{"openapi":"3.1.0","info":{"title":"Traxelio API \u2014 Agents","version":"2026-07-10","description":"Traxelio is a fleet GPS tracking platform: live vehicle location, theft and fuel-theft protection, driver behavior monitoring, and predictive maintenance for owner-operators and multi-vehicle fleets. This contract covers the authenticated fleet-operation surface (devices, positions, geofences, maintenance, subscriptions) plus the public catalog, checkout, and support\/assistant surfaces used before and around a purchase. Pricing and payments are multi-currency, including mobile money (Wave, Orange Money) alongside cards and wire transfer. Two Bearer-token paths are documented, for two different callers. Traxelio's own first-party clients (the web app and native mobile apps) call one of the Authentication endpoints (POST \/api\/login, \/api\/login\/email + \/api\/login\/email\/verify, \/api\/login\/google, or \/api\/login\/apple) and send the returned token via the \"sanctum\" security scheme. Third-party AI agents and assistants must NOT call those endpoints; instead they authenticate via the \"oauth2\" security scheme: register an OAuth client with POST \/oauth\/register (no credential required), send the user through the authorization code flow with PKCE S256 (GET \/oauth\/authorize), and exchange the code at POST \/oauth\/token for a scoped, revocable token without the assistant ever handling the user's password or first-party credentials. Every sanctum-secured operation also accepts a matching-scope oauth2 token; see each operation's \"security\" array for the scopes it needs. RFC 8414 metadata lives at \/.well-known\/oauth-authorization-server, and RFC 9728 resource metadata at \/.well-known\/oauth-protected-resource. The top-level \"x-assistant-features\" extension maps each product capability to the operation_ids that implement it, so an agent integration can go straight from \"what can I do\" to the specific documented operations rather than inferring intent from tags or summaries.","contact":{"name":"Traxelio Support","url":"https:\/\/traxelio.com\/contact","email":"support@traxelio.com"},"termsOfService":"https:\/\/traxelio.com\/terms"},"servers":[{"url":"https:\/\/traxelio.com","description":"Production"}],"tags":[{"name":"Agents","description":"Machine-facing catalogue \u2014 IMEI identity lookup, then device\/brand\/protocol setup detail"}],"paths":{"\/api\/tracker-imei":{"get":{"operationId":"agents.tracker-imei.index","summary":"Resolve brand, model, and protocol identity from an IMEI or TAC","description":"Light f(imei) identity lookup. Family and SMS commands live on GET \/api\/trackers\/{brand}\/{device} (and brand\/protocol aggregates). Identity stays free. Detail includes 3 reads per client each calendar month, then pay.sh HTTP 402. One payment covers 4 reads of that exact detail URL.","tags":["Agents"],"security":[],"parameters":[{"name":"q","in":"query","required":true,"description":"IMEI or TAC digits. Fewer than eight searchable digits returns an empty data array.","schema":{"type":"string"}}],"responses":{"200":{"description":"Matching published catalogue rows (zero or more).","content":{"application\/json":{"schema":{"type":"object","properties":{"data":{"type":"array","items":{"type":"object","properties":{"key":{"type":"string","description":"brand_slug\/device_slug"},"name":{"type":"string"},"model":{"type":"string"},"brand":{"type":"string"},"make":{"type":"string"},"brand_slug":{"type":"string"},"device_slug":{"type":"string"},"protocol":{"type":["string","null"]},"url":{"type":"string","format":"uri","description":"HTML catalogue page"},"detail_url":{"type":"string","format":"uri","description":"JSON device detail (family + SMS)"},"media_url":{"type":["string","null"]},"medias":{"type":"array","items":{"type":"object","additionalProperties":true}},"brand_logo_url":{"type":["string","null"]}},"required":["key","name","model","brand","brand_slug","device_slug","detail_url"],"additionalProperties":false}}},"additionalProperties":false},"examples":{"default":{"$ref":"#\/components\/examples\/TrackerImeiListResponse"}}}}}},"x-laravel-route-name":"api.tracker-imei.index"}},"\/api\/trackers\/{brandSlug}\/{tracker}":{"get":{"operationId":"agents.trackers.device.show","summary":"Published tracker device setup detail (family + public SMS commands)","description":"Same public setup preview as the HTML device page. First 3 reads per client each calendar month are included. The next read is pay.sh HTTP 402 (PayShResourceGate::TRACKER_DETAIL). One settled payment covers 4 reads of that exact URL, including the request that carries X-PAYMENT. Each read uses one. The next read returns HTTP 402 again. A receipt does not authorize a different URL. The 402 body includes plain payment instructions.","tags":["Agents"],"security":[],"parameters":[{"name":"brandSlug","in":"path","required":true,"description":"Brand slug.","schema":{"type":"string"}},{"name":"tracker","in":"path","required":true,"description":"Device slug.","schema":{"type":"string"}}],"responses":{"200":{"description":"Device setup preview.","content":{"application\/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"device_name":{"type":"string"},"device_slug":{"type":"string"},"brand_slug":{"type":"string"},"url":{"type":"string","format":"uri"},"detail_url":{"type":"string","format":"uri"},"status":{"type":"string"},"protocol":{"type":["string","null"]},"protocol_label":{"type":["string","null"]},"family":{"type":["object","null"],"properties":{"slug":{"type":"string"},"name":{"type":["string","null"]}},"required":["slug"],"additionalProperties":false},"host":{"type":["string","null"]},"port":{"type":["integer","null"]},"sms_commands":{"type":"array","items":{"type":"object","properties":{"key":{"type":"string"},"label":{"type":"string"},"body":{"type":"string"}},"required":["key","label","body"],"additionalProperties":false}}},"required":["device_name","device_slug","brand_slug","status","sms_commands"],"additionalProperties":false}},"additionalProperties":false},"examples":{"default":{"$ref":"#\/components\/examples\/TrackerDeviceDetailResponse"}}}}},"403":{"$ref":"#\/components\/responses\/Forbidden"},"404":{"$ref":"#\/components\/responses\/NotFound"}},"x-laravel-route-name":"api.trackers.device.show"}},"\/api\/trackers\/{brandSlug}":{"get":{"operationId":"agents.trackers.brand.show","summary":"Published brand setup summary with representative devices","description":"Aggregate setup coverage for a brand's published devices. Same monthly free reads, then pay.sh HTTP 402. One payment covers 4 reads of this brand URL only.","tags":["Agents"],"security":[],"parameters":[{"name":"brandSlug","in":"path","required":true,"description":"Brand slug.","schema":{"type":"string"}}],"responses":{"200":{"description":"Brand setup summary.","content":{"application\/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"brand_name":{"type":"string"},"brand_slug":{"type":"string"},"device_count":{"type":"integer"},"status_counts":{"type":"object","additionalProperties":true},"representatives":{"type":"array","items":{"type":"object","properties":{"device_name":{"type":"string"},"device_slug":{"type":"string"},"brand_slug":{"type":"string"},"url":{"type":"string","format":"uri"},"detail_url":{"type":"string","format":"uri"},"status":{"type":"string"},"protocol":{"type":["string","null"]},"protocol_label":{"type":["string","null"]},"family":{"type":["object","null"],"properties":{"slug":{"type":"string"},"name":{"type":["string","null"]}},"required":["slug"],"additionalProperties":false},"host":{"type":["string","null"]},"port":{"type":["integer","null"]},"sms_commands":{"type":"array","items":{"type":"object","properties":{"key":{"type":"string"},"label":{"type":"string"},"body":{"type":"string"}},"required":["key","label","body"],"additionalProperties":false}}},"required":["device_name","device_slug","brand_slug","status","sms_commands"],"additionalProperties":false}},"detail_url":{"type":"string","format":"uri"},"url":{"type":"string","format":"uri"}},"required":["brand_name","brand_slug","device_count","representatives"],"additionalProperties":false}},"additionalProperties":false}}}},"403":{"$ref":"#\/components\/responses\/Forbidden"},"404":{"$ref":"#\/components\/responses\/NotFound"}},"x-laravel-route-name":"api.trackers.brand.show"}},"\/api\/trackers\/protocol\/{protocol}":{"get":{"operationId":"agents.trackers.protocol.show","summary":"Published protocol setup groups (family + SMS)","description":"Groups published devices on a protocol by setup status and command family. Same monthly free reads, then pay.sh HTTP 402. One payment covers 4 reads of this protocol URL only.","tags":["Agents"],"security":[],"parameters":[{"name":"protocol","in":"path","required":true,"description":"Protocol slug.","schema":{"type":"string"}}],"responses":{"200":{"description":"Protocol setup groups.","content":{"application\/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"protocol":{"type":"string"},"protocol_label":{"type":"string"},"device_count":{"type":"integer"},"groups":{"type":"array","items":{"type":"object","properties":{"key":{"type":"string"},"status":{"type":"string"},"protocol":{"type":["string","null"]},"family":{"type":["object","null"],"properties":{"slug":{"type":"string"},"name":{"type":["string","null"]}},"required":["slug"],"additionalProperties":false},"host":{"type":["string","null"]},"port":{"type":["integer","null"]},"sms_commands":{"type":"array","items":{"type":"object","properties":{"key":{"type":"string"},"label":{"type":"string"},"body":{"type":"string"}},"required":["key","label","body"],"additionalProperties":false}},"representatives":{"type":"array","items":{"type":"object","properties":{"device_name":{"type":"string"},"device_slug":{"type":"string"},"brand_slug":{"type":"string"},"detail_url":{"type":"string","format":"uri"},"url":{"type":"string","format":"uri"}},"required":["device_name","device_slug","brand_slug","detail_url"],"additionalProperties":false}}},"required":["key","status","sms_commands","representatives"],"additionalProperties":false}},"detail_url":{"type":"string","format":"uri"},"url":{"type":"string","format":"uri"}},"required":["protocol","device_count","groups"],"additionalProperties":false}},"additionalProperties":false}}}},"403":{"$ref":"#\/components\/responses\/Forbidden"},"404":{"$ref":"#\/components\/responses\/NotFound"}},"x-laravel-route-name":"api.trackers.protocol.show"}}},"components":{"schemas":{"ErrorMessage":{"type":"object","properties":{"message":{"type":"string","description":"Human-readable error message."}},"required":["message"],"additionalProperties":false},"OAuthChallengeError":{"type":"object","properties":{"error":{"type":"string","description":"RFC 6750 section 3.1 error code.","enum":["invalid_request","invalid_token","insufficient_scope"]},"error_description":{"type":"string","description":"Human-readable and localized. The identical WWW-Authenticate parameter is ASCII-only per RFC 6749 section 5.2, so the translated message travels here instead."},"scope":{"type":"string","description":"Space-delimited scopes this operation requires. Re-run the authorization code flow asking for these. Omitted when the operation has no scope entry at all, which is itself a refusal."}},"required":["error","error_description"],"additionalProperties":false},"ValidationErrorResponse":{"type":"object","properties":{"message":{"type":"string","description":"Summary message, e.g. \"The given data was invalid.\""},"errors":{"type":"object","description":"Keyed by field name; each value is a list of failing-rule messages for that field.","additionalProperties":{"type":"array","items":{"type":"string"}}}},"required":["message","errors"],"additionalProperties":false}},"examples":{"TrackerImeiListResponse":{"summary":"One published match for an eight-digit TAC","value":{"data":[{"key":"sinotrack\/st-901","name":"SinoTrack ST-901","model":"SinoTrack ST-901","brand":"SinoTrack","make":"SinoTrack","brand_slug":"sinotrack","device_slug":"st-901","protocol":"h02","url":"https:\/\/traxelio.com\/trackers\/sinotrack\/st-901","detail_url":"https:\/\/traxelio.com\/api\/trackers\/sinotrack\/st-901","media_url":null,"medias":[],"brand_logo_url":null}]}},"TrackerDeviceDetailResponse":{"summary":"Device setup detail with public SMS commands","value":{"data":{"device_name":"SinoTrack ST-901","device_slug":"st-901","brand_slug":"sinotrack","url":"https:\/\/traxelio.com\/trackers\/sinotrack\/st-901","detail_url":"https:\/\/traxelio.com\/api\/trackers\/sinotrack\/st-901","status":"commands","protocol":"h02","protocol_label":"H02","family":{"slug":"h02_hash","name":"H02 hash"},"host":"gps.traxelio.com","port":5023,"sms_commands":[{"key":"server","label":"Set server","body":"server,gps.traxelio.com,5023"}]}}}},"responses":{"Unauthorized":{"description":"Missing, invalid, or expired bearer token.","headers":{"WWW-Authenticate":{"description":"RFC 6750 challenge: Bearer, an RFC 9728 resource_metadata pointer at \/.well-known\/oauth-protected-resource, and on a scope refusal the error code plus the scopes the operation requires. Absent when a first-party sanctum token was refused by a policy rather than a scope.","required":false,"schema":{"type":"string"},"example":"Bearer error=\"insufficient_scope\", resource_metadata=\"https:\/\/traxelio.com\/.well-known\/oauth-protected-resource\""}},"content":{"application\/json":{"schema":{"$ref":"#\/components\/schemas\/ErrorMessage"}}}},"Forbidden":{"description":"The caller is authenticated but not authorized. A first-party sanctum token that fails a policy gets ErrorMessage; an OAuth token missing a scope gets OAuthChallengeError, which names the scopes to ask for.","headers":{"WWW-Authenticate":{"description":"RFC 6750 challenge: Bearer, an RFC 9728 resource_metadata pointer at \/.well-known\/oauth-protected-resource, and on a scope refusal the error code plus the scopes the operation requires. Absent when a first-party sanctum token was refused by a policy rather than a scope.","required":false,"schema":{"type":"string"},"example":"Bearer error=\"insufficient_scope\", resource_metadata=\"https:\/\/traxelio.com\/.well-known\/oauth-protected-resource\""}},"content":{"application\/json":{"schema":{"oneOf":[{"$ref":"#\/components\/schemas\/ErrorMessage"},{"$ref":"#\/components\/schemas\/OAuthChallengeError"}]}}}},"NotFound":{"description":"The resource does not exist, or does not belong to the caller.","content":{"application\/json":{"schema":{"$ref":"#\/components\/schemas\/ErrorMessage"}}}},"ValidationError":{"description":"Request failed validation.","content":{"application\/json":{"schema":{"$ref":"#\/components\/schemas\/ValidationErrorResponse"}}}},"ServerError":{"description":"The request was well-formed but could not be completed. Safe to retry.","content":{"application\/json":{"schema":{"$ref":"#\/components\/schemas\/ErrorMessage"}}}},"TooManyRequests":{"description":"Rate limit or plan-quota (consumable allowance) exceeded.","headers":{"Retry-After":{"description":"Seconds to wait before retrying. Present on rate-limiter-enforced 429s (Laravel's throttle middleware); not always present on plan-quota (consumable allowance) 429s.","required":false,"schema":{"type":"integer"}}},"content":{"application\/json":{"schema":{"$ref":"#\/components\/schemas\/ErrorMessage"}}}}},"securitySchemes":{"sanctum":{"type":"http","scheme":"bearer"},"oauth2":{"type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https:\/\/traxelio.com\/oauth\/authorize","tokenUrl":"https:\/\/traxelio.com\/oauth\/token","refreshUrl":"https:\/\/traxelio.com\/oauth\/token","scopes":{"user.view":"See your name, phone, and email on file.","user.update":"Change your name, phone, or email, and update your app preferences.","cart.update":"See what's in your cart and add, change, or remove items.","order.view":"See your order details and their progress.","order.create":"Start a new order or add an add-on to an existing one.","order.checkout":"Create a payment and get a checkout link for an order.","appointment.view":"See your scheduled service appointments.","appointment.create":"Schedule a new service appointment.","appointment.update":"Reschedule or mark an appointment complete.","appointment.delete":"Cancel a scheduled appointment.","device.subscription.update":"Create, renew, or upgrade a device's subscription plan.","tracking.read":"See where your vehicles are, their trip history, and recent activity.","device.alarm":"Turn a vehicle's anti-theft alarm on or off.","device.immobilize":"Remotely cut or restore a vehicle's engine power.","device.locate":"Request a single position fix, or stop a device from reporting its location.","report.read":"See mileage, odometer, and activity reports for your fleet.","geofence.read":"See your geofences and points of interest.","geofence.write":"Create, change, or delete geofences and points of interest.","maintenance.read":"See inspections, documents, service history, issues, and costs.","maintenance.write":"Log inspections, service visits, documents, issues, and costs, or remove them.","device.settings.read":"See alert thresholds like speed limit, towing, impact, low battery, and fuel monitoring.","device.settings.write":"Change or remove alert thresholds like speed limit, towing, impact, low battery, and fuel monitoring.","device.activate":"Bind a tracker to your account and select its plan.","device.destroy":"Detach a device from your account. Its history and subscription stay intact: only your ownership link is removed.","device.share.view":"See which people already reach your vehicles, and what each of them is allowed to do.","device.share.manage":"Grant another person access to your vehicles, change what they are allowed to do, or revoke it. Anyone granted access reaches those vehicles from their own account.","subscription.view":"See subscriptions, orders, payments, and devices tied to your account.","team.view":"See your team's members and the devices assigned to it.","team.manage":"Add, remove, or change team members and their device assignments.","customer.view":"See your team's customers, their contact details, and the addresses you deliver to. Your customers' data, not yours.","customer.manage":"Add, change, or remove your team's customers and their delivery addresses. Your customers' data, not yours.","notification.view":"See which devices are registered to receive push notifications.","notification.manage":"Register or remove a device for push notifications, and mark alerts as read.","support.read":"See your chat conversations with support.","support.write":"Send chat messages and start or delete support conversations.","session.revoke":"End one of your active app sessions.","connected-app.revoke":"Remove an app or AI assistant's access to your account.","catalog.read":"See which permissions exist, check whether an action is allowed for you, and ask us to cover a country we do not cover yet.","camera.read":"See your dashcams, their live and recorded sessions, driving positions and scores, and the status of clips you've requested.","camera.control":"Start a live video stream from a dashcam, and run its connectivity or hardware diagnostics.","camera.share":"Create or revoke a time-limited link that lets someone view a dashcam's live feed without signing in.","camera.clip-request":"Request a video clip from a dashcam session, and create a shareable link once it's approved.","camera.driver-profile.view":"See a driver's camera profile, including whether their face is enrolled for recognition.","camera.driver-profile.manage":"Create a driver's camera profile, upload a face photo for recognition, and resolve driver-identity verification requests.","camera.enrollment":"See your own enrolled face photos and the times cameras recognised you."}}}}}}}