UPS's APIs run on https://wwwcie.ups.com for testing and https://onlinetools.ups.com for live. Trade your app's client id and secret for a token first. Tracking needs transId and transactionSrc headers.
Create an app on the UPS Developer Portal. The token call sends its client id and secret as Basic auth (-u, PostTaco's Auth tab); the returned access_token is {{UPS_ACCESS_TOKEN}} in the other calls.
Full reference: https://developer.ups.com/
curl -X POST https://wwwcie.ups.com/security/v1/oauth/token \
-u {{UPS_CLIENT_ID}}:{{UPS_CLIENT_SECRET}} \
-H "Content-Type: application/x-www-form-urlencoded" \
-d grant_type=client_credentials
curl https://wwwcie.ups.com/api/track/v1/details/{{TRACKING_NUMBER}} \
-H "Authorization: Bearer {{UPS_ACCESS_TOKEN}}" \
-H "transId: posttaco-1" \
-H "transactionSrc: posttaco"