The Live Shipping Rates service is currently supported for the following API2Cart's integrations: .
Please note that depending on the platform, the structure of the request and the expected response will be slightly different, as some platforms may support more fields. That is why we strongly recommend that you familiarize yourself with the structure of the callback request and the response we expect using the Swagger-based documentation below.
To manage "Live Shipping Service" you can use the following API methods:
On WooCommerce stores there can be an unlimited amount of services, but on Shopify you can create only one service (Shopify limit).
To create the service you’ll have to specify the name of the service and callback url, that will return us shipping rates. We validate the callback when it is being created by sending test request to it. Test requests contain header X-Shipping-Service-Test-Request: 1.
To check it the request was really sent by API2Cart, compare header signature X-Shipping-Service-Signature
The signature is built based on all headers that start with X-Shipping-Service, except for X-Shipping-Service-Signature.
Video tutorial:
The algorithm:
Create array of headers, let the header name be its key, its value - the header value string. Sort the headers by the name.
Create the string for signature, that is made of headers.For that, encode the array of headers in JSON and concatenate from request body.
Calculate sha256 signature in binary format by using store key as a signing key.
When we send a certain amount of packages, we expect to get the same amount of packages_rates objects. The property rates can be empty,
which means there can be no rates for a certain package.
If the structure is not valid, we return an error.For example, you will get error when you pass a string in total_cost.
expand source
{
"return_code": 109,
"return_message": "Bad Response. Field \"rates->0->total_cost\" has wrong type. It must be decimal",
"result": {}
}
If the callback returns 404 error code,we will not try again
If the callback returns 200 error code, we will check response validity and then return it to the store in the format that fits the store.
If the store returns 200 error code, butwith empty or incorrect response, we will wait 2 seconds and will try again.
If the callback don’t respond in 15 seconds, we will throw an error and will not try again.
expand source
{
"return_code": 109,
"return_message": "Callback http://www.stores.local/rates.php did not respond within 15 sec",
"result": {}
}
If everything is ok, the new service will be created.
2) As the store requests rates, we unify the request and send it to callback specified when the service was created. Also, we send
X-Shipping-Service-Id
header.
If the response is not valid or the callback didn’t answer, we will log the error and increment error count of the shipping service by 1.If the next request will be successful, the count will be reduced to zero.Soon we will add the functionality that will turn off the service when the error limit is exceeded.
Cookie Consent
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Contains information related to marketing campaigns of the user. These are shared with Google AdWords / Google Ads when the Google Ads and Google Analytics accounts are linked together.
90 days
__utma
ID used to identify users and sessions
2 years after last activity
__utmt
Used to monitor number of Google Analytics server requests
10 minutes
__utmb
Used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server.
30 minutes after last activity
__utmc
Used only with old Urchin versions of Google Analytics and not with GA.js. Was used to distinguish between new sessions and visits at the end of a session.
End of session (browser)
__utmz
Contains information about the traffic source or campaign that directed user to the website. The cookie is set when the GA.js javascript is loaded and updated when data is sent to the Google Anaytics server
6 months after last activity
__utmv
Contains custom information set by the web developer via the _setCustomVar method in Google Analytics. This cookie is updated every time new data is sent to the Google Analytics server.
2 years after last activity
__utmx
Used to determine whether a user is included in an A / B or Multivariate test.
18 months
_ga
ID used to identify users
2 years
_gali
Used by Google Analytics to determine which links on a page are being clicked
30 seconds
_ga_
ID used to identify users
2 years
_gid
ID used to identify users for 24 hours after last activity
24 hours
_gat
Used to monitor number of Google Analytics server requests when using Google Tag Manager
1 minute
Marketing cookies are used to follow visitors to websites. The intention is to show ads that are relevant and engaging to the individual user.
Facebook Pixel is a web analytics service that tracks and reports website traffic.
This is used for CSRF prevention - preventing third party websites from accessing your data. Expires after a year.
1 year
__hs_do_not_track
This cookie can be set to prevent the tracking code from sending any information to HubSpot.
13 months
__hs_cookie_cat_pref
This cookie is used to record the categories a visitor consented to.
6 months
__hs_initial_opt_in
This cookie is used to prevent the banner from always displaying when visitors are browsing in strict mode.
7 days
__hs_gpc_banner_dismiss
This cookie is used when the Global Privacy Control banner is dismissed.
180 days
hs_ab_test
This cookie is used to consistently serve visitors the same version of an A/B test page they’ve seen before.
session
__hs_notify_banner_dismiss
This cookie is used when the website uses a Notify consent banner type.
180 days
hs-messages-is-open
This cookie is used to determine and save whether the chat widget is open for future visits.
30 minutes
hs-messages-hide-welcome-message
This cookie is used to prevent the chat widget welcome message from appearing again for one day after it is dismissed.
1 day
__hsmem
This cookie is set when visitors log in to a HubSpot-hosted site.
1 year
hs-membership-csrf
This cookie is used to ensure that content membership logins cannot be forged.
session
hs_langswitcher_choice
This cookie is used to save the visitor's selected language choice when viewing pages in multiple languages.
2 years
__hstc
The main cookie for tracking visitors.
13 months
hubspotutk
This cookie keeps track of a visitor's identity. It is passed to HubSpot on form submission and used when deduplicating contacts.
13 months
__hssc
This cookie keeps track of sessions.
30 minutes
__hssrc
Whenever HubSpot changes the session cookie, this cookie is also set to determine if the visitor has restarted their browser.
session
messagesUtk
This cookie is used to recognize visitors who chat with you via the chatflows tool. If the visitor leaves your site before they're added as a contact, they will have this cookie associated with their browser.
13 months
hubspotapi
This cookie allows the user to access the app with the correct permissions.
7 days
hubspotapi-prefs
This is used with the hubspotapi cookie to remember whether the user checked the 'remember me' box (controls the expiration of the main cookie's authentication).
1 Year
__hs_opt_out
This cookie is used by the opt-in privacy policy to remember not to ask the visitor to accept cookies again.
13 months
LinkedIn Insight is a web analytics service that tracks and reports website traffic.
Registers a unique ID on mobile devices to enable tracking based on geographical GPS location.
1 day
VISITOR_INFO1_LIVE
Tries to estimate the users' bandwidth on pages with integrated YouTube videos. Also used for marketing
179 days
PREF
This cookie stores your preferences and other information, in particular preferred language, how many search results you wish to be shown on your page, and whether or not you wish to have Google’s SafeSearch filter turned on.
10 years from set/ update
YSC
Registers a unique ID to keep statistics of what videos from YouTube the user has seen.
Session
DEVICE_INFO
Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website.
179 days
LOGIN_INFO
This cookie is used to play YouTube videos embedded on the website.
2 years
VISITOR_PRIVACY_METADATA
Youtube visitor privacy metadata cookie
180 days
You can find more information in our Cookie Policy and .
Discover how API2Cart can ease your eCommerce integrations with a personalized demo. See how seamlessly our solution can connect your software with over 70 eCommerce platforms.
Don't miss out! This is an exclusive one-time offer. Secure your additional trial period by booking your demo now.