Environments
The API runs in two isolated environments. They share the same contract; only the base URL, the credentials and the data differ.
| Environment | Base URL | Data |
|---|---|---|
| Sandbox | https://api-sandbox.uniqueonthego.com |
Synthetic tasks and locations, safe to test against |
| Production | https://api.uniqueonthego.com |
Your live fleet data |
Credentials are environment-specific. A sandbox client_id is rejected in
production and the other way around.
Getting credentials
Section titled “Getting credentials”Credentials are issued during partner onboarding:
- Your account manager opens an API access request with the Unique team.
- You name a technical contact and, optionally, the egress IP ranges your integration will call from.
- We issue a sandbox
client_idandclient_secretthrough a secure, one-time link. We never send secrets over email or chat. - Once your integration works in sandbox, we issue production credentials the same way.
Rotating and revoking credentials
Section titled “Rotating and revoking credentials”- Each client can hold two active secrets at the same time, so you can deploy a new secret before retiring the old one without downtime.
- Ask for a rotation whenever a team member with access leaves, or at least once a year.
- If you believe a secret has leaked, contact security@uniqueonthego.com. We revoke it immediately; tokens already issued with it stop working within their one-hour lifetime at most.
IP allowlisting
Section titled “IP allowlisting”If you share your egress IP ranges, we can restrict your credentials to them.
Requests from any other address are then rejected with 403 forbidden, even
with a valid token.