Sendway

Authentication

Every request carries an API key. Keys belong to your SendWay account, so parcels you book are yours and appear in your dashboard.

Getting a key

Sign in to SendWay, open Developers, and create one. Test keys are issued immediately. Live keys need your account approved — email info@shopinn.co.ke when you have tested.

The key is shown once, at creation. We store only a hash, so if you lose it you create a new one and revoke the old. Never put a live key in front-end code or a public repository — anyone holding it can book parcels you will pay for.

Sending it

bash
curl https://api.shopinn.co.ke/api/sendway/v1/towns \
  -H "Authorization: Bearer sw_live_7f3a9c21_..."

HTTP Basic also works, with the key as the username and an empty password, because that is what most PHP and WooCommerce HTTP clients reach for first.

bash
curl -u "sw_live_7f3a9c21_...:" \
  https://api.shopinn.co.ke/api/sendway/v1/towns

Test mode

A key starting sw_test_ runs everything: the same validation, the same prices, the same response shapes and the same errors. What it does not do is create anything. No parcel row, no rider dispatched, no M-Pesa prompt, no SMS to a real recipient.

Test responses carry "livemode": false. Branch on that if you show staff a warning banner — it is the honest signal that nothing will actually be collected.

Scopes

A key only does what you allow. Give a checkout page quotes:read and nothing else; keep parcels:write on your server.

ScopeLets the key
quotes:readPrice a parcel.
network:readRead towns, stations and coverage.
parcels:readList and read your parcels, and track.
parcels:writeBook and cancel parcels.
wallet:readRead your balance and COD settlements.
webhooks:manageRegister and remove webhook endpoints.

A call outside a key's scopes returns 403 insufficient_scope, naming what is missing.

When a key stops working

CodeWhat happened
missing_api_keyNo Authorization header.
malformed_api_keyNot shaped like a SendWay key — usually a truncated paste.
invalid_api_keyNo such key, or the wrong secret.
revoked_api_keyRevoked from the developers page.
expired_api_keyPast its expiry date.
client_not_activeA live key on an account not yet approved. Test keys still work.
client_suspendedAccount suspended — contact support.

Rotating a key

  1. Create the replacement.
  2. Deploy it.
  3. Confirm the new key's last used is moving on the developers page.
  4. Revoke the old one.

Revocation is immediate, so do it in that order rather than the reverse.