Setting up your environment

Authentication

Authentication data must be provided for every call. It is expected as an HTTP authentication (HTTP basic protocol). The user and client login data is transmitted in the format:

USER@CLIENT:PASSWORT

❗️

You cannot use regular Carrier Connect users for API requests! Instead you will need a special API user to transmit API requests, which usually starts with WSM.

The login data must be base 64–encoded. The password is written out, so this is why we require using HTTPS encryption and the data cannot be intercepted by unauthorized parties.

Example:

The string "API_TEST@APITEST:API_TEST2024", when encoded in base 64, yields "QVBJX1RFU1RAQVBJVEVTVDpBUElfVEVTVDIwMjQ=".

The following line would therefore be added to the HTTP header:

Authorization: Basic QVBJX1RFU1RAQVBJVEVTVDpBUElfVEVTVDIwMjQ=
❗️

Copy the trailing "=" as well

It is part of the base 64 padding. Some servers reject an unpadded value.

Always send Accept: application/json as well, so that error responses come back as JSON rather than as an HTML error page.

Firewall: IP subnetworks of the AEB data centers

Carrier Connect is reached over HTTPS on port 443 only. If your firewall or proxy restricts outbound traffic, allow AEB's inbound web subnetworks:

194.15.60.0/25
194.15.61.0/25
194.15.62.0/25
193.98.221.0/25
194.175.186.0/24

Allow all five, not the single IP address of the host you happen to call. AEB moves services between data centers, and a rule pinned to one address stops working on failover.

💡

The API is only available via Secure Socket Layer (SSL).

Port 443. There is no plain-HTTP endpoint.

Two cases need more than the rows above, and both are covered by Public IP subnetworks of the AEB data centers — the maintained source, which wins over this page:

  • SFTP (TCP 22), if you exchange EDI files with AEB — its own set of subnetworks.
  • AEB's outbound source IPs, if your own firewall filters traffic coming from AEB.

Systems

Every URL in this guide contains an {installation} placeholder. Replace it with the system you connect to:

{installation}Description
demo1caiDemo system — shared, used for connectivity tests and the test credentials below
test2caiTest environment
prod1caiProductive environment
prod2caiProductive environment (First Customer)

Endpoints

All Carrier Connect operations are POST calls under one base URL:

https://rz3.aeb.de/{installation}/rest/DLCarrierBFBean/{operation}

For example: https://rz3.aeb.de/demo1cai/rest/DLCarrierBFBean/createShipment.

The complete list of operations, with every field, is under API Reference:


Documentation

REST (OpenApi)

https://rz3.aeb.de/{installation}/rest/openapi.json

This is the authoritative machine-readable contract for every field. The file covers the whole installation — Carrier Connect operations are the ones tagged Shipping, under DLCarrierBFBean.

SOAP

Carrier Connect is also available over SOAP. Use REST for new integrations; SOAP is there for existing ones.

https://rz3.aeb.de/{installation}/servlet/bf/DLCarrierBF?WSDL
https://rz3.aeb.de/{installation}/servlet/bf/doc/DLCarrierBF/de/aeb/xnsg/dl/bf/IDLCarrierBF.html

Optional: token authentication

Instead of sending Basic credentials on every call, you can exchange them once for a token:

curl -u 'USER@CLIENT:PASSWORD' \
  -H 'Accept: text/plain' \
  'https://rz3.aeb.de/{installation}/rest/logon/authToken'

Send the returned token as Authorization: Bearer <token> on subsequent calls.

❗️

This one call needs "Accept: text/plain"

/logon/authToken returns the token as plain text. With Accept: application/json it answers 406 Not Acceptable.

POST /logon/user (body: userName, password, clientName, optional localeName) is the alternative, and additionally returns the roles granted to the user.

📘

"X-XNSG_WEB_TOKEN" is not an API integration path

The header is declared globally in the OpenAPI file, but Carrier Connect operations reject it with 401 Authentication required. Use Basic or Bearer.

Test Credentials

Before you can start using the Carrier Connect API, you need a user and a password. AEB will provide them to you.

❗️

The client "APITEST" is intended for basic connectivity testing and is used by different users. This is not intended to use for API integration tests. Don't use it with sensitive data.

If you do not have your own client yet, you can use the following credentials to test the API:

ParameterValue
Carrier Connect Systemdemo1cai
ClientAPITEST
UserAPI_TEST
PasswordAPI_TEST2024

Check your setup

Confirm that credentials and endpoint work before you build a shipment:

curl -s -u 'API_TEST@APITEST:API_TEST2024' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -X POST 'https://rz3.aeb.de/demo1cai/rest/DLCarrierBFBean/getShipments' \
  -d '{}'

How to read the outcome:

ResponseMeaning
401 with "no @ for client found"The USER@CLIENT format is missing the client part
401 Authentication requiredCredentials rejected
403 Access denied to method …Authentication worked; the user lacks the role for that operation
200 with a JSON bodyYou are through — continue with Carrier Connect API Essentials

Note that the 200 body of this deliberately empty request contains "hasErrors": true. That is not a setup problem — it is the first thing the next page explains.


Did this page help you?