openapi: 3.0.3 info: title: Skydropx Pro Address Templates Authentication API description: 'The Skydropx Pro API is a REST interface for the Skydropx multi-carrier shipping and logistics platform (Mexico and Latin America). It lets you request multi-carrier rate quotations, create shipments and purchase labels, schedule carrier pickups, manage saved address templates, track parcels, and read the prepaid account credit balance. All requests are authenticated with an OAuth2 client-credentials Bearer token obtained from POST /oauth/token using your client_id and client_secret. Tokens are valid for about two hours and requests are rate limited to roughly two per second. Grounding note: base URLs, the OAuth2 client-credentials flow, the token endpoint, the rate limit, and the resource paths below are grounded in Skydropx''s public API documentation (docs.skydropx.com and pro.skydropx.com/es-MX/api-docs). Request and response SCHEMAS are MODELED from documented fields and common shipping-API conventions and should be reconciled against the live reference before production use. A separate classic Skydropx API (https://api.skydropx.com/v1, authenticated with an `Authorization: Token token=API_KEY` header) and a Radar tracking API (https://radar-api.skydropx.com/v1) also exist and are not modeled here.' version: '1.0' contact: name: Skydropx url: https://www.skydropx.com/ servers: - url: https://pro.skydropx.com/api/v1 description: Skydropx Pro production - url: https://sb-pro.skydropx.com/api/v1 description: Skydropx Pro sandbox security: - oauth2ClientCredentials: [] tags: - name: Authentication description: OAuth2 client-credentials token issuance. paths: /oauth/token: post: operationId: createToken tags: - Authentication summary: Issue an OAuth2 access token description: Exchanges a client_id and client_secret for a Bearer access token using the client_credentials grant. Send as application/x-www-form-urlencoded. Tokens are valid for about two hours. security: [] requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object required: - grant_type - client_id - client_secret properties: grant_type: type: string enum: - client_credentials client_id: type: string client_secret: type: string responses: '200': description: An access token. content: application/json: schema: $ref: '#/components/schemas/AccessToken' '401': $ref: '#/components/responses/Unauthorized' components: schemas: Error: type: object properties: message: type: string errors: type: object additionalProperties: true AccessToken: type: object properties: access_token: type: string token_type: type: string example: Bearer expires_in: type: integer description: Token lifetime in seconds (about 7200). created_at: type: integer responses: Unauthorized: description: Missing or invalid access token. content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: oauth2ClientCredentials: type: oauth2 description: 'OAuth2 client-credentials flow. Exchange client_id and client_secret at POST /oauth/token for a Bearer access token, sent as `Authorization: Bearer ACCESS_TOKEN`. Tokens last about two hours.' flows: clientCredentials: tokenUrl: https://pro.skydropx.com/api/v1/oauth/token scopes: {}