APIs for forward delivery — moving items from warehouses and sellers to customers across India.
Use these APIs to place delivery orders, track shipments in real time, cancel orders, and update order details before dispatch.
Authentication
Shadowfax supports two authentication methods. Both work across all API endpoints.
Token Authentication — pass your API token in the header:
Code
OAuth2 Authentication — exchange client credentials for a short-lived Bearer token (valid 1 hour):
Code
Generate your credentials from the SFX 360 Partner Portal.
Order Flow
Code
See the status field on OrderDetails below for the full set of order states, or the Order Lifecycle guide for how they fit together.
Reading Responses
A 200 does not mean the order was created. Validation and business rejections on this API are returned with HTTP 200 and a message of Failure — a missing required field, an unserviceable pincode, and a replayed client_order_id all come back as 200. Branch on message, never on the status code.
message | Meaning | Where to look |
|---|---|---|
Success | Order created | data holds the order, including awb_number |
Failure | Order not created | data is absent; errors describes the problem |
errors is a plain string on this API. (Reverse Logistics differs on both counts — it returns HTTP 400 and an object keyed by field. Don't share an error handler between the two without normalising.)
Serviceability
Every leg of an order is checked independently, against a different service and a different tier — seller/warehouse pickup, customer delivery, and the return leg. A pincode serviceable for one leg is not necessarily serviceable for another. See Serviceability for which services to check and which tier to look for.
Rate Limits
API rate limits are applied per client. Contact your Shadowfax account manager to adjust limits.
E-Way Bill
E-way bill is mandatory when the product value of a single order exceeds ₹50,000.
Token <your_api_token> in the Authorization header.Bearer <access_token> in the Authorization header. Obtain a token via OAuth2 client credentials flow.