generated: '2026-09-06' method: searched source: https://www.bnsf.com/ship-with-bnsf/support-services/customer-api/getting-started/ docs: - https://www.bnsf.com/ship-with-bnsf/support-services/customer-api/getting-started/ description: >- BNSF runs a named Trial environment on a separate host, reachable with the same client certificate as Production. It is a real, provider-published test surface — not a mock — and it is where BNSF tells new callers to make their first request. environments: - name: Trial host: api-trial.bnsf.com port: 6443 base_url: https://api-trial.bnsf.com:6443 default_for_new_callers: true note: >- Restricted Services are NOT available here. BNSF requires at least one unrestricted service to be working in Trial before it will move a caller to Production. - name: Production host: api.bnsf.com port: 6443 base_url: https://api.bnsf.com:6443 default_for_new_callers: false credentials: separate_test_keys: false note: >- There is no test-mode key and no key prefix scheme. The same registered client certificate authenticates against both hosts; the environment is chosen by hostname alone. That means a caller cannot tell Trial from Production by looking at its credential — only by the URL. first_request: documented_by_provider: true tool: Postman steps: - Configure a client certificate in Postman for host api-trial.bnsf.com, port 6443, supplying the CRT and KEY files in PEM format, unencrypted. A passphrase is optional. - Create a GET request to https://api-trial.bnsf.com:6443/v1/cars - Add the header Content-Type: application/json - Send. source: https://www.bnsf.com/ship-with-bnsf/support-services/customer-api/getting-started/ health_check: url: https://api-trial.bnsf.com:6443/healthcheck expected_body: OK observed_body: ok observed_status: 200 observed_on: '2026-09-06' anonymous: true note: >- The health check answered 200 anonymously on both api.bnsf.com and api-trial.bnsf.com when probed on 2026-09-06 — it is the one operation on the surface reachable without a client certificate. The provider documents the body as uppercase OK; the live body is lowercase ok. troubleshooting_published_by_provider: - Use port 6443 when connecting or downloading the certificate. - Certificates must be PEM format and unencrypted in Postman. - Run the health check and expect OK. - 'Verify the firewall path with: powershell Test-Netconnection -ComputerName "api-trial.bnsf.com" -Port 6443' test_data: fixtures: none published test_values: none published time_simulation: none published note: >- BNSF publishes no test railcars, test VINs, test waybills or seeded fixtures. A Trial caller sees the data its own certificate is entitled to — meaning a company not named on a waybill gets an empty result in Trial exactly as it would in Production. There is nothing to rehearse a write against, which is why the ingate/outgate validate operations in conventions/bnsf-conventions.yml are the only rehearsal available.