At a glance
Days until your Sendle API key expires (or, where keys are non-expiring, days until the calendared rotation date set by the merchant). Sendle’s primary auth model is a long-lived API key tied to the workspace; some enterprise accounts schedule rotations on quarterly or annual cadences for security hygiene. When the key invalidates, label-print and tracking calls fail, breaking despatch end-to-end.
Calculation
Calculated automatically from your Sendle data. See the At a glance summary above for what the metric tracks and the worked example below for a typical reading.Worked example
The Australian DTC home-goods brand. Reading taken at 09:00 AEDT on 12 Mar 26.
The card reads 16 days. The alert at
<14 days is not yet firing but will trigger in 2 days. Five things to notice:
- The 16-day reading is the right time to schedule rotation. It is calendar-warning land: the operator has time to plan a rotation window during business hours next week. Sendle’s API does not auto-expire, so the merchant is rotating purely for security hygiene; missing the calendared date does not break despatch immediately.
- Sendle keys are functionally non-expiring. Unlike ShippyPro’s OAuth bearer model, Sendle’s API key remains valid indefinitely until the merchant manually revokes. The “expiry” the card tracks is a self-imposed rotation discipline, not a Sendle constraint. Some merchants set this to “never” and suppress the alert; the discipline is recommended for SOC 2 / ISO 27001 alignment.
- Rotation is fast. Generate new key in Sendle Dashboard → Settings → Account & Plans → API, copy, paste into the Vortex IQ connector settings, save. Total time <5 minutes if access is pre-authorised. The old key remains valid until manually revoked, so there is a grace overlap.
- For multi-region merchants, each region has its own key. AU and US Sendle accounts are separate; rotate independently and stagger the rotation calendar so they never expire in the same week.
- The card resets to the new rotation cadence after rotation. Update the calendared next-rotation in the connector config; the card re-reads on the next poll. If you forget to update the calendar, the card will show 0 or negative days while the actual key continues working; Sendle’s API will not error.
Sibling cards merchants should reference together
Token-expiry is binary at the day level (alert fires or not), and a leading indicator for connector failure when the merchant treats it as a real expiry not a calendared discipline.Reconciling against the vendor’s own dashboard
Where to look in Sendle’s own dashboard: Sendle Dashboard → Settings → API Keys. The page lists active keys with creation date and last-used timestamp. There is no expiry column because Sendle keys do not natively expire; the rotation calendar is merchant-owned. The card and the portal will not match exactly because the rotation date is held in Vortex IQ’s connector config, not in Sendle. Why our number may legitimately differ from Sendle’s portal:
Cross-connector reconciliation: