# Passport (Passport Global, Inc.) > Cross-border ecommerce logistics and compliance platform, founded 2017. Passport ships direct-to-consumer > brands' orders internationally to 190+ markets and handles the customs, duty, tax, and trade-compliance layer > around those shipments. Its public REST API — the Passport Global API, v3.15 — covers landed-cost rating, > label purchase and voiding, order submission, cart-level duty/tax quoting, currency-converted product pricing, > and a standalone tax-and-duty calculator. ## Key facts - Company: Passport Global, Inc. — https://passportglobal.com/ - Founded: 2017. 200+ employees, operations across 20 countries, ships to 190+ markets. - Product lines: Passport Shipping (cross-border parcel), Passport Global (cross-border management, in-country enablement, marketplace management), Compliance Services, Seller/Merchant of Record, Duty Drawback, Returns. - API base URL (production): https://api.passportshipping.com/v3 - API base URL (testing): https://api-stg.passportshipping.com/v3 - Authentication: API key in the `X-Access-Token` request header, issued by the Passport onboarding team. There is no self-service signup, no OAuth, and no scope model. - Spec: OpenAPI 3.0.1, version 3.15 — https://docs.passportglobal.com/passport_public_api_v3_15.yml ## Documentation - API reference (Redoc): https://docs.passportglobal.com/ - OpenAPI 3.15 (latest): https://docs.passportglobal.com/passport_public_api_v3_15.yml - OpenAPI 3.14: https://docs.passportglobal.com/passport_public_api_v3_14.yml - OpenAPI 3.13: https://docs.passportglobal.com/passport_public_api_v3_13.yml - Technology / platform overview: https://passportglobal.com/technology/ - Product updates: https://passportglobal.com/product-release/ - Status: https://status.passportglobal.com/ - Service alerts: https://passportglobal.com/service-alerts/ - Security measures: https://passportglobal.com/security-measures/ - GDPR: https://passportglobal.com/gdpr/ - Privacy policy: https://passportglobal.com/privacy-policy/ - Terms of use: https://passportglobal.com/terms-of-use/ - Contact sales (the only route to an API key): https://passportglobal.com/contact-sales/ ## Operations (Passport Global API v3.15) - POST /rate — Request a shipping rate including landed cost (rate, duty, tax, insurance, serviceName). - POST /ship — Purchase a shipping label. Returns tracking code, label image URL, tracking URL. - POST /void/{code} — Void an existing label by tracking code. - POST /order — Submit order information (totals, items with HS codes, address, chosen shipping). - PUT /order?orderNames=... — Update a submitted order. Orders older than one year are rejected (403). - GET /order?orderNames=... — Retrieve orders by name. - DELETE /order?orderNames=... — Delete orders by name. - POST /cart — Rate a whole cart; returns service options with rate, tax, duty, insurance, total, EDD, and a duty/tax breakdown, plus a request_id. - POST /product-price — Convert product values into a presentment currency (rate, fee, formatted values). - POST /tax-and-duty — Calculate duty and tax for items given a shipping rate and origin/destination. - GET /ping — Health check. Authenticated: an unauthenticated call returns 401. ## Working with this API - Every request is HTTPS + JSON with the `X-Access-Token` header. A missing or wrong key returns 401 with `{"message": "Unable to access the requested resource, authorization failed.", "details": "missing/incorrect authorization data"}`. - All items in one request must share a single ISO 4217 currency; mixed currencies return 400 MixedCurrency. - Money values are bounded 0.01–99999999.99. `order_name` is <= 100 characters. - The normal flow is: POST /rate (or POST /cart) to price the shipment, choose a `serviceName`, then POST /ship with that `service_name` to buy the label, and POST /order to register the commercial order. - 422 responses carry field-level validation errors under `details.body` and `details.items`. - 500 responses embed a `RequestId` inside the message string — capture it and give it to Passport support. ## What Passport does NOT publish (verified 2026-08-04) - No idempotency mechanism — POST /ship, the label-purchasing operation, is not replay-safe. Do not blind-retry it; recover with POST /void/{code}. - No rate limits, quotas, or 429 semantics anywhere in the spec or docs. - No pagination on GET /order and no list-all operation. - No webhooks, events, or AsyncAPI. Shipment updates reach integrators via the branded tracking page, the Passport Portal, or third-party aggregators (EasyPost, AfterShip, ShipEngine, TrackingMore). - No first-party SDKs, CLI, or Postman collection on any public registry. - No MCP server, no agent card, no /.well-known documents of any kind, and no security.txt. - No dated changelog and no deprecation or sunset policy. - No SOC 2, ISO 27001, or PCI attestation, and no trust center.