Skip to main content
The External API is the machine-to-machine surface of DropHub. There are eleven endpoints. A merchant system authenticates as an OAuth client, creates a shipment from an order reference and two coordinates, and receives signed webhook events as the shipment moves.

Quickstart

Token to delivered shipment in four calls.

Authentication

Client credentials, three scopes, token lifecycle.

Shipments

The minimal create request and what comes back.

Webhooks

One endpoint, seven events, HMAC-SHA256 signatures.

What you send

Everything DropHub needs to move a parcel:

What DropHub derives

You do not model any of the following, and there is no API for configuring them. DropHub resolves each one internally when the shipment is created:
There is no quote step, no branch or pickup directory to read, no carrier to pick, no coverage to configure, and no tracking link to mint. If you are looking for one of those, it is because DropHub already did it.

The whole surface

Conventions

Idempotency and ETags

Your order reference is the retry key. If-Match guards webhook changes.

Errors

RFC 9457 problem details with stable machine codes.
Responses are JSON. Errors are application/problem+json. Timestamps are UTC and ISO 8601. Money is an exact decimal in SAR — never a floating-point number.