Case study API gateway & security

Carrier & Shipping Integration Layer

A centralised, secure API gateway on Azure API Management with OAuth 2.0 that automates carrier integrations, label generation and live tracking — turning a 20-minute manual task into zero clicks.

The problem

Dispatch teams were spending hours creating shipping labels and tracking packages by hand across separate FedEx, DHL and UPS portals. It was a twenty-minute manual process, and it held back shipping SLA compliance.

Architecture

I built a centralised, secure API gateway on Azure API Management, protected with OAuth 2.0, that automates the carrier integrations: label generation goes through the gateway, and tracking updates arrive as live webhooks instead of someone checking each portal.

Dispatch applications call Azure API Management, secured with OAuth 2.0, which routes requests to FedEx, DHL and UPS Dispatch API MgmtOAuth 2.0 FedEx DHL UPS
Simplified architecture. Carrier names are the real integrations; internal routing is omitted.

What the gateway takes care of

  • One entry point for every carrier, so dispatch systems integrate once instead of three times.
  • Authentication with OAuth 2.0 and Azure AD B2C, validated at the gateway before requests reach a carrier.
  • Automated label generation and live tracking via webhooks, replacing manual portal work.

Engineering decisions

A gateway in front of every carrier

API Management centralises cross-cutting concerns — token validation, throttling, versioning and logging — so each carrier integration only contains carrier-specific logic.

Trade-off: the gateway becomes a critical dependency, so its tier, scaling and availability have to be planned like any production service.

OAuth 2.0 tokens instead of shared credentials

Callers authenticate with short-lived tokens validated at the gateway, which keeps carrier API keys out of client applications.

Trade-off: token issuance and app registrations add setup, and expiring tokens must be handled gracefully by every client.

Webhooks for tracking instead of polling

Carriers push status changes as they happen, so tracking stays current without repeatedly querying each carrier.

Trade-off: webhook endpoints must verify senders and cope with retries and duplicate events.

Outcomes

  • A 20-minute manual process reduced to zero clicks.
  • 40+ hours per week of dispatch overhead saved.
  • Significantly improved shipping SLA compliance.

Skills demonstrated

API design and governance with Azure API Management, identity with OAuth 2.0 and Azure AD B2C, and integration of third-party carrier APIs. The same gateway-first pattern appears in my current role at FSP Consulting.

control plane · access granted

You found the control plane.

Everything is healthy. Nothing is on fire. Here is the whole stack in one breath:

Client APIM Functions Logic Apps Data deployed by Bicep + Azure DevOps · secured by Managed Identity

Secret commands also work in the terminal. Try sudo.