Authentication
Every request carries an API key. Keys belong to your SendWay account, so parcels you book are yours and appear in your dashboard.
Getting a key
Sign in to SendWay, open Developers, and create one. Test keys are issued immediately. Live keys need your account approved — email info@shopinn.co.ke when you have tested.
Sending it
curl https://api.shopinn.co.ke/api/sendway/v1/towns \
-H "Authorization: Bearer sw_live_7f3a9c21_..."HTTP Basic also works, with the key as the username and an empty password, because that is what most PHP and WooCommerce HTTP clients reach for first.
curl -u "sw_live_7f3a9c21_...:" \
https://api.shopinn.co.ke/api/sendway/v1/townsTest mode
A key starting sw_test_ runs everything: the same validation, the same prices, the same response shapes and the same errors. What it does not do is create anything. No parcel row, no rider dispatched, no M-Pesa prompt, no SMS to a real recipient.
Test responses carry "livemode": false. Branch on that if you show staff a warning banner — it is the honest signal that nothing will actually be collected.
Scopes
A key only does what you allow. Give a checkout page quotes:read and nothing else; keep parcels:write on your server.
| Scope | Lets the key |
|---|---|
quotes:read | Price a parcel. |
network:read | Read towns, stations and coverage. |
parcels:read | List and read your parcels, and track. |
parcels:write | Book and cancel parcels. |
wallet:read | Read your balance and COD settlements. |
webhooks:manage | Register and remove webhook endpoints. |
A call outside a key's scopes returns 403 insufficient_scope, naming what is missing.
When a key stops working
| Code | What happened |
|---|---|
missing_api_key | No Authorization header. |
malformed_api_key | Not shaped like a SendWay key — usually a truncated paste. |
invalid_api_key | No such key, or the wrong secret. |
revoked_api_key | Revoked from the developers page. |
expired_api_key | Past its expiry date. |
client_not_active | A live key on an account not yet approved. Test keys still work. |
client_suspended | Account suspended — contact support. |
Rotating a key
- Create the replacement.
- Deploy it.
- Confirm the new key's last used is moving on the developers page.
- Revoke the old one.
Revocation is immediate, so do it in that order rather than the reverse.
