Settings, cron automation and technical code flow

Understand Courier public routes

Identify token and webhook endpoints without exposing internal files.

Audience: Courier operations staffPermission: Courier: AdministratorModule v2.0.0
Exact navigationApplication routes → Courier public/API controllers

What this guide covers

Identify token and webhook endpoints without exposing internal files. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.

Exact step-by-step process

  1. Open Application routes → Courier public/API controllers.
  2. Review the source record and choose the supported action.
  3. Save or submit once, then reopen the record and verify the result.

Fields, choices and supported possibilities

/clm/pod/{token}Public POD page.
/clm/signature/{token}Controlled signature image.
/clm/snapshot/{token}Controlled snapshot image.
/clm/webhook/{provider_slug}Provider webhook receiver.

Code-backed validations and workflow rules

  • POD/image access uses the retained token.
  • Webhook access uses provider slug plus configured authentication/signature validation.

Expected result and verification

  • The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.

Security, audit and operational checks

  • Use the exact record and least-privilege role before changing any state.
  • Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
  • Use protected document and image routes rather than exposing server filesystem paths.
  • Keep customer, driver, provider, financial and credential data within the authorised workflow.
  • For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.