.png)
UPS Integration Guide
Connect enterprise order, warehouse, and customer-service systems with UPS REST APIs, tracking notifications, shipping operations, and OAuth 2.0.
UPS integration options at a glance
UPS provides current REST APIs for shipping and label generation, tracking, rating, address validation, time-in-transit estimates, pickup operations, and related services. Applications generally authenticate with OAuth 2.0, while older implementations may use legacy access-key credentials. UPS also supports webhook-style tracking notifications for selected events and use cases, with scheduled Tracking API requests available where webhook coverage is incomplete. Labels and shipping documents can be returned through applicable APIs. Martini can consume these APIs, receive supported notifications, secure credentials in environment-specific secrets, transform UPS JSON and document payloads, and orchestrate retries, reconciliation, and downstream updates.
Common UPS integration patterns
Common UPS data objects used in integrations
Authentication and security considerations
OAuth 2.0 and secrets
Current UPS APIs generally use OAuth 2.0 access tokens obtained through a registered UPS Developer Portal application. Store client credentials, account numbers, token configuration, and environment-specific settings in Martini secrets and configuration rather than workflow payloads.
Environment and account controls
- Separate UPS test and production configuration.
- Restrict access to client secrets and account-specific settings.
- Confirm permissions, country availability, and account authorization for each UPS service.
- Treat legacy access-key credentials as sensitive and transitional where they remain necessary.
Webhook protection
Validate the documented authentication or validation mechanism for UPS webhook-style notifications, correlate requests to known shipments, prevent replay or duplicate processing where applicable, and acknowledge quickly before longer downstream processing.
Operational considerations for UPS integrations
Rate limits and retries
Check UPS quotas and traffic policies for the relevant application and account. Apply controlled backoff for throttling and temporary service failures, while returning validation and authorization errors for correction instead of retrying them indefinitely.
Idempotency and shipment safety
Shipment creation is operationally sensitive because a lost response can hide a successful request. Persist order, fulfillment, or shipment keys with UPS identifiers before allowing a retry, and distinguish duplicate requests from transient failures.
Data and schema handling
- Handle nested collections and multiple rates or packages without assuming the first result is correct.
- Validate addresses, country codes, dimensions, weight, service, billing, and customs data before shipment creation.
- Preserve label binary content and its media type rather than treating it as ordinary JSON.
- Apply timestamp and status-ordering rules to repeated or out-of-order tracking events.
- Version mappings for API changes, service codes, enumerations, and regional differences.
Testing and monitoring
Test test-environment credentials, regional service availability, label formats, duplicate scenarios, timeout behavior, and webhook coverage before production rollout. Monitor workflow logs, API failures, reconciliation gaps, and documents that cannot be delivered to target systems.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond point-to-point calls
Martini centralizes UPS API calls, webhook intake, scheduled reconciliation, validation, transformations, downstream updates, and exception handling in maintainable workflows rather than scattering logic across scripts and applications.
Stable enterprise contracts
Martini can expose an internal API façade that shields consuming systems from UPS-specific payloads, OAuth details, service codes, document formats, and legacy SOAP dependencies.
Operational reliability
- Apply reusable mappings, business rules, idempotency checks, and controlled retries.
- Combine selected UPS notifications with scheduled polling when event coverage is incomplete.
- Separate business validation errors from transient provider failures.
- Keep credentials and regional configuration outside deployed workflow logic.