Trust is part of the contract
Public guidance explains the shared control model. Customer-specific endpoints, entitlements, credentials, and verification details are provided through the approved onboarding channel.
Access is agreed for your integration
Production shipment creation requires an approved APIM subscription key. Confirm permitted shipment scope and identifier mappings with EDRAY; use only the shipper IDs approved for your integration.
Test validation and production activation require separate approval. Store secrets in an approved secret manager, restrict access, and rotate them through the managed onboarding process.
Public security principles
- APIM subscription
- Production shipment creation requires an APIM subscription key. Keep credentials in your server-side integration.
- Request records and recovery
- Retain request time, shipment references, HTTP status, and response details for support. Confirm retry and duplicate-handling behavior during onboarding.
- Integration-specific delivery
- Agree on milestone fields, delivery method, and authentication during onboarding.
- Private-preview access
- Use the HTTPS APIM endpoint and access details provided for your approved integration. Production access is managed with EDRAY.
Trust boundary
- Client systemAPIM subscription key and approved shipment identifiers
- APIM security boundarySubscription required for production shipment creation
- EDRAY processingRetain request references and response details for support
- Integration-specific milestone deliveryAgree on delivery authentication and verification during onboarding
Operate for recovery
Keep request time, shipment references, and response details with your submission records, excluding credentials. Confirm retry and duplicate-handling behavior before resubmitting a request.
Delivery authentication, verification, and replay handling depend on the integration. Agree on these controls and the support path for post-acceptance failures during onboarding.
