Connect delivery workflows to your software.
Apply for scoped API access, create approved credentials, and receive signed delivery events through governed server-to-server integrations.
A bounded delivery API.
Quote requests
Create delivery price quotes for an approved owner.
Courier orders
Create, read, cancel eligible orders, and read safe tracking for approved ownership.
Store orders
Read and manage approved store-order actions for an approved store.
Signed events
Create and manage verified webhook subscriptions and read safe delivery history.
Access is specific, reviewed, and owner-bound.
Start in the existing developer account route. Applications move through the canonical lifecycle: draft, submitted, under review, approved, then active where appropriate. Terms are accepted through the existing application flow.
- 01Create a draft
Record the integration purpose and intended environment through the authenticated route.
- 02Submit for review
The canonical application workflow records terms acceptance before submission.
- 03Receive approved scopes
Credentials require an active, approved scope grant and are bound to the application owner.
- 04Keep credentials protected
An opaque credential or signing secret is shown once only; rotate or revoke it through the protected route if necessary.
Work from the contract, not assumptions.
Authentication and environments
Use an opaque bearer credential from a protected server environment. The contract includes a test environment; live API access remains unavailable until it is activated.
Scopes
Scopes constrain what an approved application may do. They are not account permissions and are granted through the canonical review process.
quotes:writeCreate delivery price quotes for the approved owner.orders:readRead courier orders belonging to the approved owner.orders:writeCreate courier orders for the approved owner.tracking:readRead safe operational tracking for owned courier orders.store_orders:manageExecute approved marketplace store-order actions for the approved store.webhooks:writeCreate and manage verified webhook subscriptions.
Rate limits and quotas
Every operation names a rate-limit class and quota categories in the OpenAPI contract. The contract does not publish a universal numeric allocation, so this page does not invent one.
Idempotency
Send the documented Idempotency-Key for operations that declare it. Reuse a key only for the same intended request.
Errors
Rejected requests use RFC 9457-style Problem Details: type, title, status, detail, instance, code, and requestId; retry information appears when applicable.
Versioning
The public contract is versioned as v1. Use the served OpenAPI document as the authoritative route and schema reference.
Verify, then process events safely.
Create a webhook subscription through the protected owner route, complete its verification, and verify the raw request body before processing an event.
- Verify the raw bytes,
Content-Digest, HTTP message signature, timestamp tolerance, and replay protection. - Process events asynchronously after verification; do not use a secret in browser code or logs.
- Delivery retries are governed by the canonical webhook lifecycle. Authorized owners may request an eligible retry through the protected route.
POST /your-webhook-endpoint
Content-Digest: <digest of raw body>
Signature: <HTTP message signature>
Webhook-Id: <event identifier>
Webhook-Timestamp: <timestamp>
{
"type": "za.co.ktcouriers.order.updated.v1",
"data": { "reference": "<owned order reference>" }
}See the exact route and method contract.
The OpenAPI resource is served from the canonical checked-in contract. It is documentation, not a browser API console.
Quotes/quotes
Orders/orders
Catalog/catalog/products
Store orders/store-orders
Webhooks/webhooks