---
title: "Carrier credentials in Ingrid"
canonical: "https://ingrid-support.refined.site/space/KB/591200257/Carrier%20credentials%20in%20Ingrid"
format: markdown
---
## What is it?

Carrier credentials are the authentication keys, tokens, and account details that let Ingrid communicate with your carriers on your behalf — to fetch rates, book shipments, generate labels, track parcels, and process returns.

Without valid credentials, Ingrid can't talk to the carrier. For some carriers, Ingrid manages the credentials centrally — for others, you bring your own. Setting them up correctly the first time, keeping them current as carriers rotate them, and handing them off cleanly when people change jobs are all part of running carrier integrations day to day.

This article covers the concepts and common scenarios that apply across all carriers. For carrier-specific setup steps (which fields to find in the carrier's own portal, exact field names, validation quirks), see the per-carrier articles in this section (coming soon) and [carrier.ingrid.com](https://carrier.ingrid.com/) for product capabilities and required configuration.

---

## How carrier credentials work in Ingrid

### Where credentials live

Carrier credentials are stored securely in Ingrid's carrier configuration. Once entered, credentials are stored encrypted and cannot be viewed in plain text afterward — only updated or replaced.

### Who provides the credentials

The source of credentials depends on the carrier and on the specific function (checkout, tracking, booking). For the same carrier, the model can differ between functions.

- **Ingrid-unified credentials** — Ingrid uses its own credentials and you don't manage them directly. **This is the most common model for checkout integrations**, where Ingrid handles authentication centrally so merchants don't have to. Onboarding is faster and credential management is centralized.
- **Merchant-owned credentials** — you obtain credentials from the carrier directly (from the carrier's own portal, account manager, or 3PL) and enter them in Ingrid. Common for carriers where coverage, pricing, or features depend on your specific contract — for example, where a carrier limits service to specific zip codes per partner, or where pricing varies by account.
- **Hybrid models** — some integrations combine Ingrid's "parent" credentials with a merchant-specific "child" credential generated during setup (as with FedEx Compatible Solution Provider integrations).

**Note:** The model can differ between checkout and tracking for the same carrier. A carrier may use Ingrid-unified credentials for checkout but require merchant-owned credentials for tracking (or vice versa).

A per-carrier reference is in progress and will be integrated into the carrier library at [carrier.ingrid.com](https://carrier.ingrid.com/). For now, contact your Ingrid CSM to confirm the model for your specific carriers.

### What credentials look like

Credentials vary by carrier — they may be API keys, OAuth tokens (consumer key + secret), username/password pairs, or account numbers paired with one or more API endpoints. The exact format follows the carrier's API design.

When a carrier integration requires merchant-owned credentials, Ingrid shows the fields you need to fill in. Required vs optional fields differ by carrier.

---

## Common scenarios

### Initial setup

Setup depends on the credentials model:

**For carriers with Ingrid-unified credentials:** no credentials to provide. Confirm the integration is enabled for your account through your CSM, then start using the carrier.

**For carriers with merchant-owned credentials:**

1. Get credentials from the carrier — usually through the carrier's own merchant or developer portal, your account manager, or your 3PL if they hold the carrier contract.
2. Add the credentials in Ingrid's carrier configuration.
3. Validate by running a test booking, label generation, or tracking call.

For carriers where setup involves multi-factor authentication (MFA), an end-user license agreement (EULA), or a contract migration step, follow the per-carrier guide.

### Rotation

**For Ingrid-unified carriers,** Ingrid handles rotation centrally — no merchant action needed.

**For carriers with merchant-owned credentials,** some rotate credentials on a fixed cycle (annual rotations are common with global express carriers). When rotation happens:

1. The carrier provides new credentials before the old ones expire.
2. Update the credentials in Ingrid before the rotation date.
3. Validate the new credentials by running a test call.

If credentials aren't updated in time, booking and label generation will fail for the affected carrier.

### Employee turnover

This scenario applies to carriers with merchant-owned credentials. For Ingrid-unified carriers, there's nothing to recover at handover.

If the person who originally set up the credentials has left the company, the credentials themselves remain valid — they aren't tied to the individual user. What you need to recover is access to the source of those credentials:

- The carrier's merchant portal (request access through your carrier account manager)
- Internal records (your IT or operations team)
- 3PL or fulfillment partner who set up the integration

Once you can retrieve fresh credentials from the carrier, replace the existing ones in Ingrid.

### 3PL access

If a third-party logistics (3PL) provider holds your carrier credentials on your behalf:

- Confirm whose name the carrier contract is under — yours or the 3PL's. This determines who owns and can share the credentials.
- If the contract is in your name, ask the 3PL to share the credentials or set them up directly in Ingrid.
- If the contract is in the 3PL's name, the credentials belong to them — carriers generally avoid sharing a third party's credentials for security reasons. In rare cases, the carrier's account manager may open a new account on your behalf and issue a separate set of credentials for your direct use. Confirm feasibility with the carrier first.

### Replacement and migration

When you replace credentials (for example, moving from a legacy integration to a modern API, or switching between carrier contracts):

1. Obtain the new credentials from the carrier.
2. Update them in Ingrid.
3. Run a test booking and a test label generation to confirm the new credentials work end to end.
4. Disable or remove any legacy credentials no longer in use.

### Security best practices

- Don't share credentials over email or in shared spreadsheets.
- Use the carrier's official portal or a secure password manager to transfer credentials between people.
- Limit access to the carrier's merchant portal to people who need it.
- Document where credentials are stored internally so handovers are clean.

---

## What if something goes wrong?

| Symptom | Likely cause | What to check |
| --- | --- | --- |
| Credentials worked yesterday, fail today | Carrier rotated credentials or revoked the API user | Check with the carrier; obtain new credentials and update in Ingrid |
| Cannot find credentials in the carrier's portal | Permission level too low, or credentials owned by another role | Ask your carrier account manager or 3PL |
| 3PL won't share credentials | Contract held under their name; security and policy reasons | Confirm with the carrier — in rare cases they can open a new account on your behalf |
| Original setter has left the company | Access to the carrier portal lost with them | Recover access through the carrier (account manager or IT) |
| Credentials accepted but bookings fail | Credentials valid but configuration incomplete (missing fields, contract ID, market) | Verify the full configuration; see per-carrier guides |

For issues not covered above, contact your Ingrid CSM.

---

## FAQ

**Q: Why can't I see my credentials in plain text after entry?**  
A: For security, Ingrid stores credentials in encrypted form and doesn't display them after they're saved. You can replace credentials at any time, but you can't re-read them.

**Q: How often do carriers rotate credentials?**  
A: It depends on the carrier. Some rotate annually (common for global express carriers), others not on a fixed schedule. For Ingrid-unified carriers, rotation is handled by Ingrid. For merchant-owned credentials, check with your carrier or account manager for the rotation policy.

**Q: My 3PL holds my credentials — what should I do?**  
A: Confirm whose name the carrier contract is in. If the 3PL holds the contract, they own the credentials and need to grant you access or set up the integration on your behalf. If the contract is in your name, the carrier can issue credentials directly to you.

**Q: I'm a new joiner — how do I take over carrier setup from my predecessor?**  
A: For Ingrid-unified carriers, there's nothing to take over — Ingrid manages the credentials. For merchant-owned credentials, recover access to the carrier's merchant portal first (through your carrier account manager or internal IT). Once you can retrieve credentials from the carrier, you can update them in Ingrid — the previous credentials don't need to be "transferred" to you.

**Q: When does Ingrid provide the credentials versus when do I?**  
A: For most checkout integrations, Ingrid uses its own credentials (Ingrid-unified model). For carriers where coverage or pricing depends on your specific contract — and for many tracking integrations — you provide credentials directly. The model can differ between checkout and tracking for the same carrier. A per-carrier reference is in progress in the carrier library; for now, your Ingrid CSM can clarify for your specific carriers.

**Q: Can I see which carriers I have credentials set up for?**  
A: Yes — Ingrid shows your configured carriers and their integration status. If a carrier appears as not configured and uses merchant-owned credentials, you may still need to provide them.