Documentation, status and answers.
Technical material for evaluators: what the API looks like, which integrations exist or are planned, how status reporting would be presented, and the questions we are asked most.
Validated JSON endpoints, session-authenticated.
The sandbox exposes the same endpoints the console uses. Writes require a CSRF token and a same-origin request. Public API keys and versioned documentation are planned for early-access customers.
curl -s https://api.example.com/api/shipments \
-G --data-urlencode "status=delayed" \
-H "Cookie: qf_session=…"{
"items": [{
"ref": "QF-24777",
"lane": "Shanghai → Hamburg",
"status": "delayed",
"temp": { "last": -0.4, "min": -22, "max": -18 },
"risk": 82
}],
"total": 3
}| Endpoint | Method | Minimum role |
|---|---|---|
| /api/shipments | GET | viewer |
| /api/shipments | POST | planner |
| /api/shipments/{id} | GET, PATCH | viewer, planner |
| /api/shipments/{id} | DELETE | manager |
| /api/approvals/{id} | POST | manager |
| /api/audit | GET | manager |
| /api/health | GET | public |
What exists, and what is planned.
Only the REST API and CSV export are available. Everything else is a roadmap item that we will scope with early-access customers; no partnerships are implied.
Uptime reporting, as it would appear.
Quayfold is a sandbox, so this panel illustrates the layout of a status page using generated sample data. It is not a live monitor and not a service-level commitment.
Is Quayfold a shipping product I can buy today?
Not yet. It is a product concept in early access, running here as a sandbox against fictional data so you can evaluate the workflows, permissions and audit behaviour.
Which security certifications do you hold?
None. We describe the controls that are implemented in the code and those that are planned, and we do not claim SOC 2, ISO 27001 or any other attestation.
Where does the temperature data come from?
In the sandbox, readings are simulated. In a deployment they would be ingested from logger and telematics feeds, which are listed as planned integrations.
Can we run it on our own infrastructure?
The reference build is a Node service with an embedded database and a Docker image. Production tenancy on PostgreSQL is on the roadmap.
How are approvals and the audit trail protected?
The API refuses a requester approving their own request, and every state change appends an audit entry that commits to the hash of the one before it.
How do we get access?
Use Contact sales or join the early-access list. We are onboarding a small number of forwarders, shippers and 3PLs.
Recent changes.
Great-circle routes on a dotted world map with a live day and night terminator.
Six-probe temperature drawing on the shipment page with in-range and out-of-range states.
One action in the console recomputes the chain and reports the first break, if any.