Zipypost

Zipypost is an Indian multi-courier aggregator whose live API gateway demands authorization, sellerid and timestamp headers but publishes no documentation.

Zipypost, operated by Zipypost Tech Private Limited, is an Indian e-commerce shipping aggregator: one seller panel over about fifteen courier partners, with rate comparison, bulk label and manifest generation, tracking, weight dispute handling and COD remittance. For a seller it is a carrier layer, not a sales channel, so the objects that matter are rates and pincode serviceability, shipment creation with an AWB and label, pickup, tracking events, NDR, RTO and COD remittance. There is no public developer portal. What can be verified from outside is that a working API host exists and that it expects a specific set of headers, which is recorded below.

At a glance

What it is

A shipping aggregator in the Shiprocket and NimbusPost mould, pan-India, aimed at D2C sellers and small marketplaces sellers, with a B2B and enterprise line and a warehousing and fulfilment line alongside. The homepage claims 15 plus courier partners and all-India coverage. The carrier list published at zipypost.com/courier-carrier-integrations/ names Delhivery, Blue Dart, XpressBees, Ekart, DTDC, Amazon Shipping, Shadowfax, Blitz, India Post and DP World, with Delhivery's reach quoted as 18,700 plus pincodes.

Panel features advertised on 2026-09-22 are courier rate comparison, what the site calls AI-powered courier allocation, bulk label generation and manifest download, real-time tracking with SMS, WhatsApp and email updates to the buyer, COD remittance in three to seven days, weight dispute protection with automated verification, performance analytics, a branded tracking page and abandoned cart recovery. Store integrations named are Shopify, WooCommerce, Amazon, Flipkart and custom stores, with automatic order sync.

It is a small, recent operator. Treat the claimed numbers as marketing until a contract is in place.

API access

No documentation is published. There is no /developers, /api or /docs page on the marketing site, no SDK, no Postman collection and no GitHub presence found. The route to credentials is a seller account plus a conversation with support, using the contact form at zipypost.com/contact-us/.

The public surfaces are:

What the live API host tells us

Every path tried on https://api.zipypost.com, including /, /api, /v1, /api/v1, /health, /docs, /swagger, /swagger.json, /openapi.json and /redoc, returns the same response on 2026-09-22:

{
  "success": false,
  "message": "Required keys are not provided.",
  "error": {
    "authorization": "authorization not found.",
    "sellerid": "sellerid not found.",
    "timestamp": "timestamp not found."
  }
}

The response headers are HTTP/1.1 400 Bad Request, Server: nginx/1.18.0 (Ubuntu), X-Powered-By: Express, Content-Type: application/json; charset=utf-8.

Three things follow, and only three. First, a real JSON API exists and is reachable. Second, a header check runs in front of routing, so no route discovery is possible unauthenticated and no OpenAPI document is exposed. Third, the credential model involves a seller identifier separate from the authorization value, and a timestamp, which almost always means either replay protection or a signature computed over the timestamp. None of that is a documented contract and none of it tells you the value formats.

Warning

Those three header names are observed from an unauthenticated error response, not read from documentation. Do not treat them as a specification. Ask Zipypost for the integration document before writing a client, and expect the header semantics, in particular whether authorization is a bearer token or a computed signature, to be settled in that conversation.

Authentication

Not documented. The gateway requires authorization, sellerid and timestamp on every request. No token endpoint, lifetime, refresh mechanism, scope model or signature algorithm is published, and no multi-account pattern is described. A credential store design should assume, provisionally, a long-lived per-seller key plus a seller id, and should leave room for a per-request signature over the timestamp.

No authenticated call can be shown here, because no authenticated call has been made and guessing credentials against someone else's production host is not acceptable practice.

Objects we can read

Orders

Not applicable as a source of truth. Zipypost pulls orders in from Shopify, WooCommerce, Amazon, Flipkart and custom stores so a seller can ship them, but the order originates in the sales channel and should be read from that channel's connector.

Order items

Not applicable, same reason.

Products and listings

Not applicable. Zipypost holds no catalogue.

Inventory

Not applicable in the aggregator product. A separate warehousing and fulfilment line exists at zipypost.com/warehouse-fulfilment-solutions/, which would imply stock at Zipypost operated locations, but nothing describes a stock interface.

Shipments and tracking

The core object. The panel provides AWB allocation on booking, label and manifest download, and live tracking across the ten carriers, with buyer notifications over SMS, WhatsApp and email. A public branded tracking page runs at track.zipypost.com.

Endpoint, parameters, pagination and field names are not published. Sample response not published.

Returns and cancellations

Returns are listed as handled in the panel alongside labels and manifests. RTO reduction is a marketing theme. No interface detail is published.

Proof of delivery and NDR

Neither is described in public material in interface terms. Weight dispute handling with automated verification is advertised, which implies a dispute object exists in the panel. Nothing is documented.

Payments and settlements

COD remittance in three to seven days is advertised on the homepage, read 2026-09-22. That makes Zipypost a partial source of settlements for COD orders. No remittance report format or endpoint is published.

Customers

Consignee name, address and phone travel on every shipment and are PII. Not exposed publicly.

Locations

Pickup addresses are configured in the panel. No public interface.

Writing back: listings, price and stock

Not applicable, this is a carrier and aggregator. There is no catalogue, no price and no stock to write.

The write path is the shipment lifecycle: create a shipment against a chosen courier and receive an AWB, fetch the label, generate the manifest, schedule the pickup, and cancel the shipment before handover. All of that exists in the panel, including bulk label generation and manifest download. None of it is documented as an interface, and the API host refuses every request without credentials, so no endpoint, request body or batch size can be stated here without inventing it.

Webhooks and notifications

No seller-facing webhook mechanism is published. The notifications Zipypost advertises are buyer-facing messages over SMS, WhatsApp and email, plus the branded tracking page, which do not help a data pipeline.

Until a contract says otherwise, assume polling. For a multi-carrier aggregator of this size a reasonable cadence is every 30 minutes for shipments in transit and every 6 hours for anything terminal, with a daily sweep for COD remittance. Confirm that against whatever rate limit Zipypost states before running it.

Rate limits and pagination

Not published. No quota header was returned by the gateway on any unauthenticated request. Nothing on the site states a limit or a page size.

Mapping to the unified model

Only shipments, returns and part of settlements apply. Platform field names are unknown, so the right column records the concept rather than a name.

Gaps and open questions

  • The entire interface contract is unknown: routes, request bodies, response field names, status vocabulary, error codes, limits.
  • Whether authorization carries a static key or a signature computed over timestamp is the single most important open question, because it decides the shape of the credential store.
  • No sandbox is mentioned. Assume integration testing happens against live shipments unless told otherwise.
  • Whether Zipypost exposes COD remittance as a report, a statement download or an endpoint is unknown, and it matters for settlements.
  • Zipypost does not appear in the ClickPost carrier directory or in Unicommerce's integration list, so there is no third-party description of its interface to cross-check against.
  • Company scale is unverified. No funding, volume or seller count figure was found from a source independent of Zipypost's own marketing.

Sources

  • Zipypost homepage, read 2026-09-22, for the company name, feature list, COD remittance window and channel integrations
  • Zipypost courier and carrier integrations, for the ten named courier partners
  • Zipypost sales channels, which describes multi-channel selling but no integration mechanism
  • Zipypost pricing
  • Live unauthenticated HTTP checks against https://api.zipypost.com across thirteen paths, https://app.zipypost.com and https://track.zipypost.com, run 2026-09-22, for the required header names and the server stack