Otter Inventory Endpoints API

Endpoints to interact with product inventory.

OpenAPI Specification

otter-inventory-endpoints-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Public Account Pairing Endpoints Inventory Endpoints API
  description: "# Overview\n\nThe API endpoints are developed around [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer) principles secure via the OAuth2.0 protocol.\n\nBeyond the entry points, the API also provides a line of communication into your system via [webhooks](https://en.wikipedia.org/wiki/Webhook).\n\nFor testing purposes, we offer a staging environment. Also, more detailed information about the business rules and workflows can be found on the [**Documentation Section**](/docs/)\n\n## Versioning\nEach API is versioned individually, but we follow these rules:\n- Non breaking changes (eg: adding new fields) are added in the current version without previous communication\n- Breaking changes (fields removal, semantic changed or schema update) have the version incremented\n- Users will be notified about new versions and will be given time to migrate (the time will be set on a case by case basis)\n- Once users migrate to the new version, we will deprecate the old ones\n- Once there is a new version for an API, we won't accept new integrations targeting old versions\n\n## API General Definitions\nThe APIs use resource-oriented URLs communicating, primarily, via JSON and leveraging the HTTP headers, [response status codes](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status), and verbs.\n\nTo exemplify how the API is to be consumed, consider a fake GET resource endpoint invocation below:\n\n```\ncurl --request GET 'https://{{public-api-url}}/v1/resource/123' \\\n--header 'Authorization: Bearer 34fdabeeafds=' --header 'X-Store-Id: 321'\n```\n\n|      Header      | Description |\n| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n|`Authorization`   | Standard HTTP header is used to associate the request with the originating invoker. The content of this header is a `Bearer` token generated from you client_secret, defined in the [API Auth](#/section/Guides/API-Auth) guide.|\n|`X-Store-Id`      | The ID of the store in your system this call acts on behalf of. |\n\n_All resource endpoints expect the `Authorization` header, the remaining headers are explicitly stated in the individual endpoint documentation section._\n\nWith these headers, the system will:\n - Validate the client token, making sure the call is originating from a trusted source.\n - Validate that the Application has the permission to access the `v1/resource/{id}` resource via the Application's pre-configured scopes.\n - Translate your X-Store-Id to our internal store ID (e.g. `AAA`).\n - Validate and retrieve resource `AAA`, that is associated to your Application via store id `321`.\n\nPOST/PUT methods will look similar to the GET calls, but they'll take in a body in the HTTP request (default to the application/json content-type).\n\n```\ncurl --location --request POST 'https://{{public-api-url}}/v1/resource' \\\n--header 'Authorization: Bearer 34fdabeeafds=' --header 'X-Store-Id: 321'\n--data '{\"foo\": \"bar\"}'\n```\n\n## API Authentication/Authorization\n\n<SecurityDefinitions />\n\n## Webhook\n\nThe Public API is able to send notifications to your system via HTTP POST requests.\n\nEvery webhook is signed using HMAC-SHA256 that is present in the header `X-HMAC-SHA256`, and you can also authenticate the requests using Basic Auth, Bearer Token or HMAC-SHA1 (legacy). Please, refer to [**Webhook Authentication Guide**](/docs/guides-webhook-authentication/) for more details.\n\n_Please work with your Account Representative to setup your Application's Webhook configurations._\n\n```\nExample Base-URL = https://{{your-server-url}}/webhook\n```\n\n### Notification Schema\n\n| **Name**                | **Type** | **Description**                                                      |\n| ------------------------| ---------| -------------------------------------------------------------------- |\n| eventId                 | string   | Unique id of the event.                                              |\n| eventTime               | string   | The time the event occurred.                                         |\n| eventType               | string   | The type of event (e.g. create_order).                               |\n| metadata.storeId        | string   | Id of the store for which the event is being published.              |\n| metadata.applicationId  | string   | Id of the application for which the event is being published.        |\n| metadata.resourceId     | string   | The external identifier of the resource that this event refers to.   |\n| metadata.resourceHref   | string   | The endpoint to fetch the details of the resource.                   |\n| metadata.payload        | object   | The event object which will be detailed in each Webhook description. |\n\n### Notification Request Example\n\n```\ncurl --location --request POST 'https://{{your-server-url}}/webhook' \\\n--header 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36' \\\n--header 'Authorization: MAC <hash signature>' \\\n--header 'Content-Type: application/json' \\\n--data-raw '{\n   \"eventId\": \"123456\",\n   \"eventTime\": \"2020-10-10T20:06:02:123Z\",\n   \"eventType\": \"orders.new_order\",\n   \"metadata\": {\n      \"storeId\": \"755fd19a-7562-487a-b615-171a9f89d669\",\n      \"applicationId\": \"e22f94b3-967c-4e26-bf39-9e364066b68b\",\n      \"resourceHref\": \"https://{{public-api-url}}/v1/orders/bf9f1d81-f213-496e-a026-91b6af44996c\",\n      \"resourceId\": \"bf9f1d81-f213-496e-a026-91b6af44996c\",\n      \"payload\": {}\n   }\n}\n```\n\n### Expected Response\n\nThe partner application should return an HTTP 200 response code with an empty response body to acknowledge receipt of the webhook event.\n## Rate Limiting\nPlease, refer to [**Rate Limiting Guide**](/docs/guides-rate-limiting/) for more details.\n\n## Error codes\nThe APIs use standard HTTP status codes to indicate the success or failure of a request. Error codes are divided into two categories: 4XX codes for client-side errors and 5xx codes for server-side errors.\n### 4XX Client-Side Errors\nClient-side errors are indicated by status codes in the 4xx range. These errors are typically the result of a problem with the request made by your application.\nIf a client-side error occurs, our API will return a response that includes an appropriate error message. This message will provide information about the cause of the error. The aim of these messages is to assist you in identifying and resolving the issue.\nFor example, if you submit a request with missing or invalid parameters, you might receive a 400 Bad Request error with a message indicating which parameters were missing or incorrect.\n### 5XX Server-Side Errors\nServer-side errors are represented by status codes in the 5xx range. These errors suggest a problem with our server, not with your application's request.\nServer-side errors are typically transient, meaning they are temporary. If a server-side error occurs, we recommend that the client retries the same request with the exact same parameters.\nFor example, if you get a 500 Internal Server Error, it's possible that our server is suffering a temporary problem. In such cases, retrying the request after a short delay is often successful.\nIf you continually receive server-side errors, reach out to our support team for further assistance."
  version: v1
  license:
    name: Proprietary
  contact:
    name: Kin Lane
    email: kin@apievangelist.com
  x-generated-from: documentation
  x-source-url: https://developer-guides.tryotter.com/api-reference/
  x-last-validated: '2026-06-03'
servers:
- url: https://{public-api-url}/
  description: Otter Public API base URL. The concrete host is provisioned per integration partner/account via your Otter account representative; substitute the value provided during onboarding.
  variables:
    public-api-url:
      default: public-api-url
      description: Account-specific Public API host provided by Otter during onboarding.
tags:
- name: Inventory Endpoints
  description: Endpoints to interact with product inventory.
  x-displayName: Inventory
paths:
  /inventories/v1/summaries:
    get:
      tags:
      - Inventory Endpoints
      summary: Otter List Inventory Summaries
      operationId: listInventorySummaries
      description: '`RATE LIMIT: 32 per minute`


        List inventory summaries by the requested parameters.

        '
      parameters:
      - $ref: '#/components/parameters/inventory-summary-limit'
      - $ref: '#/components/parameters/opaquePaginationToken'
      - $ref: '#/components/parameters/storeIdHeader'
      responses:
        '200':
          description: The inventory summaries were successfully retrieved
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InventorySummariesResponse'
              examples:
                ListInventorySummaries200Example:
                  summary: Default listInventorySummaries 200 response
                  x-microcks-default: true
                  value:
                    inventorySummaries:
                    - id: ZDlhYTc1NjUtMzU3Z
                      gtin: 00049000608779
                      name: Coca-Cola Classic Coke Soft Drink 12 oz. can
                      slug: coca-cola-classic-soft-drink-12-oz-can
                      externalId: some-id-from-a-vendor-123
                      sellableQuantity: 42
                      unsellableQuantity: 42
                      inboundQuantity: 8
                    nextToken: H12MAF2fFaFFFa
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '404':
          $ref: '#/components/responses/404'
        '422':
          $ref: '#/components/responses/422'
      security:
      - OAuth2.0:
        - catalog
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /inventories/v1/shipments:
    get:
      tags:
      - Inventory Endpoints
      summary: Otter List Shipments
      operationId: listInventoryShipments
      description: '`RATE LIMIT: 8 per minute`


        List shipments by the requested parameters.

        '
      parameters:
      - $ref: '#/components/parameters/inventory-limit'
      - $ref: '#/components/parameters/opaquePaginationToken'
      - $ref: '#/components/parameters/storeIdHeader'
      responses:
        '200':
          description: The shipments were successfully retrieved
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListShipmentsResponse'
              examples:
                ListInventoryShipments200Example:
                  summary: Default listInventoryShipments 200 response
                  x-microcks-default: true
                  value:
                    shipments:
                    - id: 18695c43-c670-4c57-a714-e0d7b215db20
                      deliveryInfo: {}
                      lineItems:
                      - {}
                      stateChanges:
                      - {}
                    nextToken: H12MAF2fFaFFFa
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '404':
          $ref: '#/components/responses/404'
        '422':
          $ref: '#/components/responses/422'
      security:
      - OAuth2.0:
        - catalog
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
    post:
      tags:
      - Inventory Endpoints
      summary: Otter Create Shipment
      operationId: createShipment
      description: '`RATE LIMIT: 32 per minute`


        Create a new shipment.

        '
      parameters:
      - $ref: '#/components/parameters/storeIdHeader'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateShipmentRequest'
            examples:
              CreateShipmentRequestExample:
                summary: Default createShipment request
                x-microcks-default: true
                value:
                  deliveryInfo: {}
                  lineItems:
                  - id: 1b8aec80-21aa-43f1-b510-2199ac54156a
                    slug: pizza-pepperoni-12-inch
                    externalId: id-in-external-system
                    manifestQuantity: 5
                    receivedSellableQuantity: 5
                    receivedUnsellableQuantity: 5
        required: true
      responses:
        '200':
          description: The shipment was successfully created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateShipmentResponse'
              examples:
                CreateShipment200Example:
                  summary: Default createShipment 200 response
                  x-microcks-default: true
                  value:
                    id: 18695c43-c670-4c57-a714-e0d7b215db20
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '404':
          $ref: '#/components/responses/404'
        '422':
          $ref: '#/components/responses/422'
      security:
      - OAuth2.0:
        - catalog
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  schemas:
    CreateShipmentLineItem:
      required:
      - manifestQuantity
      type: object
      properties:
        id:
          type: string
          description: A CSS SKU UUID for the product. One of id, slug or externalId is required.
          example: 1b8aec80-21aa-43f1-b510-2199ac54156a
        slug:
          type: string
          description: A CSS SKU slug for the product. One of id, slug or externalId is required.
          example: pizza-pepperoni-12-inch
        externalId:
          type: string
          description: A SKU external ID for the product. One of id, slug or externalId is required.
          example: id-in-external-system
        manifestQuantity:
          type: integer
          description: The expected quantity of the product in the shipment.
          example: 5
        receivedSellableQuantity:
          type: integer
          description: The quantity of the product in the shipment received that was sellable.
          example: 5
        receivedUnsellableQuantity:
          type: integer
          description: The quantity of the product in the shipment received that was unsellable (damaged, expired, etc.).
          example: 5
    ShipmentStateChange:
      required:
      - timestamp
      - state
      type: object
      properties:
        state:
          $ref: '#/components/schemas/ShipmentState'
        timestamp:
          type: string
          description: ISO-8601 timestamp representing when the state change occurred.
          format: date-time
          example: '2007-12-03T10:15:30+01:00'
    InventorySummariesResponse:
      type: object
      properties:
        inventorySummaries:
          type: array
          description: A list of the inventory summaries.
          maxItems: 100
          items:
            $ref: '#/components/schemas/InventorySummary'
        nextToken:
          type: string
          description: Opaque token used to fetch the following page. If set, pass the value of nextToken to the next request. If not set, no more results are available.
          example: H12MAF2fFaFFFa
    SelfDropDeliveryInfo:
      allOf:
      - $ref: '#/components/schemas/DeliveryMetadata'
      - required:
        - delivererName
        type: object
        description: Detailed delivery information for self-delivered shipments.
        properties:
          delivererName:
            type: string
            description: The name of the deliverer.
            example: Local Delivery Service
          delivererEmailAddress:
            type: string
            description: The email address of the deliverer.
            example: foo.bar@deliver.com
        additionalProperties: true
    DeliveryMetadata:
      required:
      - deliveryWindow
      - deliveryType
      type: object
      properties:
        deliveryWindow:
          $ref: '#/components/schemas/DeliveryWindow'
          description: The delivery window for the shipment.
        deliveryType:
          type: string
          description: The type of delivery service for this shipment.
          example: string
      additionalProperties: true
    Shipment:
      required:
      - id
      - deliveryInfo
      - lineItems
      - stateChanges
      type: object
      properties:
        id:
          type: string
          description: A UUID for the shipment.
          example: 18695c43-c670-4c57-a714-e0d7b215db20
        deliveryInfo:
          $ref: '#/components/schemas/ShipmentDeliveryInfo'
        lineItems:
          type: array
          description: A list of the shipment line items.
          items:
            $ref: '#/components/schemas/ShipmentLineItem'
        stateChanges:
          type: array
          minItems: 1
          description: The state changes for the shipment. The final state change represents the current state of the shipment.
          items:
            $ref: '#/components/schemas/ShipmentStateChange'
    Gtin:
      type: string
      description: A 14 digit Global Trade Item Number (GTIN). For GTIN values that are shorter than 14 digits, value will be padded with leading zeroes.
      example: 00049000608779
    ErrorDetail:
      type: object
      properties:
        attribute:
          type: string
          description: The error attribute.
          example: Order Currency Code
        message:
          type: string
          description: The error detail description.
          example: Order Currency Code must be exactly 3 characters
      description: The error detail response object.
    ErrorMessage:
      type: object
      properties:
        message:
          type: string
          description: The error description.
          example: The request body is invalid.
        details:
          type: array
          description: The error details.
          items:
            $ref: '#/components/schemas/ErrorDetail'
      description: The error response object.
    ShipmentState:
      type: string
      description: The state of the shipment.
      enum:
      - SCHEDULED
      - ARRIVED
      - STOCKING
      - CLOSED
      - CANCELED
    ListShipmentsResponse:
      type: object
      properties:
        shipments:
          type: array
          description: A list of shipments.
          maxItems: 50
          items:
            $ref: '#/components/schemas/Shipment'
        nextToken:
          type: string
          description: Opaque token used to fetch the following page. If set, pass the value of nextToken to the next request. If not set, no more results are available.
          example: H12MAF2fFaFFFa
    ParcelCarrierDeliveryInfo:
      allOf:
      - $ref: '#/components/schemas/DeliveryMetadata'
      - required:
        - carrierName
        type: object
        description: Detailed delivery information for standard postal carriers who deliver parcel shipments.
        properties:
          carrierName:
            type: string
            description: The name of the company delivering the shipment.
            enum:
            - FED_EX
            - UPS
            - ON_TRAC
            - DHL
            - CORREOS
            - ESTAFETA
            - BR_POST
            - TNT
            - OTHER
          trackingNumber:
            type: string
            description: The tracking number for this shipment
            example: 18492b99ad000
        additionalProperties: true
    DeliveryWindow:
      required:
      - start
      - end
      type: object
      description: The delivery window in which the shipment is expected to arrive at the destination.
      properties:
        start:
          type: string
          description: ISO-8601 timestamp representing the start of the time range.
          format: date-time
          example: '2007-12-03T10:15:30+01:00'
        end:
          type: string
          description: ISO-8601 timestamp representing the end of the time range.
          format: date-time
          example: '2007-12-03T10:15:30+01:00'
    InventorySummary:
      required:
      - id
      - name
      - sellableQuantity
      type: object
      properties:
        id:
          type: string
          description: A unique identifier for the product.
          example: ZDlhYTc1NjUtMzU3Z
        gtin:
          $ref: '#/components/schemas/Gtin'
        name:
          type: string
          description: The name of the product.
          example: Coca-Cola Classic Coke Soft Drink 12 oz. can
        slug:
          type: string
          description: short, unique human-readable id for the product
          example: coca-cola-classic-soft-drink-12-oz-can
        externalId:
          type: string
          description: id of the product provided by the seller
          example: some-id-from-a-vendor-123
        sellableQuantity:
          type: integer
          description: The total quantity of the product ready to be sold. Does not include pending or in-progress shipments.
          example: 42
        unsellableQuantity:
          type: integer
          description: The total quantity of the product that is in the facility but unable to be sold. This will include inventory that is damaged, expired or otherwise unsellable.
          example: 42
        inboundQuantity:
          type: integer
          description: The total quantity of the product inbound to the facility or waiting at the facility to be processed.
          example: 8
      description: The inventory summary for a specific product.
    ShipmentDeliveryInfo:
      type: object
      description: Delivery information for a shipment.
      discriminator:
        propertyName: deliveryType
        mapping:
          selfDropDeliveryInfo: '#/components/schemas/SelfDropDeliveryInfo'
          courierServiceDeliveryInfo: '#/components/schemas/CourierServiceDeliveryInfo'
          parcelCarrierDeliveryInfo: '#/components/schemas/ParcelCarrierDeliveryInfo'
      oneOf:
      - $ref: '#/components/schemas/CourierServiceDeliveryInfo'
      - $ref: '#/components/schemas/ParcelCarrierDeliveryInfo'
      - $ref: '#/components/schemas/SelfDropDeliveryInfo'
    CourierServiceDeliveryInfo:
      allOf:
      - $ref: '#/components/schemas/DeliveryMetadata'
      - required:
        - courierName
        type: object
        description: Detailed delivery information for shipments using small point-to-point courier operations that may offer specialized services (scheduling, chill chain, etc).
        properties:
          courierName:
            type: string
            description: The name of the company delivering the shipment.
            example: Express Local Delivery Services
          trackingId:
            type: string
            description: The tracking ID for this shipment
            example: 18492b99ad000
        additionalProperties: true
    CreateShipmentRequest:
      required:
      - deliveryInfo
      - lineItems
      type: object
      properties:
        deliveryInfo:
          $ref: '#/components/schemas/ShipmentDeliveryInfo'
        lineItems:
          type: array
          description: A list of the shipment line items.
          items:
            $ref: '#/components/schemas/CreateShipmentLineItem'
    ShipmentLineItem:
      required:
      - id
      - manifestQuantity
      type: object
      properties:
        id:
          type: string
          description: A CSS SKU UUID for the product.
          example: 1b8aec80-21aa-43f1-b510-2199ac54156a
        manifestQuantity:
          type: integer
          description: The expected quantity of the product in the shipment.
          example: 5
        receivedSellableQuantity:
          type: integer
          description: The quantity of the product in the shipment received that was sellable.
          example: 5
        receivedUnsellableQuantity:
          type: integer
          description: The quantity of the product in the shipment received that was unsellable (damaged, expired, etc.).
          example: 5
    CreateShipmentResponse:
      required:
      - id
      type: object
      properties:
        id:
          type: string
          description: A unique identifier for the shipment.
          example: 18695c43-c670-4c57-a714-e0d7b215db20
      description: A response containing information about the created shipment.
    StoreId:
      type: string
      description: The unique identifier of the store in the partner application. This ID, along with the `Application ID`, will be used to match the correct store when performing operations. It cannot be longer than 255 characters and must only contain printable ASCII characters. During on-boarding, this ID will be similar to `onboarding:905bb725-b141-4a9b-832a-1f254f772c94` (where the UUID is the Internal Store ID). During off-boarding, this field will be filled with the last known Store ID, or with an empty string, in case none is found. In that case, please fall back to the provided `internalStoreId` (a.k.a. Sku-Sku ID).
      example: partner-store-unique-identifier
  parameters:
    storeIdHeader:
      name: X-Store-Id
      in: header
      required: true
      schema:
        $ref: '#/components/schemas/StoreId'
    inventory-limit:
      name: limit
      in: query
      required: false
      schema:
        type: string
        description: Max number of entities to retrieve
        example: 5
        maximum: 50
    opaquePaginationToken:
      name: token
      in: query
      required: false
      schema:
        type: string
        description: Opaque token used for paging. Query parameters must be URL encoded.
        example: CgwI09+kjQYQwOvF2AM=/(urlencoded:CgwI09%2BkjQYQwOvF2AM%3D)
    inventory-summary-limit:
      name: limit
      in: query
      required: false
      schema:
        type: string
        description: Max number of entities to retrieve
        example: 5
        maximum: 200
  responses:
    '422':
      description: The request body is not valid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorMessage'
    '400':
      description: The request is malformed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorMessage'
    '403':
      description: Authorization not valid for the requested resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorMessage'
    '404':
      description: Resource not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorMessage'
    '401':
      description: Invalid authorization.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorMessage'
  securitySchemes:
    OAuth2.0:
      type: oauth2
      description: "The **Authorization API** is based on the [OAuth2.0 protocol](https://tools.ietf.org/html/rfc6749), supporting the (Client Credentials)[https://datatracker.ietf.org/doc/html/rfc6749#section-4.4] and the (Authorization Code)[https://datatracker.ietf.org/doc/html/rfc6749#section-4.1] flows. Resources expect a valid token sent as a `Bearer` token in the HTTP `Authorization` header.\n### Scopes\nScopes must be configured by our internal team to be enabled for an app. Once the scopes are configured they can be enabled on the Application Settings Page in Developer Portal. Each endpoint requires a given scope that can be verified on each endpoint documentation. When generating an OAuth2.0 token multiple scopes can be requested.\n\n### Authorization Code Flow\nTo perform this flow, the authorization code flow must be enabled in the Application Settings Page in Developer Portal. When enabling the flow it is mandatory to provide a redirect URI pointing to your application. Once the flow is complete we will redirect the user to this URI passing the 'code' and 'state' parameters.\nThe Authorization Code flow provides a temporary code that the client application can exchange for an access token. To start the flow the application must request the user authorization. This is done by sending a request to https://{{public-api-url}}/v1/auth/oauth2/authorize.\nExample\n```\ncurl --location 'https://{{public-api-url}}/v1/auth/oauth2/authorize?client_id=[CLIENT_ID]&redirect_uri=[REDIRECT_URI]&response_type=code&scope=organization.read&state=8A9D16B4C3E25F6A'\n```\nThis call will return a 302 redirecting the user to our authorization page. If the user approves the application, we will redirect to configured URI passing the authorization code in the query parameter 'code'. The 'state' parameter is also sent to ensure the source of the data.\nWith the authorization code, the client application can generate the token.\n### Client Credentials Flow\nThe client_credentials flow does not require any steps before generating the token. Once your application is ready, and the client_id and client_secret are available, the token can be generated by following the instructions in the next section.\n\n### Generate Token\nTo generate the token, use the `Client ID` and `Client Secret` (provided during onboarding), and optionally the authorization code obtained after performing the Authorization Code flow, to the [Token Auth endpoint](#operation/requestToken) endpoint. The result of this invocation is a token that is valid for a pre-determined time or until it is manually revoked.\n\nThe access token obtained will be sent as a `Bearer` value of the `Authorization` HTTP header.\n\nClient credentials in the request-body and HTTP Basic Auth are supported.\n\n#### Request Example for client_credentials\n```\ncurl --location --request POST 'https://{{public-api-url}}/v1/auth/token' \\\n  --header 'Content-Type: application/x-www-form-urlencoded' \\\n  --data-urlencode 'scope=ping' \\\n  --data-urlencode 'grant_type=client_credentials' \\\n  --data-urlencode 'client_id=[APPLICATION_ID]' \\\n  --data-urlencode 'client_secret=[CLIENT_SECRET]'\n\n```\n#### Request Example for authorization_code\n```\ncurl --location --request POST 'https://{{public-api-url}}/v1/auth/token' \\\n  --header 'Content-Type: application/x-www-form-urlencoded' \\\n  --data-urlencode 'scope=ping' \\\n  --data-urlencode 'grant_type=authorization_code' \\\n  --data-urlencode 'client_id=[APPLICATION_ID]' \\\n  --data-urlencode 'client_secret=[CLIENT_SECRET]' \\\n  --data-urlencode 'code=[code]' \\\n  --data-urlencode 'redirect_uri=[redirect_uri]'\n\n```\n#### Response Example\n```\n{\n  \"access_token\": \"oMahtBwBbnZeh4Q66mSuLFmk2V0_CLCKVt0aYcNJlcg.yditzjwCP7yp0PgR6AzQR3wQ1rTdCjkcPeAMuyfK-NU\",\n  \"expires_in\": 2627999,\n  \"scope\": \"ping orders.create\",\n  \"token_type\": \"bearer\"\n}\n```\n\n### Token Usage\n\nThe token provided in field `access_token` is used to authenticate when consuming the API endpoints. Send the token value in the `Authorization` header of every request. The token expiration time is represented in the field `expired_in`, in seconds. Currently, all tokens are valid for 30 days and should be stored and re-used while still valid.\n\nNote that occasionally, a 401 error may be returned for a valid token due to an internal service issue. Such occurrences should be rare. To prevent exposing potential vulnerabilities to attackers, the Public API does not disclose other types of errors in the authentication flow if for any reason the token can't be validated (when it's a valid token then it's ok to return 5XX or other 4XX though - such as 403). In such scenarios, although the internal auth flow avoids retries to prevent attacks, if the token is known to be valid and not expired, a retry with a backoff interval by the client is advised. Another option is to request a new token.\n\n#### Example\n\n```\ncurl --location --request GET 'https://{{public-api-url}}/v1/ping' \\\n  --header 'Authorization: Bearer <access_token>' \

# --- truncated at 32 KB (80 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/otter/refs/heads/main/openapi/otter-inventory-endpoints-api-openapi.yml