Authentication
OAuth 2.0 client credentials, machine to machine. Tokens are short-lived JWTs scoped to your organization and roles; send Authorization: Bearer <token> on every request and mint fresh tokens rather than caching near expiry.
| Scope | Grants |
|---|---|
catalog:read | Browse catalogs, avails, and rates within your agreements |
catalog:write | Sellers: publish packages, rates, avails |
orders:write | Create, confirm, respond, cancel |
orders:approve | Sellers: decide orders at the review gate |
webhooks:manage | Register and allowlist notify endpoints |
settlement:read | Invoices and make-good ledger on cleared trades |
Webhooks the platform sends you carry an HMAC signature in X-Signature computed over the timestamp and body; verify it with your signing key before trusting any event, and reject stale timestamps. Tokens are validated for audience: a token minted for another service will be rejected here.