openapi: 3.0.3
info:
title: Skydropx Pro Address Templates Authentication API
description: 'The Skydropx Pro API is a REST interface for the Skydropx multi-carrier shipping and logistics platform (Mexico and Latin America). It lets you request multi-carrier rate quotations, create shipments and purchase labels, schedule carrier pickups, manage saved address templates, track parcels, and read the prepaid account credit balance. All requests are authenticated with an OAuth2 client-credentials Bearer token obtained from POST /oauth/token using your client_id and client_secret. Tokens are valid for about two hours and requests are rate limited to roughly two per second.
Grounding note: base URLs, the OAuth2 client-credentials flow, the token endpoint, the rate limit, and the resource paths below are grounded in Skydropx''s public API documentation (docs.skydropx.com and pro.skydropx.com/es-MX/api-docs). Request and response SCHEMAS are MODELED from documented fields and common shipping-API conventions and should be reconciled against the live reference before production use. A separate classic Skydropx API (https://api.skydropx.com/v1, authenticated with an `Authorization: Token token=API_KEY` header) and a Radar tracking API (https://radar-api.skydropx.com/v1) also exist and are not modeled here.'
version: '1.0'
contact:
name: Skydropx
url: https://www.skydropx.com/
servers:
- url: https://pro.skydropx.com/api/v1
description: Skydropx Pro production
- url: https://sb-pro.skydropx.com/api/v1
description: Skydropx Pro sandbox
security:
- oauth2ClientCredentials: []
tags:
- name: Authentication
description: OAuth2 client-credentials token issuance.
paths:
/oauth/token:
post:
operationId: createToken
tags:
- Authentication
summary: Issue an OAuth2 access token
description: Exchanges a client_id and client_secret for a Bearer access token using the client_credentials grant. Send as application/x-www-form-urlencoded. Tokens are valid for about two hours.
security: []
requestBody:
required: true
content:
application/x-www-form-urlencoded:
schema:
type: object
required:
- grant_type
- client_id
- client_secret
properties:
grant_type:
type: string
enum:
- client_credentials
client_id:
type: string
client_secret:
type: string
responses:
'200':
description: An access token.
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
'401':
$ref: '#/components/responses/Unauthorized'
components:
schemas:
Error:
type: object
properties:
message:
type: string
errors:
type: object
additionalProperties: true
AccessToken:
type: object
properties:
access_token:
type: string
token_type:
type: string
example: Bearer
expires_in:
type: integer
description: Token lifetime in seconds (about 7200).
created_at:
type: integer
responses:
Unauthorized:
description: Missing or invalid access token.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
securitySchemes:
oauth2ClientCredentials:
type: oauth2
description: 'OAuth2 client-credentials flow. Exchange client_id and client_secret at POST /oauth/token for a Bearer access token, sent as `Authorization: Bearer ACCESS_TOKEN`. Tokens last about two hours.'
flows:
clientCredentials:
tokenUrl: https://pro.skydropx.com/api/v1/oauth/token
scopes: {}