openapi: 3.0.3 info: title: 3PL Warehouse Manager (SecureWMS) REST Authentication Orders API description: 'REST API for 3PL Warehouse Manager, the cloud warehouse management system (WMS) for third-party logistics providers, sold under Extensiv and historically known as "3PL Central". The public integration surface is the SecureWMS REST API served from https://secure-wms.com. It is used to create and retrieve orders, manage SKU items and inventory, read stock summaries and stock details, submit and track inbound receivers (Advance Ship Notices), and enumerate customers, warehouses/facilities, and locations. Authentication is OAuth 2.0 client-credentials. Base64-encode "clientId:clientSecret" and POST it as a Basic Authorization header to /AuthServer/api/Token with a JSON body of {"grant_type":"client_credentials","user_login_id":} (a user_login or user_login_id provided by the warehouse for auditing). The returned bearer access token is short-lived - typically valid 30 to 60 minutes - and should be refreshed at least every 30 minutes. All traffic must use HTTPS; plain HTTP is not supported. Collection endpoints are paged with pgnum (page number) and pgsiz (page size) query parameters and can be filtered with Resource Query Language (RQL, http://api.3plcentral.com/rels/rql) via the rql parameter and ordered with sort. Responses are HAL-style JSON where list payloads carry records under a ResourceList (or Summaries for stock summaries) property. Endpoint provenance: read (GET) endpoints for customers, items, inventory, stock details, stock summaries, facility locations, and orders are CONFIRMED against the public developer portal and the open-source singer-io tap-3plcentral extractor. Order creation, receiver (ASN) create/list/get, and the facilities and order-packages resources are documented in the 3PL Warehouse Manager developer portal; request/response shapes that are gated behind the authenticated developer portal are MODELED here honestly and marked per-operation with x-endpoint-status.' version: '1.0' contact: name: Extensiv - 3PL Warehouse Manager Developer Community url: https://developer.3plcentral.com/ license: name: Proprietary url: https://www.extensiv.com/legal servers: - url: https://secure-wms.com description: 3PL Warehouse Manager (SecureWMS) production security: - bearerAuth: [] tags: - name: Orders description: Outbound order creation and retrieval. paths: /orders: get: operationId: listOrders tags: - Orders summary: List orders description: Lists outbound orders. Paged, filterable with rql, sortable by ReadOnly.lastModifiedDate. CONFIRMED (GET /orders). x-endpoint-status: confirmed parameters: - $ref: '#/components/parameters/pgnum' - $ref: '#/components/parameters/pgsiz' - $ref: '#/components/parameters/rql' - $ref: '#/components/parameters/sort' responses: '200': description: A page of orders. content: application/json: schema: $ref: '#/components/schemas/ResourceListResponse' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createOrder tags: - Orders summary: Create an order description: Creates an outbound order (customer, ship-to, line items, shipping instructions). Creating and retrieving orders is the most common use of the API. DOCUMENTED in the developer portal (POST /orders); request body is MODELED here. x-endpoint-status: modeled requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OrderCreate' responses: '201': description: The created order. content: application/json: schema: $ref: '#/components/schemas/Order' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' /orders/{orderId}: get: operationId: getOrder tags: - Orders summary: Retrieve an order description: Retrieves a single order by id. DOCUMENTED in the developer portal; response is MODELED here. x-endpoint-status: modeled parameters: - $ref: '#/components/parameters/orderId' responses: '200': description: The order. content: application/json: schema: $ref: '#/components/schemas/Order' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: parameters: pgsiz: name: pgsiz in: query description: Page size (records per page). required: false schema: type: integer minimum: 1 default: 100 pgnum: name: pgnum in: query description: Page number (1-based). required: false schema: type: integer minimum: 1 default: 1 orderId: name: orderId in: path required: true description: The order identifier. schema: type: integer sort: name: sort in: query description: Field to sort by, e.g. ReadOnly.lastModifiedDate or receivedDate. required: false schema: type: string rql: name: rql in: query description: Resource Query Language filter, e.g. "readonly.lastModifiedDate=ge=2024-01-01". Reference http://api.3plcentral.com/rels/rql. required: false schema: type: string schemas: CustomerIdentifier: type: object properties: Id: type: integer Name: type: string FacilityIdentifier: type: object properties: Id: type: integer Name: type: string OrderCreate: type: object required: - CustomerIdentifier - OrderItems properties: CustomerIdentifier: $ref: '#/components/schemas/CustomerIdentifier' FacilityIdentifier: $ref: '#/components/schemas/FacilityIdentifier' ReferenceNum: type: string PoNum: type: string ShipTo: $ref: '#/components/schemas/Address' OrderItems: type: array items: $ref: '#/components/schemas/OrderItem' ItemIdentifier: type: object properties: Id: type: integer Sku: type: string Order: allOf: - $ref: '#/components/schemas/OrderCreate' - type: object properties: OrderId: type: integer ReadOnly: type: object additionalProperties: true ResourceListResponse: type: object description: HAL-style list payload. Records are carried under ResourceList. properties: TotalResults: type: integer ResourceList: type: array items: type: object additionalProperties: true _links: type: object additionalProperties: true OrderItem: type: object properties: ItemIdentifier: $ref: '#/components/schemas/ItemIdentifier' Qty: type: number SecondaryQty: type: number Address: type: object properties: Name: type: string Address1: type: string Address2: type: string City: type: string State: type: string Zip: type: string Country: type: string responses: Unauthorized: description: Missing, invalid, or expired access token. BadRequest: description: The request payload failed validation. NotFound: description: The requested resource was not found. securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: Short-lived access token from POST /AuthServer/api/Token. basicAuth: type: http scheme: basic description: Base64-encoded "clientId:clientSecret" used only to obtain a token.