Provider connections, APIs and webhooks

Create a provider connection

Configure an external job/invoice/POD provider with secure endpoints and mappings.

Audience: Courier operations staffPermission: Courier: Manage integrationsModule v2.0.0
Exact navigationAdmin Area → Courier & Logistics → Settings → Providers → Add Provider

What this guide covers

Configure an external job/invoice/POD provider with secure endpoints and mappings. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.

Exact step-by-step process

  1. Open Settings and Providers.
  2. Enter provider name and choose type.
  3. Confirm the generated unique slug.
  4. Enter public HTTPS base URL and endpoint paths.
  5. Choose authentication method and enter credentials.
  6. Enter valid mapping JSON.
  7. Set sync interval from 5 to 1,440 minutes.
  8. Save inactive first.
  9. Test the provider.
  10. Activate only after successful validation.

Fields, choices and supported possibilities

Provider typescx, custom_json, returnloads or telematics.
Authenticationbearer, api_key, basic, oauth2_client_credentials or none.
Interval5–1,440 minutes.
MappingsValid JSON paths for provider payload normalisation.
SecretsEncrypted at rest and redacted from logs/audits.

Code-backed validations and workflow rules

  • Base and endpoint requests must resolve to public HTTPS destinations.
  • Secrets containing line breaks are rejected.

Expected result and verification

  • The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.

Security, audit and operational checks

  • Use the exact record and least-privilege role before changing any state.
  • Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
  • Use protected document and image routes rather than exposing server filesystem paths.
  • Keep customer, driver, provider, financial and credential data within the authorised workflow.
  • For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.