# DoorDash > DoorDash is an on-demand local commerce platform. Its developer program exposes the Dasher > logistics network and the DoorDash marketplace through thirteen publicly documented REST APIs: > Drive and Drive (classic) for on-demand delivery, Parcel for shipped goods, Marketplace and > Marketplace (legacy) for merchant order flow, Item Management for catalog and inventory, > Storefront for white-label ordering, Reporting for financial and operational data exchange, Ads > for advertising, plus Refunds, Redelivery, Dasher Feedback and Checkout. All of them authenticate > with a self-signed HS256 JSON Web Token presented as a bearer token. Generated by API Evangelist on 2026-09-17 from DoorDash's own published OpenAPI documents and developer documentation. DoorDash does not publish an llms.txt of its own (https://developer.doordash.com/llms.txt returned 404 on 2026-09-17). This file is an independent third-party index, not a DoorDash artifact. ## What an agent needs to know first - Base host: `https://openapi.doordash.com` (Marketplace legacy: `https://pointofsale.doordash.com`). - Auth: sign your own JWT. HS256, header `{"alg":"HS256","typ":"JWT","dd-ver":"DD-JWT-V1"}`, claims `aud=doordash`, `iss=`, `kid=`, `iat`, `exp` at most 1800s past `iat`. Sign with the base64-decoded signing secret. Send as `Authorization: Bearer `. - No OAuth, no OpenID Connect, no scopes, no token endpoint. - Sandbox and production share the same base URL and are separated by which access key you sign with. Sandbox is self-serve; Drive production access is restricted and Marketplace APIs are not generally available. - Rate limit: approximately 300 requests per 60 seconds per access key. No rate-limit response headers are returned — count your own calls. 429 on exhaustion. - Errors: `{"code": "...", "message": "...", "field_errors": [{"field":"...","error":"..."}]}`. Branch on `code`; `message` is debug-only. Not RFC 9457. - Idempotency: `external_delivery_id` is the replay key on delivery creation only. No Idempotency-Key header exists, and no other write on the platform has replay protection. - Reversibility: a delivery can be cancelled only before a Dasher is assigned; afterwards DoorDash creates a return delivery billed at 60% of the original fee. Catalog, menu, inventory and promotion writes have no undo. - No pagination is documented on any collection endpoint. - No request-id or trace header. Correlate on your own external identifiers. ## Documentation - [Developer portal](https://developer.doordash.com/portal) - [Documentation home](https://developer.doordash.com/en-US/) - [Get started with Drive](https://developer.doordash.com/en-US/docs/drive/tutorials/get_started/) - [JWT format reference](https://developer.doordash.com/en-US/docs/drive/reference/JWTs) - [Error codes and reasons](https://developer.doordash.com/en-US/docs/drive/reference/errors) - [Retry strategy](https://developer.doordash.com/en-US/docs/drive/reference/retry_pattern) - [Delivery statuses](https://developer.doordash.com/en-US/docs/drive/reference/delivery_statuses) - [Webhooks how-to](https://developer.doordash.com/en-US/docs/drive/how_to/webhooks) - [Delivery simulator](https://developer.doordash.com/en-US/docs/drive/how_to/use_delivery_simulator) - [Pricing and payment](https://developer.doordash.com/en-US/docs/drive/overview/pricing_payment) - [FAQs](https://developer.doordash.com/en-US/docs/drive/overview/faqs) - [Status page](https://www.doordashstatus.com) ## API reference (each page is rendered from a first-party OpenAPI) - [Drive API 2.1.59](https://developer.doordash.com/en-US/api/drive) — quotes, deliveries, serviceability, address autocomplete, substitution recommendations, businesses and stores. - [Drive (classic) API 0.4.8](https://developer.doordash.com/en-US/api/drive_classic) - [Parcel API 0.3.6](https://developer.doordash.com/en-US/api/drive_v2_parcel) - [Drive Refunds API 0.0.3](https://developer.doordash.com/en-US/api/drive_refunds) - [Drive Redelivery API 0.0.1](https://developer.doordash.com/en-US/api/drive_redelivery) - [Drive Dasher Feedback API 0.0.1](https://developer.doordash.com/en-US/api/drive_dasher_feedback) - [Marketplace API 1.0.0](https://developer.doordash.com/en-US/api/marketplace) — orders, menus, store and item status. - [Marketplace (legacy) API](https://developer.doordash.com/en-US/api/marketplace_legacy) - [Item Management API 2.0](https://developer.doordash.com/en-US/api/marketplace_v2) — items, store inventory, promotions, in-store checkout transactions, merchant onboarding. - [Reporting APIs 1.0.0](https://developer.doordash.com/en-US/api/reporting) - [Storefront V1 API](https://developer.doordash.com/en-US/api/storefront) - [Ads API](https://developer.doordash.com/en-US/api/ads) - [Checkout API Interface 0.1.6](https://developer.doordash.com/en-US/api/external_checkout) ## Machine-readable contracts DoorDash serves each OpenAPI document as plain YAML at `https://developer.doordash.com/redocusaurus/plugin-redoc-.yaml` (indices 0-27). Nothing on the site links to these files; the index-to-product mapping is recorded in `openapi/_original/doordash-openapi-sources.yml` in this profile. ## Release notes - [Reporting](https://developer.doordash.com/en-US/docs/reporting/overview/release_notes) — last updated 2026-05-21 - [Marketplace](https://developer.doordash.com/en-US/docs/marketplace/overview/release_notes) — last updated 2024-02-22 - [Drive](https://developer.doordash.com/en-US/docs/drive/overview/release_notes) — last updated 2023-01-12 - [Drive (classic)](https://developer.doordash.com/en-US/docs/drive_classic/overview/release_notes) — last updated 2022-02-28 ## SDKs - [@doordash/sdk](https://www.npmjs.com/package/@doordash/sdk) — Node.js, Drive delivery requests only. Latest 0.6.13, published 2024-10-07. - [oapi-codegen-dd](https://github.com/doordash-oss/oapi-codegen-dd) — DoorDash's Go code generator, not a client SDK. Latest v1.16.3, 2024-06-04. No first-party Python, Ruby, PHP, Java or .NET SDK exists. ## Not available - No Model Context Protocol server. Every DoorDash MCP server on the registries is third-party. - No A2A agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json` on any host. - No `/.well-known/security.txt`, `/.well-known/api-catalog`, OAuth or OpenID metadata anywhere. - No AsyncAPI document for the webhook surface. - No public GraphQL API. (DoorDash's consumer app uses an internal GraphQL surface that is not documented, not supported, and not part of the developer program.) - No deprecation or sunset policy, and no Sunset/Deprecation response headers. - No published uptime SLA. ## Security - [Bug bounty program](https://hackerone.com/doordash) — public, on HackerOne. - [Trust center](https://trust.doordash.com/) — SOC 2 and PCI DSS (last read 2026-07-11; the page is behind a Cloudflare bot interstitial to anonymous clients).