Provider connections, APIs and webhooks

Understand provider webhook event processing

Know how invoice, job and location payloads are routed.

Audience: Courier operations staffPermission: Courier: Manage integrationsModule v2.0.0
Exact navigationPublic API route → /clm/webhook/{provider_slug}

What this guide covers

Know how invoice, job and location payloads are routed. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.

Exact step-by-step process

  1. Open Public API route → /clm/webhook/{provider_slug}.
  2. Review the source record and choose the supported action.
  3. Save or submit once, then reopen the record and verify the result.

Fields, choices and supported possibilities

invoice eventsImported into provider invoice records.
job eventsNormalised/imported or applied to linked jobs.
location eventsRetained/processed for operational snapshot where supported.
authenticationSignature-valid state retained with the webhook log.

Code-backed validations and workflow rules

  • Payload, hash, signature result and HTTP status are logged.
  • External completion does not bypass local POD evidence.

Expected result and verification

  • The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.

Security, audit and operational checks

  • Use the exact record and least-privilege role before changing any state.
  • Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
  • Use protected document and image routes rather than exposing server filesystem paths.
  • Keep customer, driver, provider, financial and credential data within the authorised workflow.
  • For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.