DT_smW2zxW_v1V7XnKW3db9b51VksF3W45ygWp2vHhqPW2Kz--w2RN8BTW3gtMbV3b504_W2MpCjN34zZh2W3P5tbz30sjvsW3JH9r21Nj0PfW3gxLv132y3gWW3d36972YfvDWW4pJbDw24_DtlW2ThY7L4mrh2jW2MCSXf3BZNk3W1BDDDb4ffxZzW1BKH5X4hgB2MW41D0Zf2Pl1NyW4pjthp1N4jSLW2r3bVK49PBWkW4ft8nV2FXKgXW4mCtrm4pFH_9W3g761H4mCtfXW4kvlR838mhy7W3zdxy52-lHSlW4fHRn-1V74wqW43F4CX3d1Qz-W3HdJLG2TM83kW4pHSjf2xMMLLW2FG2FR3GKQY0W3SLvXY1Q5LYpW2HzgPV3LXhRGW2sTVRT3GFC_cW3M6W2h3XZ8z8W2RPS_62w2PLGW4pbDwC1_t7HpW4klrPD4rCQXVW2KDsqw4p9M4jW1Lv9Gw2vHJ_9W3j0bjg2PyKFtW36y68_4ryz4_W3QKRl92-HxJKW3BMVL23W4TwyW4kGw8z2vXJ4lW2qVYLc21nQ4HW3VyFsq34fssTW34rvSC4mjgkqW2YFH-N2sFwtgW386swR3g6Bq7W3bzqhz1ZcGQsW1ZfM452PnyYsW30t75Y4fyfsSf3NT4Hp04&_hsenc=p2ANqtz-9eSWw7R6tMcaLa3aU_zi7XiT5U77YHEUsFUd2WzEPHEt7hbqTj8DqyFUbgybXWxcyeRgOdpJnoPAky1QO6NpwimAROAhqgMAIYqPJV7ZQ0Ggwwlr9IrBzZ9n5OLf5NJ0-f7ZMp&_hsmi=422472520 ) Manage preferences (https://hs-45023718.s.hubspotemail.net/hs/preferences-center/en/page?data=W2nXS-N30h-RTW3P2YHX45kg6jW3VHNgh1_5-HKW30B1T-3NGMdSW1X8ZQ92RlGSlW2Ry4XR3dkfNkW3g25Wf4hGpX-W2p7w9h45DT6jW3K3pWm4mcbTqW4hDdQL3jfVZ4W2KpqNs49lYQzW36wtpS4cGnh5W3S_bGv3DT_smW2zxW_v1V7XnKW3db9b51VksF3W45ygWp2vHhqPW2Kz--w2RN8BTW3gtMbV3b504_W2MpCjN34zZh2W3P5tbz30sjvsW3JH9r21Nj0PfW3gxLv132y3gWW3d36972YfvDWW4pJbDw24_DtlW2ThY7L4mrh2jW2MCSXf3BZNk3W1BDDDb4ffxZzW1BKH5X4hgB2MW41D0Zf2Pl1NyW4pjthp1N4jSLW2r3bVK49PBWkW4ft8nV2FXKgXW4mCtrm4pFH_9W3g761H4mCtfXW4kvlR838mhy7W3zdxy52-lHSlW4fHRn-1V74wqW43F4CX3d1Qz-W3HdJLG2TM83kW4pHSjf2xMMLLW2FG2FR3GKQY0W3SLvXY1Q5LYpW2HzgPV3LXhRGW2sTVRT3GFC_cW3M6W2h3XZ8z8W2RPS_62w2PLGW4pbDwC1_t7HpW4klrPD4rCQXVW2KDsqw4p9M4jW1Lv9Gw2vHJ_9W3j0bjg2PyKFtW36y68_4ryz4_W3QKRl92-HxJKW3BMVL23W4TwyW4kGw8z2vXJ4lW2qVYLc21nQ4HW3VyFsq34fssTW34rvSC4mjgkqW2YFH-N2sFwtgW386swR3g6Bq7W3bzqhz1ZcGQsW1ZfM452PnyYsW30t75Y4fyfsSf3NT4Hp04&_hsenc=p2ANqtz-9eSWw7R6tMcaLa3aU_zi7XiT5U77YHEUsFUd2WzEPHEt7hbqTj8DqyFUbgybXWxcyeRgOdpJnoPAky1QO6NpwimAROAhqgMAIYqPJV7ZQ0Ggwwlr9IrBzZ9n5OLf5NJ0-f7ZMp&_hsmi=422472520 )
- Accession
- nse/nylas/2026-09-10/1123
- From
- Joel Garcia · tips@nylas.com
- Sent
- 10 September 2026 · 14:00 UTC




