The API clients list
Open API in the sidebar. The list shows every client for the selected carrier, with the API families it can call, its current key (by its last characters) and expiry, and its status.
API clients for a carrier, with clients that need attention flagged
- show action required;
- have No assumed users;
- have an expired key, or one that expires within 14 days (shown as Expires in N days).
Create an API client
Select Create API client. The Setup panel on the right tracks the five steps.Client details

Name the client and choose when its key expires
API access

Select the endpoints the client may call
Assumed users

Choose the Cedar users the client may act as
Review and create
Save credential

The key is shown once. It is cleared when you leave the page.
Available API families
Railcar, Waybill, Work Order, Bookings, Charges, Shipper Invoices, Shipper Quotes, Truck Load Tender, Network Structure, and Notes. Which endpoints you can choose depends on Cedar’s published API catalog; an endpoint marked Deprecated is being retired and shouldn’t be used for new integrations.Call the API with your key
Send the key in thex-arms-api-key header and the email of one of the client’s assumed users in the
x-arms-assume-user header.
carrierId is your carrier’s numeric ID. Data Depot shows it as the foreign carrier ID on a Postgres source’s details
page, for example “Carrier-scoped to DEMO · Demo Rail Group (foreign carrier ID 9001)”.
- Use the right region. Keys are region-specific. Carriers in the EU use the
cedarai.sehostnames instead ofcedarai.com. See Regions. - Permissions come from the assumed user. A call succeeds only if the endpoint is selected on the client and the assumed user’s own Cedar roles allow it.
- Find each endpoint’s URL and body from the Documentation link in Data Depot or the API documentation.
Manage an API client
Select a client in the list to open its details.
An API client's details page
Change the endpoints
Select Edit access, change the selected endpoints, and select Save changes. The bar at the bottom summarizes the change, for example “Access will change from 4 to 6 endpoints”. The key doesn’t change.Manage assumed users
The Assumed users section shows how many users can call the client’s APIs.- Under Direct members, select Add users or Remove next to a user.
- Under Source group, select Link source group to sync membership from one Cedar user group. A linked group shows Synced, or Sync pending while changes are applied. You can Replace or Unlink it.

Assumed users and the client's credentials
Rotate the credential
Rotate before a key expires, or whenever you need a new one.Start the rotation
Save the new key
Switch your integration

Rotate with an overlap so your integration never loses access
Revoke a credential
Under Credentials, select Revoke next to a key and confirm. The key stops working immediately. This can’t be undone.Delete the client
Select Delete API client and type the client’s name to confirm. This revokes every key the client has and removes its API access.Credential statuses
Client details
The Client details panel shows the carrier, when the client was created, and the API catalog version it was built against. Data Depot manages a user group, role, and binding in the Admin Portal for each client; Technical details links to them with Open in Admin.When a client needs attention
- Action required. A change didn’t finish applying. Select Retry cleanup and reconciliation to try again. This needs the permission to delete API clients.
- Credential delivery could not be confirmed. The connection dropped while a new key was being created. Select Check request status. If the key can’t be shown, select Revoke unseen credential and generate replacement to get a new one safely.
- The API catalog changed. If Cedar retires an endpoint while you’re creating or editing a client, Data Depot asks you to review the updated selection.