Parselv1.0.0

Authentication

Learn how to authenticate with the Parsel API using Bearer tokens.

Bearer Authentication

All requests to the Parsel API must include an authorization token in the HTTP headers. This token verifies your identity and determines your access permissions.

Header Format

Include your API key in the Authorization header using the Bearer scheme:

Authorization: Bearer <your_token>

cURL example

curl https://api.parsel.app/billing/invoices \
  -H "Authorization: Bearer <your_token>"

A missing or invalid token returns 401 Unauthorized.

Obtaining an API Key

During developer preview, API keys are provisioned manually by the Parsel team.

To obtain your API key:

  1. Create an account on the Parsel platform
  2. Contact our engineering team at engineering@getparsel.com
  3. Once approved, our team will share your API key with you

Scopes

Every API token carries a set of scopes, and every endpoint requires one. A request whose token lacks the scope an endpoint needs gets a 403 Forbidden with a required_scope field naming what's missing — see Errors.

Scopes come in READ_*/WRITE_* pairs per resource area, except Billing and Rate shopping profiles, which are read-only in the public API today and so have no WRITE_* counterpart:

ScopeGrants
READ_SHIPMENTSList/get shipments and shipping labels, tracking.
WRITE_SHIPMENTSCreate/cancel shipments, buy rates, verify addresses.
READ_BILLINGList/get invoices and line items.
READ_RATE_SHOPPING_PROFILESList/get rate shopping profiles.
READ_WEBHOOKSList/get webhook subscriptions and their events.
WRITE_WEBHOOKSCreate/update webhook subscriptions.

Endpoint reference

MethodEndpointRequired scope
GET/shipmentsREAD_SHIPMENTS
POST/shipmentsWRITE_SHIPMENTS
GET/shipments/{id}READ_SHIPMENTS
PUT/shipments/{shipment_id}/cancelWRITE_SHIPMENTS
POST/shipments/{shipment_id}/rates/{shipping_rate_id}WRITE_SHIPMENTS
POST/addresses/verifyWRITE_SHIPMENTS
GET/shipping_labelsREAD_SHIPMENTS
GET/shipping_labels/{id}READ_SHIPMENTS
GET/shipping_labels/{shipping_label_id}/trackREAD_SHIPMENTS
GET/track/{tracking_code}READ_SHIPMENTS
POST/track/bulkREAD_SHIPMENTS
GET/billing/invoicesREAD_BILLING
GET/billing/invoices/{id}READ_BILLING
GET/billing/invoices/{id}/line_itemsREAD_BILLING
GET/rate_shopping_profilesREAD_RATE_SHOPPING_PROFILES
GET/rate_shopping_profiles/{profile_key}READ_RATE_SHOPPING_PROFILES
GET/webhooksREAD_WEBHOOKS
POST/webhooksWRITE_WEBHOOKS
GET/webhooks/{id}READ_WEBHOOKS
PUT/webhooks/{id}WRITE_WEBHOOKS
PATCH/webhooks/{id}WRITE_WEBHOOKS
GET/webhooks/{id}/eventsREAD_WEBHOOKS

Tokens can carry more than one scope. Contact engineering@getparsel.com if your token needs a scope it doesn't have.

Security Best Practices

  • Never share your API keys or embed them directly in client-side code
  • Store API keys in environment variables or a secure key management system
  • Use different API keys for development and production environments

On this page