DropHub publishes two deployments. They share one contract and share nothing else — data, credentials, and webhook secrets are separate.
A production credential is never valid against the sandbox, and a sandbox credential is never valid against production. Keep them in separate secret stores so one cannot be reached from the other’s configuration.
Prerequisites
Before your first call you need exactly two things:
- A merchant account on the environment you are calling.
- An API credential for it — a
client_id and client_secret, issued from the DropHub console.
That is the whole list. There are no branch codes, pickup-location codes, coverage zones, carrier accounts, or price lists to set up first.
Every request
Writes also send Content-Type: application/json.
Accept-Language is optional and selects a localized representation where one exists. Machine error codes never change with language; only human-readable text does.
GET /v2/public/tracking/{code} is the one endpoint with no Authorization header — it is the link your customer opens. Everything under /v2/external requires a bearer token.