Information
- OpenAPI version:
3.1.1
The tenant-facing API for connecting an ERP or e-commerce system to PickUpper: push orders and the tenant’s own drivers in — courier is the domain name of a driver, so couriers:write and /api/couriers/sync keep your driver list in sync — and read back what PickUpper planned and what happened on delivery.
Authentication. Every operation needs Authorization: ApiKey <key>, where the key was issued in the PickUpper admin app under API keys. A key carries scopes (orders:write, orders:read, trips:read, couriers:write; vehicles:read also exists but is not required by any operation yet); an operation outside the key’s scopes gets 403, a missing or revoked key gets 401.
Identity of an order. Orders are addressed by the externalId your system assigned; pushing the same externalId again updates the order (200) instead of creating a second one (201).
Errors. Failures are RFC 9457 Problem Details (application/problem+json). type carries a stable machine-readable code; 400 validation failures list the offending fields under errors. Every operation is rate-limited per key and answers 429 with a Retry-After header when the limit is exceeded.
Idempotency. Mutating requests may send an Idempotency-Key header; a repeat with the same key within the retention window replays the original response instead of running again.
Conventions. JSON with camelCase members; enums as strings; timestamps as ISO 8601 in UTC (…Z) unless the member name says otherwise; identifiers are UUIDs.
API key sent as: Authorization: ApiKey
Security scheme type: http