Configure the BP fuel connection
Create the secure connection used to fetch fuel transactions.
Exact navigationAdmin Area → Courier & Logistics → Settings → BP Fuel
What this guide covers
Create the secure connection used to fetch fuel transactions. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.
Exact step-by-step process
- Choose sandbox or production environment.
- Choose authentication method.
- Enter public HTTPS base URL and transactions endpoint.
- Enter required credentials/token endpoint.
- Enter mapping JSON containing transaction_id and transaction_at.
- Set interval from 15 to 1,440 minutes.
- Save inactive.
- Test.
- Activate only after validation.
Fields, choices and supported possibilities
Environmentproduction or sandbox; other values fall back to sandbox.
Authenticationoauth2, bearer, api_key or none.
Required mappingtransaction_id and transaction_at.
Interval15–1,440 minutes.
Code-backed validations and workflow rules
- Active configuration requires base URL and transactions endpoint.
- Authentication-specific credentials must be present.
- Header values and secrets are sanitised; line breaks are rejected.
Expected result and verification
- The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.
Security, audit and operational checks
- Use the exact record and least-privilege role before changing any state.
- Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
- Use protected document and image routes rather than exposing server filesystem paths.
- Keep customer, driver, provider, financial and credential data within the authorised workflow.
- For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.
