Developers
Get Started
OpenAPI ↗
REST API v1 · Developer previewLive API credentials are not yet generally available. Hosted test access is not enabled.

Getting started

Authentication

One secret key, one account, one environment.

Production access disabled

The executable quickstart uses the local fixture API. The server facade is unreleased; hosted test provider wiring and authorized billing are not installed. Domestic production booking also requires declared_value; international and imported-order booking remain disabled.

Use a Bearer key

Authorization: Bearer $PX_API_KEY

Use keys from your server only. Do not embed them in browser JavaScript, mobile apps, URLs or public repositories. HTTPS is required for the future hosted API; HTTP is permitted only for the loopback fixture sandbox.

Key lifecycle

Keys use px_test_ and px_live_ prefixes, followed by 256 bits of random secret material. The sandbox stores SHA-256 hashes, account identity, scopes, optional expiration and last-used time; the raw key is shown at provisioning. Revocation takes effect on the next authentication check. Missing, malformed, unknown, expired and revoked keys return 401. Scope failure returns 403.

Scopes

ScopeAccess
quotes:readRequest retail quotes
shipments:readList and retrieve shipments
shipments:writeCreate and request cancellation
tracking:readShipment and account-scoped number lookup
labels:readDownload available label formats
collections:writeConfirm supported schedule
orders:readRead imported orders
webhooks:writeRegister and list subscriptions

Provisioning and revocation

The local CLI provisions a full-scope test key. An operator can issue narrower keys using SandboxStore.issueKey and revoke them using SandboxStore.revokeKey. No public key-management endpoint or live credential portal is released. The planned live control plane requires authenticated account admins, approval/audit records and independent scope checks.