GRAPHQL API
Explore, test, and integrate with our GraphQL endpoint
Authentication and account operations
Revoke the current access token
Change the authenticated user password
Authenticate and obtain an access token
Issue a fresh access token for the authenticated user
Issues a NEW access token while the CURRENT one keeps working for a grace window (default 60 minutes), after which it expires automatically. The current token's lifetime is only ever shortened, never extended.
Driver app operations: routes, orders, delivery, uploads
Get kiosk receiving area package count for a kiosk pickup order on a route
Get driver order files by order ID
Get unified price detail for a driver order
The authenticated driver's own orders
Get order notes
Get order status list
The authenticated driver profile
Get routes for one driver
Get order stop number by ref/orderid/trackingnumber
Get orders on route for one driver
Get points on route for one driver
Get SMS fail content by order ID
Get SMS success content by order ID
Get SMS content by template ID and order ID
Get driver SMS templates
Add Gps Tracking Record
Batch update delivery status for multiple orders
Cancel a route as the assigned driver
Create a new route by driver
Delete driver FCM token
Delete order picture by orderfile Id
end Delivery By route id
Scan a code at a kiosk location and receive an awaiting-processing package (return, express drop-off or storage drop-off) from the receiving area onto driver vehicle inventory
optimize route
Create a note on one of the driver's orders
Update the status of one of the driver's orders
Update the authenticated driver profile
Register a new driver
Add order to route by ref/orderid/trackingnumber
Batch Add Orders to Route by Driver
Batch remove orders from a route
Remove order from route by orderId
Validate an order ref against an order id
start Delivery By route id
Update delivery status for an order
Update driver FCM token for push notifications
Upload order picture
Driver profile records management
The business driver list
Create a driver
Delete driver information by driver ID
Client (business) operations: orders, routes, customers
Get async batch-order-create result by id
Available options for building routes (engines, capacity/related-order/order-source types, defaults).
List the client/employee customer directory
Get address by postcode
The id => name order-status map
Available Local Delivery order channels
The business routes with per-status counts and driver rollup
Orders on a route (optionally for one driver)
User-selectable surcharges for Local Delivery orders
The authenticated business's active territories
Batch Create orders
Queue an async batch order-create
Build routes
Build routes using V2 endpoint
Build routes using V3 endpoint with full /orders/build parameter support
Create an order
Dispatch the batch-receive job for an order batch
Receive a single package by search key (order id / ref / tracking number)
Add orders to a route
Cancel a route
Move orders from one route to another
Optimize a route for the given drivers
Remove orders from a route (optionally cancelling them)
Replace a driver on an existing route
Customer app operations: storage / moving / shipping orders
Get the configuration bundle needed to render the customer create-moving-order form
Get the detail of one moving order owned by the authenticated customer
Paginated list of the authenticated customer's moving orders
Get the per-service configuration bundle for a shipping service the customer has access to
List shipping services available to the authenticated customer
Get the detail of one shipping order owned by the authenticated customer, under a specific service
Paginated list of the authenticated customer's shipping orders under one service
Get the configuration bundle needed to render the customer create-storage-order form
Get the detail of one storage order owned by the authenticated customer
Paginated list of the authenticated customer's storage orders
Customer storage ship-out flow
List storage packages eligible for shipout, optionally filtered by warehouse_id
Customer cancels a shipout (allowed only in PENDING/CONFIRMED). Releases the StoragePackage pivot lock.
Create a shipout request from one or more storage packages (single warehouse)
Customer pays a storage-shipout from their wallet balance
Customer picks one of the carrier-returned rates on a label-direct shipout
Order lifecycle operations
Get order by Id or reference number or tracking number
Cancel an order by id (legacy path, unchanged), or by tracking_number / external_tracking_number (idempotent path, backs POST /v1/orders/cancel: already-cancelled orders return result=true with already_cancelled=true; a number matching multiple live orders returns matched_order_ids).
Stable (updated_at, id) cursor pagination over the caller's orders within an updated_at window. Pass next_cursor from the previous page to continue; items carry unix timestamps. updated_from/updated_to accept unix timestamps or 'Y-m-d H:i:s' strings in the platform timezone.
Id-ascending cursor pagination over the caller's tracking events (append-only) within an updated_at window. occurred_at/occurred_timestamp expose the business occurrence time (falls back to created time for historical rows).
Get packages of an order
Delete an order
Modify an order
Pickup an order
Get order by Id or reference number or tracking number
Get orders by status
Delete packages from an order
Rate a shipment
Update order batch
Update order time window by refs
Put order on HOLD
Release order from HOLD
Pages orders_files rows by updated_at window + id-ASC cursor, scoped to the caller's business (and customer for customer users). Lets partners sync late or replaced POD attachments without re-querying whole orders. Hard-deleted files stop appearing - pair with the pod.files_updated webhook (action=deleted) to observe removals.
Submit up to 500 of YOUR numbers (matched against external_tracking_number, tracking_number and package ref) and get back, per number: whether it exists, the matched order(s) with current status, proof-attachment count and latest tracking-event id - plus a `missing` list. Designed for scheduled consistency checks without one-by-one tracking queries.
Shipping label printing and stop lookup
Print/download a shipping label by order id, ref or tracking number
Generate a shipping label PDF (base64) with label metadata
Get a stop number by ref within a route
Third-party shipping label service integration
cancel a created shipping label
end of day submit shipping information
get Shipping Detail By Order ID or Tracking Number or Third Party Tracking Number
download Shipping Label pdf by Order ID or Tracking Number or Third Party Tracking Number
list the caller shipping methods
get rate
submit a new label order
submit shipping information for one or more orders
upload a shipping label for a label-service order
Address book entries
Get the address book list for the current user
Get the address book list for the current user
Address search and geocoding
Get address by postcode
Search address by text
Search address by structured address
Driver skills
Get the skills list for the current user
Get the skills list for the current user
Return reasons
Get the return reasons list for the current user
Get the return reasons list for the current user
Coverage area and postcode checks
Get the covered postcodes for the current user's territories
Check whether postcodes are within the caller's coverage
Inventory and package warehouse operations
Aggregated stock levels per SKU/variant across the tenant warehouses
get driver stock out list
find route by package search key
Process package outbound from inventory
Receive package by given orderId/ref/tracking/externalTracking/Inventory Ref
search package by key
batch stock in inventory records by grid_code
stock out by given orderId/ref/tracking/externalTracking/Inventory Ref
Warehouse-management-system provider integration
get warehouse list
get wms connect warehouse list
get wms connect
get warehouse field by id
List available WMS provider types and their field schemas
Cancel Inbound Request
Cancel Outbound Request
Get Inbound Request Detail
getNearestWarehouse
getShippingMethodFromWarehouse
get inventory list
submit a new inbound request
submit a new outbound request
Upload Shipping Label for Outbound Orders
create wms connect
Delete a WMS connect integration
Inter-warehouse transfer batches
Transfer selected packages from one warehouse to another and update order fulfillment center
Paginated list of warehouse transfer batches
Rollback an entire warehouse transfer batch
Search candidate mis-received local delivery packages for warehouse transfer
Get a warehouse transfer batch detail
Package tracking (public and internal)
Get 17Track tracking information by tracking number
Get internal tracking information by tracking number
Get public tracking information by tracking number
Generate tracking numbers
Look up package information by tracking number
get operation events
Submit external tracking event
OTEP tracking integration
OTEP unified tracking timeline for a tracking number, optionally projected to EPCIS / ONE Record / UN-CEFACT.
Business alliance membership and permissions
Get access logs for an alliance
Get clients whose data the caller may access via alliances
Get the list of alliances for the current user
Get the members of an alliance
Get pending join requests for an alliance
Get alliance and member permissions
Get details of a single alliance
Approve a pending join request
Create a new alliance
Dissolve an alliance (owner only)
Invite a client to an alliance
Leave an alliance
Reject a pending join request
Remove a member from an alliance
Request to join an alliance by code
Transfer alliance ownership to another member (owner only)
Update alliance info (owner/admin only)
Update the caller's member-level permissions in an alliance
Update alliance-level permissions (owner/admin only)
Datasets: groups, records, statistics, validation, webhooks, imports, computed columns
Get audit logs for a dataset
Get column distribution statistics for a dataset
Get geographic statistics for a dataset
Get list of datasets
Get list of groups for a dataset
Get list of records for a group within a dataset
Get change history for a record
Get scheduled imports for a dataset
Get a single dataset by ID
Get a single group within a dataset
Get a single record within a group and dataset
Get statistics for a dataset
Get validation rules for a dataset
Get delivery logs for a webhook
Get webhooks for a dataset
Bulk delete records within a group
Bulk create records within a group
Configure audit settings for a dataset
Create a computed column for a dataset
Create a scheduled import for a dataset
Create a validation rule for a dataset column
Create a webhook for a dataset
Delete a scheduled import from a dataset
Delete a validation rule from a dataset
Delete a webhook from a dataset
Delete a dataset
Delete a group within a dataset
Delete a record within a group
Re-geocode all records in a group
Re-geocode a single record
Manually run a scheduled import now
Search records within a dataset
Create a new dataset
Create a new group within a dataset
Create a new record within a group
Send a test payload to a webhook
Update an existing dataset
Recompute computed columns for a group
Update a group within a dataset
Update a record within a group
Update a scheduled import for a dataset
Update a webhook for a dataset
Validate all records within a group
UA (last-mile confirmation) business API
Get the authenticated client's UA orders
Delete a UA order initialization
Initialize a new UA order
Update an existing UA order
UA (last-mile confirmation) end-user API
Get the authenticated UA user's orders
Add a family phone number to the UA user
Request an SMS code to add a phone number
Request an SMS verification code to log in
Update the authenticated UA user profile
Validate/confirm delivery of a UA order
Verify an SMS code and obtain a UA access token
Points of interest
Get a paginated list of POIs
Get details of a specific POI
Get available POI types with form field definitions
Delete a POI
Get POIs with filtering and distance ranking
Create a new POI (admin)
Submit a new POI
Toggle the status of a POI
Update an existing POI (admin)
Multimodal loading solver with heterogeneous rectangular equipment spaces, optional palletization and optional unload sequencing.
Product catalog
Get a single product with full details including variants, options, and platform links
List products with filtering and pagination
Create a new product
Sync products from an external platform (WooCommerce, Shopify, Magento)
Third-party delivery provider assignment API
Native typed resolver calling PartnerLockerScopeApplicationService directly. Partner Locker operations share a 60-request-per-minute authenticated-user quota with REST and return LOCKER_RATE_LIMITED when exhausted.
The child scope is always intersected with its platform grant. The authenticated-user rate quota is shared with REST.
Native typed update over PartnerLockerScopeApplicationService. The authenticated-user rate quota is shared with REST.
The scope remains available for historical audit but cannot be used for new codes. The authenticated-user rate quota is shared with REST.
Returns masked access codes only, with a default page size of 50 and maximum of 100. Authorized provider users receive pickupCode and settlement counts after delivery. The P6 read model also returns masked webhook delivery state, recipient notification state, and an event timeline without signing secrets, full recipient contacts, or raw error messages. The authenticated-user rate quota is shared with REST.
An authorized active detail may return the complete access code. A delivered detail returns the independent associated-package-group pickup code and confirmed Inventory references. It also exposes masked webhook and recipient-notification state plus the event timeline. Terminal details never expose either code. The authenticated-user rate quota is shared with REST.
The native resolver calls PartnerLockerDeliveryApplicationService directly; idempotencyKey is equivalent to the REST Idempotency-Key header. The authenticated-user rate quota is shared with REST.
Releases held capacity and retains the unified code record. The authenticated-user rate quota is shared with REST.
Opens locker compartments for one of the provider's own access codes at the given location; the platform picks an eligible cabinet there (allocation may span several cabinets at that location). locationId may be omitted when the code was created for exactly one location - it is then inferred. Returns a claimToken for the follow-up confirm/abort call. The native resolver calls PartnerLockerRemoteOpenService directly; the terminal lookup abuse guard applies and the authenticated-user rate quota is shared with REST.
Settles the remote attempt after the driver has placed the packages: creates inventory and marks the delivery delivered. The attempt is identified by claimToken (locationId is an optional consistency check). decision must be confirm_all when every compartment opened, or accept_partial otherwise. The authenticated-user rate quota is shared with REST.
Aborts an in-progress remote attempt. Before any door-open request the delivery is restored for retry; after a door has opened the attempt is flagged for manual attention. The authenticated-user rate quota is shared with REST.
While an attempt is awaiting confirmation, rejects the compartment opened for one package and re-allocates + re-opens another. reason is door_not_open, compartment_occupied, or too_small (which forces a strictly larger compartment). The authenticated-user rate quota is shared with REST.
The courier asserts nothing was deposited; every opened compartment is released and the delivery is terminated as cancelled (emits partner_locker.delivery_cancelled). The authenticated-user rate quota is shared with REST.
Within the correction window (60 seconds by default) after a drop-off is confirmed, reopens the same compartments the parcels were deposited into so the courier can fix a wrong placement. The delivery stays delivered; only door-open commands are re-issued. Identify the delivery by deliveryNo (preferred) or the original accessCode. The same correction is available on the locker screen by re-entering the delivery code. Every correction reopen emits a partner_locker.delivery.correction_reopened webhook event to subscribed endpoints with the reopened compartments in the payload. The authenticated-user rate quota is shared with REST.
Returns the provider's eligible locker locations sorted by distance from a query point so partners can pick a locationId before creating a delivery or opening doors remotely. Provide latitude+longitude or a free-text address (optionally city/province/country/postcode) that the platform geocodes. Optional platformScopeGroupId/partnerScopeGroupId narrow the grants considered; mock=true lists locations by the provider's own mock lockers. The authenticated-user rate quota is shared with REST.
Sandbox tooling: lists virtual locker cabinets with per-compartment door state and occupancy. Mock lockers run through the real delivery pipeline (create with mock: true, remote open, confirm) but never mix with real locker capacity. The authenticated-user rate quota is shared with REST.
Creates a virtual cabinet (shelf + compartments) at an active location for early integration development before real-hardware testing. The returned locker.deviceId is used with the remote open API and the mock door/device controls. Limited per provider.
action: close mimics the driver shutting the door after a deposit (letting door verification settle the compartment); action: open mimics a hardware fault. A door left open blocks the compartment exactly like real hardware.
Offline mock lockers reject door-open commands with DEVICE_OFFLINE and report offline to eligibility checks, letting partners test failure handling.
Removes the virtual cabinet and its compartments. Refused while any compartment still holds inventory or an active allocation.
Get one third-party delivery assignment for the authenticated provider
Get third-party delivery assignments for the authenticated provider
Accept a third-party delivery assignment
Reject a third-party delivery assignment
Submit third-party delivery POD
Submit a third-party delivery status update
OCR parsing of labels, route lists and scan codes
OCR a shipping label image, ZIP archive, or PDF
OCR a route-list screenshot image, ZIP archive, or PDF
Extract barcodes/QR codes from an image, ZIP archive, or PDF
Asynchronous batch processing jobs
GraphQL mutation for /v1/batchprocessing/create
get batch processing result
Device webhooks, print nodes and staff tools
Submit a print job to a SuperPrinter node
Pair a print node using a one-time pairing code or activation code
Submit a smart locker provider webhook payload
Staff: generate the shipping label and stock out storage packages
Staff: mark a shipout order as shipped
Staff: record a payment for a shipout order
Staff: set the price for a shipout order
Ingest a Superbox device event
Get smart locker operator device session details
List carriers available for smart locker operator stock-in
Validate carrier package identifiers for smart locker stock-in
Resolve a carrier package placeholder by pickup code for smart locker stock-in
Suggest an empty smart locker grid for carrier stock-in
Open a smart locker compartment for carrier package placement
Confirm carrier package stock-in after placement
Notify a bound customer that a smart locker carrier package is ready for pickup
Custom Maps Layer API (public/embed + client)
Fetch Layer Envelopes for a public Custom Map. Pass embed_token when map requires it.
Fetch one Layer Envelope by type/key.
Nearest warehouses, POIs, and dataset points for a public map.
Fetch layers for a map owned by the authenticated business.
Webhook configuration and delivery management
Returns the caller's current webhook configuration; the signing secret is always masked to its last 4 characters.
Updates ONLY the submitted keys; unknown keys are rejected and every successful change is audited. Allowed keys: order_status_change_webhook_url, order_create_async_postback_url, order_create_webhook_url, tracking_event_webhook_url, pod_files_webhook_url, order_deleted_webhook_url, order_cancel_failed_webhook_url (URL fields; comma-separate multiple URLs for fan-out; empty string clears), webhook_payload_envelope / order_created_webhook_all_types / webhook_verify_ssl (0 or 1), webhook_sign_secret (16-255 chars).
Standalone warehouse mobile app operations. Native GraphQL resolvers call the same application service as REST.
Authorized warehouses, capabilities, features and device contracts.
Successful routes and route-driver jobs for one warehouse and date.
Grid-ordered packages and progress for one route-driver job.
Package, order and inventory location details.
Capability-scoped package receipt using the same order-status transitions as the web receive page.
Moves one received package to an existing warehouse grid.
Returns route-driver and stop assignment and updates sorting progress.
Audits and removes the package grid inventory record.