Authentication
Sign in with your credentials and send the access token on each request.
You sign in with the username and password your account manager gives you. In return you get an access token, which you send as a bearer token on every other request.
Sign in
POST/api/{version}/Authenticate/ClientLoginView Client login in the reference
Send your credentials as JSON:
{
"username": "testusername",
"password": "******"
}
A successful sign-in returns the token, with pnErrorHandle.isSuccess set to true:
{
"accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6I…",
"pnErrorHandle": {
"isSuccess": true,
"errorMessage": ""
}
}
Use the token
The token is valid for 4 hours. Send it in the Authorization header:
Authorization: Bearer <access-token>
When it expires, requests return 401 Unauthorized. Sign in again to get a new token.
When sign-in fails
| Status | Meaning |
|---|---|
401 Unauthorized | The username or password is wrong. |
403 Forbidden | The account is deactivated. |
423 Locked | The account is locked out. |
Each failure keeps the pnErrorHandle shape, so you can read the reason from pnErrorHandle.errorMessage.
Tracking uses different headers
Get tracking log doesn't take a bearer token. Send these two headers instead, on every call:
| Header | Value |
|---|---|
client-id | Identifies the account whose shipments you can look up. |
client-secret | Your tracking API key. |
Because it doesn't need a token, you can call it from a customer-facing tracking page.