Simple data model
Shipment identity, status, estimate, references, destination context, and recorded events stay separate and explicit.
Create accurate shipment records, keep status changes source-backed, and give customers a stable public view.
Shipment identity, status, estimate, references, destination context, and recorded events stay separate and explicit.
Business records are created and updated by signed-in users or trusted server integrations, never by anonymous public clients.
The customer lookup path returns a deliberately reduced shipment view and excludes private operational fields.
A shipment record should represent information your operation actually knows. Create the record when a shipment exists, add a delivery estimate only when one is available, and change status when the source confirms a new operational state.
{
"order_reference": "ORDER-123",
"carrier": "Carrier name",
"tracking_number": "Carrier or internal reference",
"status": "created",
"estimated_delivery_at": "2026-10-08T18:00:00Z"
}The current application recognizes created, processing, shipped, in_transit, out_for_delivery, delivered, exception, and cancelled. Use the narrowest state supported by the underlying operation. Do not advance a shipment because an expected date passed.
Customer lookup accepts a shipment identifier, or supported order details when the source requires an order and checkout email match. The response is designed for a public tracking page, not as a full order or customer API.
POST https://hhgjtpdbccaqthtjykoc.supabase.co/functions/v1/shipment-lookup
Authorization: Bearer {public_lookup_anon_jwt}
apikey: {public_lookup_anon_jwt}
Content-Type: application/json
{ "identifier": "SL-your-tracking-reference" }
// Or, for supported order lookup
{ "orderNumber": "ORDER-123", "email": "checkout-email" }Direct anonymous access to private shipment tables is disabled. A public lookup credential identifies the application but does not grant privileged business access.
The business console uses the Supabase Data API with the signed-in user's access token. Row-level security limits reads and writes to records owned by that account. Privileged service credentials should remain on trusted server infrastructure.
POST https://hhgjtpdbccaqthtjykoc.supabase.co/rest/v1/shipments
apikey: {project_publishable_key}
Authorization: Bearer {signed_in_user_access_token}
Content-Type: application/json
Prefer: return=representation
{
"order_reference": "ORDER-123",
"carrier": "Carrier name",
"status": "created"
}If a new event has not been committed, keep the previous timeline intact.
When your system receives a verified shipment change, publish that change once and preserve its timestamp.
If a connected source is unavailable, surface the failure instead of claiming the shipment does not exist.
Treat a public shipment link like any other customer-facing fulfillment link. It should not contain customer email, payment information, reusable credentials, or internal notes. Send it only to intended recipients and rotate private integration credentials independently of public shipment identifiers.