Authentication
Shadowfax's client gateway (dale.staging.shadowfax.in / dale.shadowfax.in) supports two authentication methods: static Token Authentication and OAuth2 client-credentials. Which methods are available, how long an OAuth2 token lasts, and where credentials come from all vary by product — see the table below before you build against a specific API.
Token Authentication
Pass your API token in the Authorization header on every request:
Code
The token is static and does not expire — no exchange or refresh step is needed. For most products, generate it from the SFX 360 Partner Portal; Hyperlocal Dedicated Store is the exception — see the table below.
OAuth2 Client-Credentials
Exchange your client credentials for a short-lived Bearer token, then pass that token on every subsequent request.
Generate a Token
Code
<CLIENT_BASIC_AUTH_TOKEN> is a Base64-encoded client_id:client_secret pair. Contact your Shadowfax integration POC for your client credentials. Hyperlocal Marketplace uses a different token endpoint (POST /oauth/token/) — otherwise the flow is the same.
Response
Code
Using the Token
Code
Request a new token before expiry using the same credentials exchange — there is no refresh-token grant. Expiry varies by product, see below.
Which method should I use?
| Product | Token Auth | OAuth2 | Notes |
|---|---|---|---|
| Reverse Logistics | Supported | Supported | OAuth token expires after 1 hour |
| Forward Logistics | Supported | Supported | OAuth token expires after 1 hour |
| Exchange | Supported | Supported | OAuth token expires after 1 hour |
| Hyperlocal Marketplace | Supported | Supported | OAuth token expires after 24 hours; generated via POST /oauth/token/ |
| Hyperlocal Dedicated Store | Only method | — | Staging and production keys are shared by the Shadowfax team via email, not the Partner Portal |
| Quick Commerce | — | Only method | OAuth token expires after 1 hour |