API Credentials
Deliverect uses OAuth 2.0 for API authentication. When a partner is registered, a client_id and client_secret are issued for use in the staging environment. These credentials are used to obtain an access_token, which must be included as a Bearer token in the Authorization header of all API requests.
Authorization: Bearer your-access-tokenToken Expiry & Caching
Access tokens expire at the time specified in expires_at. Always cache and reuse tokens until expiry. Do not request a new token for every API call.
Scopes
Scopes define the permissions associated with your access token, a complete list of available scopes below are granted according to the agree integration format
| Scope | Access |
|---|---|
genericCommerce | All endpoints within the Commerce API |
genericChannel:{channel_scope} | All endpoints within the Channel API |
genericPOS | All endpoints within the POS + Store API |
store | All endpoints within the Store API |
genericFulfillment | All endpoints within the Dispatch API |
genericKDS | All endpoints within the KDS API |
payments | All endpoints within the DPAY API |
Webhooks & HMAC Authentication
Deliverect signs all outbound webhook requests using HMAC authentication.
Refer to the HMAC Authentication Guide for implementation details:
