Getting started
Test vs Live
Test data and live shipping must have separate authority.
The executable quickstart uses the local fixture API. The server facade is unreleased; hosted test provider wiring and authorized billing are not installed. Domestic production booking also requires declared_value; international and imported-order booking remain disabled.
Local test mode
px_test keys address only the isolated SQLite sandbox. Quotes and tracking are synthetic. Labels are A4 PDFs marked VOID with no postage. International and multi-parcel requests exercise schemas; they do not measure carrier availability. A live-shaped key returns 503 live_not_available. The CLI refuses production and Vercel execution.
Live release
Intended host: https://api.parcelxpert.com/v1. The host is not configured by this work. Current PX quote, booking preparation, fenced purchase, label and stored tracking adapters are prepared. Distributed database authority is implemented in unapplied migrations. Billing approval, hosted test providers and staging certification remain required. A fixture must never be used as a fallback when live services fail.
Enforced sandbox limits
60 authenticated requests per key per fixed UTC minute. All authenticated attempts count, including errors and idempotency replays. A 429 response returns Retry-After and X-RateLimit-Limit, Remaining and Reset. Invalid credentials are not counted by this key limiter; a hosted service must add edge IP protections. Live limits are not yet published.