PostEx · Authentication Profile

Postex Authentication

Authentication

PostEx's merchant Order Integration API authenticates every request with a merchant API token issued from the PostEx merchant dashboard, supplied in the `token` request header. No OAuth or OpenID Connect surface was found.

PostEx secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

CompanyLogisticsCouriersShippingE-CommerceFulfillmentCash on DeliveryPaymentsFintechPakistan
Methods: apiKey Schemes: 1 OAuth flows: API key in: header

Security Schemes

merchantToken apiKey
· in: header ()

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: >-
  Live probe of https://api.postex.pk merchant Order Integration API. Every
  endpoint returns HTTP 400 "Missing request header 'token'" when called
  without credentials, confirming an apiKey-in-header auth model. The CORS
  Access-Control-Allow-Headers on the host also advertise: X-Api-Key,
  authorization, skip, token, X-Device-Id, X-LANG.
description: >-
  PostEx's merchant Order Integration API authenticates every request with a
  merchant API token issued from the PostEx merchant dashboard, supplied in the
  `token` request header. No OAuth or OpenID Connect surface was found.
summary:
  types:
    - apiKey
  api_key_in:
    - header
  oauth2_flows: []
schemes:
  - name: merchantToken
    type: apiKey
    in: header
    parameter_name: token
    description: >-
      Merchant API token issued from the PostEx merchant dashboard, sent in the
      `token` request header on every Order Integration API call.
    sources:
      - openapi/postex-order-openapi.yml
notes: >-
  The host's CORS policy additionally allows the headers X-Api-Key,
  authorization, and skip, but only the `token` header is required and enforced
  by the Order Integration API endpoints probed.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/postex-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.