Home / APIs and microservices / Use case: partner APIs
Illustrative scenario

Opening shipment-tracking APIs to 40 partners

How we would help a logistics company replace file transfers and one-off integrations with a single, secure set of APIs for its retail and marketplace partners.

This is a composite example built from common enterprise requirements. It is not a specific client engagement, and the figures are design targets for the scenario, not measured results.

Partners~40
TodayFiles and custom links
TargetOne API, one portal
Key riskOne partner seeing another's data
The situation

Forty partners, forty integrations

Each retail or marketplace partner had its own integration: some received hourly CSV files over SFTP, some called an old SOAP service, two had direct database access. Adding a partner took weeks. A missed file meant customers saw stale tracking.

The approach

What we would do

  1. One contract: a tracking API and a webhook for status changes, designed with three friendly partners and written in OpenAPI.
  2. Gateway and portal: partner sign-up, keys, sandbox and documentation in one place.
  3. Events behind the API: status changes published once, delivered to partner webhooks with retries.
  4. Strict object checks: every request verifies that the shipment belongs to the calling partner.
  5. Migrate partners in batches, keeping the old file feeds running until each partner is live.
  6. Retire direct database access first, because it is the highest risk.
What changes

Targets and how they are checked

MeasureTargetChecked by
Time to onboard a partnerDays instead of weeksOnboarding records
Tracking freshnessMinutes instead of hoursEvent delivery metrics
Partners seeing others' dataNeverAutomated authorisation tests on every release
Trade-offs

What we would flag

  • Partners move at their own pace. Old feeds may need to run for months.
  • Webhooks need care. Partners' endpoints go down; retries and a replay option are essential.
  • Versioning discipline matters from day one, because forty partners will depend on the contract.

Untangling integrations, or opening APIs to partners?

Tell us which systems need to talk, who will call your APIs, and what breaks today. We will come back with a plain view of the right structure, what to change first, and what to leave alone.