# Carrier Global > Carrier Global Corporation builds HVAC, refrigeration, fire, security and building > automation systems. Of its digital products, exactly one publishes machine-readable > API contracts today: LYNX Fleet, the telematics platform for transport refrigeration > units (TRUs) and shipping containers. Three OpenAPI 3.0.0 documents cover 16 > operations across truck/trailer telematics, two-way refrigeration control and > container telemetry. i-Vu, Carrier Comfort Network, Abound and Carrier SmartHome > publish no contract. Generated by the API Evangelist enrichment pipeline on 2026-09-05 from Carrier's own published material. Carrier does not publish an llms.txt of its own — probed 2026-08-17 and again 2026-09-05, and every candidate path on every Carrier host returns a single-page-app or CMS shell rather than a text document (see llms/carrier-global-llms-probe.yml and well-known/carrier-global-well-known.yml). ## How to reach the contracts The Lynx Dev Portal is a JavaScript single-page app: /openapi.json, /swagger.json, /openapi.yaml and every other conventional path return the same 604-byte HTML shell with HTTP 200. The specs are real but are served by the portal's GraphQL backend. - Public GraphQL endpoint (anonymous, no key): https://api.portal.fleet.lynx.carrier.io/public/graphql - Product catalogue: POST `query { getDefaultProducts }` - One contract: POST `query ($productId: String!) { getPublicApiSpecYml(productId: $productId) { yamlContent } }` - Contract + integration guide: POST `query ($productId: String!) { getPublicProductInfo(productId: $productId) { apiSpec guide } }` - Introspection is disabled on that endpoint; `{__typename}` answers 200, `{__schema{...}}` answers 400. ## APIs - [Lynx Fleet API](https://api.fleet.lynx.carrier.io): 10 operations. Assets, asset snapshots, asset history, multi-asset history, batteries, battery history, alarm-code dictionary, and two ingestion endpoints (SCB, Orbcomm). Product id 394a2e2a-3258-4bba-a77b-d0082658871e. - [Lynx 2-way Command API](https://api.fleet.lynx.carrier.io/2waycmd): 3 operations. List available commands for an asset, send a command, check command status. Product id fe08addc-2c95-4a51-91a3-9669189f441f. - [Lynx Container API](https://api.fleet.lynx.carrier.io/coa): 3 operations. Unified Model, latest source data, container asset history. Product id c090377c-06e6-4ca0-b70a-7d5fe0bd37b3. ## Authentication - Single scheme across all three contracts: an API key in the `x-lynx-api-key` request header, applied globally. No OAuth, no scopes. - Keys come from the Lynx Fleet portal (account menu → External API Key), or from Lynx API Support. The key is tenant-scoped and entitlement-scoped: Carrier configures which tenants, assets and data types it can read before any call returns data. - HTTPS only, TLS 1.2 minimum, server certificate validation required. Plain HTTP fails. - The Lynx portal's human sign-in is separate: OIDC through Carrier's own Okta tenant, issuer https://carrier.okta.com/oauth2/ausezsnschc0QFWkt4x7. That is not API auth. ## Conventions - Pagination is cursor-based: `limit` (1–250, default 100) and `nextToken` (≤2048 chars). Lists come back newest-first. - Assets can be named four interchangeable ways: assetIds, assetNames, truSerialNumbers, licensePlateNumbers. Supply none and you get everything the key is entitled to. - Versioning is a `/v1` path prefix. A breaking change produces a new version; adding resources, optional parameters or response properties is not breaking. Consumers are required to ignore unknown fields and tolerate missing ones. - Errors are a bare `{"message": "..."}` object as application/json — not RFC 9457, and with no machine-readable error code. Statuses: 400, 401, 403, 429, 500, all declared on all 16 operations. - Rate limit: 500,000 calls per month per key. 429 on exhaustion. No X-RateLimit-*, no RateLimit-*, no Retry-After — the number is in the docs, not on the wire. - Cadence: 30-minute query windows for history and snapshots; anything more frequent should use the Push API. Re-sync the asset list weekly. ## What is missing (measured, not assumed) - No idempotency key anywhere, including on the command endpoint that actuates physical refrigeration equipment. - No reversal, cancel or undo operation, and no stated reversal window. - No dry-run mode and no published sandbox, test key, test host or fixture data. - No SDK or client library in any language, on any registry. - No CLI, no status page, no changelog, no deprecation policy, no security.txt, no agent card, and no MCP server. - Webhooks ("Push API") are documented as existing but have no event catalog, no payload schema, no subscription endpoint and no delivery/retry semantics. ## Repository artifacts - openapi/ — the three contracts, verbatim - graphql/ — the public portal GraphQL surface and what was verified on it - authentication/, conventions/, errors/, lifecycle/, rate-limits/ — runtime semantics - data-model/ — the entity graph derived from the contracts - asyncapi/ — the documented Push API webhook surface and its gaps - sandbox/ — the interactive Dev Portal console; no test environment is published - conformance/ — standards asserted, and the domain standards deliberately not asserted - security/ — domain security probes and the Carrier PSIRT disclosure program - mcp/ — a candidate tool list (no server exists) and the REST/GraphQL crosswalk - skills/ — packaged agent skills grounded in real operationIds - well-known/ — the full probe record across nine hosts ## Human entry points - Dev Portal: https://doc-api.fleet.lynx.carrier.io/ - API documentation: https://doc-api.fleet.lynx.carrier.io/api-documentation - Azure APIM developer portal (subscribers): https://api.tta.lynxfleet.carrier.com/ - Lynx Fleet application: https://fleet.lynx.carrier.io - Lynx terms of use: https://www.carrier.com/lynx/terms-of-use - Product security / PSIRT: https://www.carrier.com/us/en/product-security.html - Report a vulnerability: https://www.carrier.com/us/en/product-security/report-an-issue.html - Company: https://www.corporate.carrier.com ## Access Developer portal access requires being a current Lynx Fleet subscriber. The contracts and the integration guide themselves are readable anonymously through the portal's public GraphQL backend; calling the APIs is not.