Skip to content

Choose your M Express integration ​

Choose the M Express capabilities your application needs; they do not form a required calling sequence. Public Tracking gives your browser-safe UI a current shipment projection. Webhooks keep your backend current without polling. The POD API lets your backend retrieve delivery evidence and proxy approved media.

Open interactive diagram

Integration options: query Tracking for status, receive Webhook events, or query POD for delivery evidence. Select each capability independently.

Read the arrows as request directions, not a timeline. The customer initiates Tracking and POD queries; M Express initiates Webhook delivery to the customer server.

Text equivalent: customer system → Tracking API for current status; M Express Webhooks → customer server for events; customer server → POD API for evidence using pod:read. There is no required order between these capabilities. Responses and media retrieval are described on the corresponding API pages.

Choose the surface for the job ​

You need to…Use this page
Show a safe current status from a tracking numberPublic Tracking
Receive delivery changes and update your own recordsWebhooks
Fetch a shipment POD manifest and proxy photo or signature bytesPOD API
Set the host, credential boundary, fixture, and release checksGet started

Tracking is anonymous and accepts only tracking_number. It never exposes package scan codes, recipient contact or address data, POD media, precise device location, driver identity, or internal operational fields.

Webhooks are server-to-server events from M Express to your server. Verify the unchanged raw body before parsing, persist event_id before side effects, and return a timely normal-sized 2xx before slow work. The pod.bundle_available / EVT430 event carries verified POD media links; your server reads those links with its composite media credential. It may also carry the captured POD completion location when all values are valid. That optional field is omitted when unavailable, including on older events; the shipment POD manifest retains its separate required, nullable location shape.

POD is a server-side authenticated flow. Use the same Bearer token with pod:read for the manifest and each manifest-derived media URL. Never send that token to a browser, URL, HTML document, log, mobile app, or CDN.

Documentation host is not the API host

This site, https://docs.mexpress.nz, serves documentation only. Production requests use https://mexpress.nz/api/v1.

Follow one implementation path ​

  1. Start with Get started and store secrets in your backend.
  2. Add Public Tracking for the customer status view.
  3. Add Webhooks for durable, event-driven updates.
  4. Add POD API when your account needs delivery evidence and media.

The examples use synthetic shipment MX123456789, packages PKG-0001 and PKG-0002, and fixed UTC values. They are documentation fixtures, not customer records.

Next step ​

Use Get started to establish the shared fixture and acceptance checklist.

M Express server-to-server integration guide