Authentication

Properly authenticate your requests when integrating with Ryder APIs. OAuth 2.0 with the Client Credentials grant is Ryder’s standard authentication method, while some APIs use API key authentication. This guide explains how to use each method.

Authentication Methods

  • OAuth 2.0 with Client Credentials: Ryder's standard authentication method for API integrations.

  • API Subscription Key: Used by some APIs that authenticate requests with a subscription key and do not require OAuth.

OAuth 2.0 Authentication

Ryder uses OAuth 2.0 with the Client Credentials grant as the standard authentication method for API integrations. This method is designed for server-to-server communication and allows an application to authenticate using its own credentials without requiring a user to sign in.

Client Credentials grant

To authenticate using the Client Credentials grant:

  1. Get your API Key and Client Secret from your Ryder Developer Portal application.

  2. Send a POST request to the Ryder OAuth token endpoint.

Headers

  • Content-Type: application/x-www-form-urlencoded

  • Accept: application/json

  • Authorization: Basic <Base64(api_key:client_secret)>

  • Ocp-Apim-Subscription-Key: <api_key>

Body parameters

  • grant_type: client_credentials

  • scope: APIM

Example request

POST /identityservices/oauth2/default/v1/token HTTP/1.1
Host: api.ryder.com
Content-Type: application/x-www-form-urlencoded
Accept: application/json
Authorization: Basic <Base64(api_key:client_secret)>
Ocp-Apim-Subscription-Key: <api_key>

grant_type=client_credentials&scope=APIM

If the request is successful, the response will include an access token that can be used to authenticate subsequent API requests.

Example response

{
"token_type": "Bearer",
"expires_in": 3600,
"access_token": "<access_token>",
"scope": "APIM"
}

The expires_in value is expressed in seconds. In this example, the access token is valid for 3600 seconds, or 1 hour.

Include the access token in the Authorization header using the Bearer scheme, along with your API Key in the Ocp-Apim-Subscription-Key header.

Example API request

GET /api/protected/endpoint HTTP/1.1
Host: api.ryder.com
Authorization: Bearer <access_token>
Ocp-Apim-Subscription-Key: <api_key>

API Subscription Key

Some Ryder APIs authenticate requests using an API Key without requiring OAuth 2.0.

To access these APIs, include your API Key in the Ocp-Apim-Subscription-Key request header.

GET /api/protected/endpoint HTTP/1.1
Host: api.ryder.com
Ocp-Apim-Subscription-Key: <api_key>

The authentication requirements for each API are identified in its API documentation.