# ShipBob (slim) > Outsourced fulfilment service from ShipBob, Inc. of Chicago. Merchants send orders, products, inbound stock and returns to its warehouse network through a REST API with date-based versions, a hosted MCP server and webhooks, with a separate sandbox. - Full: https://www.anchorterminal.com/tools/shipbob.md (~8,200 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/shipbob.json · canonical https://www.anchorterminal.com/tools/shipbob - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 60.8/100 · rank #387 of 722 · #4 in Shipping & fulfilment · not agent-ready · confidence medium** Assessment: OAuth with PKCE and read and write scopes per domain, a free sandbox, a public OpenAPI spec per version and a 24-month support window for each API version are documented. Fulfilment prices are by quote only, the status page has no API component, no official SDK was found, and Personal Access Tokens never expire and carry full account access. ## Facts - Kind: HTTP API · vendor: ShipBob, Inc. · category: Shipping & fulfilment · legal entity: ShipBob, Inc. · provenance 85/100 - Endpoint: `https://api.shipbob.com` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under ShipBob's Terms of Service. The MCP tutorials repository on GitHub has no licence file - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.shipbob.com/2026-07, 77 paths and 89 operations in the OpenAPI 3.0 spec, across channels, orders, products, inventory, receiving, returns, tracking, billing, locations and webhooks - Access: Self-serve. A person signs up in a browser, then creates a Personal Access Token under Integrations, API Tokens, or creates an OAuth app. The Logistics API needs credentials from a ShipBob representative - Sandbox: Free, at https://sandbox-api.shipbob.com with accounts from webstage.shipbob.dev. Uses the test card 4111 1111 1111 1111, and a simulation terminal moves shipments, receiving orders and stock through their states - MCP server: Hosted at https://api.shipbob.com/developer-api/mcp (sandbox at https://sandbox-api.shipbob.com/developer-api/mcp), streamable HTTP only, 73 tools, OAuth with dynamic client registration or a Personal Access Token as Bearer. Free for customers - Credentials: OAuth 2.0 authorisation code grant with PKCE (S256) and a client secret, access tokens for 1 hour, refresh tokens for 30 days and rotated on use. Personal Access Tokens have every scope, no expiry, and can be revoked in the dashboard - Scopes: Read and write pairs for orders, products, inventory, fulfilments, receiving, returns and webhooks, plus `channels_read`, `locations_read`, `billing_read`, `pricing_read`, `tracking_read` and `offline_access` - Rate limits: 150 requests a minute on a sliding window, per user and application. A 429 carries `x-retry-after` in seconds, and the errors page recommends exponential backoff - Versioning: Date-based (YYYY-MM) in the URL path. A new version each January and July, each supported for 24 months. Endpoints under `/experimental` can change without notice - Webhooks: 15 topics for orders, shipments and returns, signed with a `webhook-signature` header, retried with exponential backoff over 24 hours - Costs through the API: `POST /2026-07/order:estimate` returns a fulfilment cost estimate for a possible order, and the billing endpoints return invoices and transactions - SDKs: None found from ShipBob. `shipbob-node-sdk` on npm is published by an individual - Compliance: SOC 2 and ISO 27001 audits completed, per the trust page. The Trust Center runs on Vanta. A DPA dated April 2026 and a list of about 30 subprocessors, all in the United States, are public - Status: status.shipbob.com on Statuspage, three components (merchant dashboard and two warehouse systems), none for the API - Scores: Reliability 77, Performance pending, Schema & documentation 85, Agent ergonomics 56, Security & auth 55, Payments & pricing 20, Task success pending, Maintenance & community 41, Transparency & trust 77 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the REST API at api.shipbob.com. · Schema & documentation, OpenAPI 3.0 spec for each version at marketplaceapi.shipbob.com, 89 operations in 2026-07. The `openapi.json` link in the docs index returns… · Agent ergonomics, Scored on the REST API, with the MCP server noted. · Security & auth, OAuth 2.0 authorisation code grant with PKCE, read and write scopes per domain, one-hour access tokens, 30-day refresh tokens rotated on use… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, API version 2026-07 was released on 31 July 2026, 69 days before the check (20 of 30). · Transparency & trust, Closed service. - Sources: 39, open questions: 9, both in the full twin - Capabilities: shipping.rates, shipping.tracking, shipping.returns, shipping.labels - JSON: https://www.anchorterminal.com/api/v1/tools/shipbob.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/shipbob.svg` or a link to https://www.anchorterminal.com/tools/shipbob from a page on shipbob.com or one of its subdomains, or the README of github.com/ShipBob/mcp-ai-tutorials, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `GET /2026-07/channel` first and send the ID of the channel with `_write` scopes in the `shipbob_channel_id` header on every write 2. Build against `https://sandbox-api.shipbob.com` with a sandbox account. Sandbox and production accounts, tokens and data are separate 3. Set a stable `reference_id` on each order, product and return. A duplicate returns 422, which is the only guard against a double create 4. Stay under 150 requests a minute per user and application, and wait the seconds given in `x-retry-after` after a 429 5. Over MCP, writes work only on records in the channel created at consent. A 403 or 404 on a cancel usually means the record belongs to another channel ## Connect ```bash curl -X GET "https://api.shipbob.com/2026-07/channel" \ -H "Authorization: Bearer YOUR_API_TOKEN" ``` ```bash claude mcp add --transport http shipbob-mcp --scope user https://api.shipbob.com/developer-api/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/shipbob ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Easyship | B | 68.8 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | https://www.anchorterminal.com/tools/easyship.min.md | | Sendcloud | B | 62 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | https://www.anchorterminal.com/tools/sendcloud.min.md | | Shippo | C | 61.9 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | https://www.anchorterminal.com/tools/shippo.min.md | | ShipStation API | C | 59.3 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | https://www.anchorterminal.com/tools/shipstation.min.md | | EasyPost | C | 54.3 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | https://www.anchorterminal.com/tools/easypost.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)