Setting up your environment
Authentication
Authentication data must be provided for every call. It is expected as an HTTP authentication (HTTP basic protocol). The user and client login data is transmitted in the format:
USER@CLIENT:PASSWORT
You cannot use regular Carrier Connect users for API requests! Instead you will need a special API user to transmit API requests, which usually starts with WSM.
The login data must be base 64–encoded. The password is written out, so this is why we require using HTTPS encryption and the data cannot be intercepted by unauthorized parties.
Example:
The string "API_TEST@APITEST:API_TEST2024", when encoded in base 64, yields "QVBJX1RFU1RAQVBJVEVTVDpBUElfVEVTVDIwMjQ=".
The following line would therefore be added to the HTTP header:
Authorization: Basic QVBJX1RFU1RAQVBJVEVTVDpBUElfVEVTVDIwMjQ=
Copy the trailing "=" as wellIt is part of the base 64 padding. Some servers reject an unpadded value.
Always send Accept: application/json as well, so that error responses come back as JSON rather than as an HTML error page.
Firewall: IP subnetworks of the AEB data centers
Carrier Connect is reached over HTTPS on port 443 only. If your firewall or proxy restricts outbound traffic, allow AEB's inbound web subnetworks:
194.15.60.0/25
194.15.61.0/25
194.15.62.0/25
193.98.221.0/25
194.175.186.0/24Allow all five, not the single IP address of the host you happen to call. AEB moves services between data centers, and a rule pinned to one address stops working on failover.
Two cases need more than the rows above, and both are covered by Public IP subnetworks of the AEB data centers — the maintained source, which wins over this page:
- SFTP (TCP 22), if you exchange EDI files with AEB — its own set of subnetworks.
- AEB's outbound source IPs, if your own firewall filters traffic coming from AEB.
Systems
Every URL in this guide contains an {installation} placeholder. Replace it with the system you connect to:
{installation} | Description |
|---|---|
| demo1cai | Demo system — shared, used for connectivity tests and the test credentials below |
| test2cai | Test environment |
| prod1cai | Productive environment |
| prod2cai | Productive environment (First Customer) |
Endpoints
All Carrier Connect operations are POST calls under one base URL:
https://rz3.aeb.de/{installation}/rest/DLCarrierBFBean/{operation}For example: https://rz3.aeb.de/demo1cai/rest/DLCarrierBFBean/createShipment.
The complete list of operations, with every field, is under API Reference:
Documentation
REST (OpenApi)
https://rz3.aeb.de/{installation}/rest/openapi.jsonThis is the authoritative machine-readable contract for every field. The file covers the whole installation — Carrier Connect operations are the ones tagged Shipping, under DLCarrierBFBean.
SOAP
Carrier Connect is also available over SOAP. Use REST for new integrations; SOAP is there for existing ones.
https://rz3.aeb.de/{installation}/servlet/bf/DLCarrierBF?WSDL
https://rz3.aeb.de/{installation}/servlet/bf/doc/DLCarrierBF/de/aeb/xnsg/dl/bf/IDLCarrierBF.htmlOptional: token authentication
Instead of sending Basic credentials on every call, you can exchange them once for a token:
curl -u 'USER@CLIENT:PASSWORD' \
-H 'Accept: text/plain' \
'https://rz3.aeb.de/{installation}/rest/logon/authToken'Send the returned token as Authorization: Bearer <token> on subsequent calls.
This one call needs "Accept: text/plain"
/logon/authTokenreturns the token as plain text. WithAccept: application/jsonit answers406 Not Acceptable.
POST /logon/user (body: userName, password, clientName, optional localeName) is the alternative, and additionally returns the roles granted to the user.
"X-XNSG_WEB_TOKEN" is not an API integration pathThe header is declared globally in the OpenAPI file, but Carrier Connect operations reject it with
401 Authentication required. Use Basic or Bearer.
Test Credentials
Before you can start using the Carrier Connect API, you need a user and a password. AEB will provide them to you.
The client "APITEST" is intended for basic connectivity testing and is used by different users. This is not intended to use for API integration tests. Don't use it with sensitive data.
If you do not have your own client yet, you can use the following credentials to test the API:
| Parameter | Value |
|---|---|
| Carrier Connect System | demo1cai |
| Client | APITEST |
| User | API_TEST |
| Password | API_TEST2024 |
Check your setup
Confirm that credentials and endpoint work before you build a shipment:
curl -s -u 'API_TEST@APITEST:API_TEST2024' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
-X POST 'https://rz3.aeb.de/demo1cai/rest/DLCarrierBFBean/getShipments' \
-d '{}'How to read the outcome:
| Response | Meaning |
|---|---|
401 with "no @ for client found" | The USER@CLIENT format is missing the client part |
401 Authentication required | Credentials rejected |
403 Access denied to method … | Authentication worked; the user lacks the role for that operation |
200 with a JSON body | You are through — continue with Carrier Connect API Essentials |
Note that the 200 body of this deliberately empty request contains "hasErrors": true. That is not a setup problem — it is the first thing the next page explains.
Updated about 2 months ago