Provider connections, APIs and webhooks

Configure No-authentication provider

Call a public/allowlisted provider endpoint without credentials.

Audience: Courier operations staffPermission: Courier: Manage integrationsModule v2.0.0
Exact navigationAdmin Area → Courier & Logistics → Settings → Providers → Open provider

What this guide covers

Call a public/allowlisted provider endpoint without credentials. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.

Exact step-by-step process

  1. Choose the matching Authentication method.
  2. Enter only the fields required for that method.
  3. Save.
  4. Test the provider.
  5. Review the response without exposing secrets.

Fields, choices and supported possibilities

This action uses the values already stored on the selected source record. Review that record before continuing.

Code-backed validations and workflow rules

  • Credentials are encrypted before storage.
  • Secrets with line breaks are rejected.
  • Use HTTPS endpoints only.

Expected result and verification

  • The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.

Security, audit and operational checks

  • Use the exact record and least-privilege role before changing any state.
  • Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
  • Use protected document and image routes rather than exposing server filesystem paths.
  • Keep customer, driver, provider, financial and credential data within the authorised workflow.
  • For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.