# Simulate negative responses with request headers (/negative-testing/request-headers)



## Request headers [#request-headers]

> **Note:** **Note:** If you do not use the specific test values, the
> service returns the actual API responses.

You can use request headers to test the following Payments API and Orders API
methods:

* [Payments API v1](/api/deprecated/payments/v1/)

  * [Create payment](/api/deprecated/payments/v1/payment-create/)

  * [Execute approved PayPal payment](/api/deprecated/payments/v1/payment-execute/)

* [Payments API v2](/api/payments/v2/)

  * [Show details for authorized payment](/api/payments/v2/authorizations-get/)

  * [Capture authorized payment](/api/payments/v2/authorizations-capture/)

  * [Void authorized payment](/api/payments/v2/authorizations-void/)

  * [Show captured payment details](/api/payments/v2/captures-get/)

  * [Refund captured payment](/api/payments/v2/captures-refund/)

  * [Show refund details](/api/payments/v2/refunds-get/)

* [Orders API v2](/api/orders/v2/)

  * [Create order](/api/orders/v2/orders-create/)

  * [Update order](/api/orders/v2/orders-patch/)

  * [Show order details](/api/orders/v2/orders-get/)

  * [Authorize payment for order](/api/orders/v2/orders-authorize/)

  * [Capture payment for order](/api/orders/v2/orders-capture/)

## Set up your development environment [#set-up-your-development-environment]

Before you can use request headers to simulate negative responses, you must
set up your development environment. After you get a token that lets you
access protected REST API resources, you create sandbox accounts to test your
web and mobile apps. For details, see
[Get started](/platforms/get-started/).

Then, return to this page to use request headers to simulate negative
responses.

### Invoke negative testing [#invoke-negative-testing]

|    |                                                                        |
| -- | ---------------------------------------------------------------------- |
| 1. | [Enable negative testing](#enable-negative-testing).                   |
| 2. | [Test API error handling routines](#test-api-error-handling-routines). |
| 3. | [Test with negative testing](#test-with-negative-testing).             |

### Enable negative testing [#enable-negative-testing]

REST API apps use a request header to invoke negative testing in the sandbox.
This header configures the sandbox into a negative testing state for
transactions that include the merchant.

To enable negative testing:

* Add a key to the `PayPal-Mock-Response` request header in your
  API call.

### Test API error handling routines [#test-api-error-handling-routines]

To simulate an error, add a `mock_application_codes` value that
equals the error code to test:

| Request header         | Type | Example                                            |
| ---------------------- | ---- | -------------------------------------------------- |
| `PayPal-Mock-Response` | JSON | `"mock_application_codes": "DUPLICATE_INVOICE_ID"` |

For the available error codes, see
[Payment API Error Messages](/api/payments/v2/errors/)
and
[Orders API Error Messages](/api/orders/v2/error-messages).

### Test with negative testing [#test-with-negative-testing]

With a valid access token, you can make REST API calls for negative testing.

#### Example request [#example-request]

<div className="pl-[1.625rem]" />

```bash lineNumbers
curl -X POST \
https://api-m.sandbox.paypal.com/v2/checkout/orders/7WH94211LK834082R/capture \
  -H 'Authorization: Bearer <Access-Token>' \
  -H 'Content-Type: application/json' \
  -H 'PayPal-Mock-Response: {"mock_application_codes": "DUPLICATE_INVOICE_ID"}'
```

Where:

| Header                 | Value                                                                                              |
| ---------------------- | -------------------------------------------------------------------------------------------------- |
| `Content-Type`         | `application/json`                                                                                 |
| `Authorization`        | `Bearer <Access-Token>`<br />See                 [get an access token](/api/rest/authentication/). |
| `PayPal-Mock-Response` | `{\"mock_application_codes\": \"<error_name>\"}`                                                   |

#### Example response [#example-response]

<div className="pl-[1.625rem]" />

```json lineNumbers
{
  "name": "UNPROCESSABLE_ENTITY",
  "details": [
    {
      "issue": "DUPLICATE_INVOICE_ID",
      "description": "Duplicate Invoice ID detected. To avoid a potential duplicate transaction your account setting requires that Invoice Id be unique for each transaction."
    }
  ],
  "message": "The requested action could not be completed, was semantically incorrect, or failed business validation.",
  "debug_id": "70c28ae654da",
  "links": [
    {
      "href": "/api/orders/v2/#error-DUPLICATE_INVOICE_ID",
      "rel": "information_link",
      "method": "GET"
    }
  ]
}
```
