GeoVerify Developer Documentation · v0.1
Production: https://geoverifylogisticssoftware.com/api/v1 (requires X-GeoVerify-Key) · Sandbox: https://geoverifylogisticssoftware.com/api (no key, mock telemetry) — routing-agnostic verification for any delivery, dispatch, TMS, or fleet stack.
Three steps to your first verified event:
curl -X POST https://geoverifylogisticssoftware.com/api/v1/event/verify \
-H "Content-Type: application/json" \
-H "X-GeoVerify-Key: gvk_demo_7f3a9c1e55d24b8e6a01" \
-d '{ "event": { "planned_coordinates": { "lat": 32.52, "lng": -92.11 },
"actual_coordinates": { "lat": 32.52005, "lng": -92.11003 },
"planned_eta": "2026-07-14T14:30:00Z",
"timestamp": "2026-07-14T14:31:12Z",
"claimed_event_type": "delivered", "observed_event_type": "delivered",
"telemetry": { "speed_kmh": 0, "accuracy_m": 7 } } }'
# → { "truth_status": "true", "distance_delta_m": 6.1, … }Versioning: production traffic targets /api/v1. The unversioned /api sandbox remains keyless for evaluation and powers the public playground.
Everything GeoVerify returns derives from one formula. An event is TRUE only when all of the following hold:
TRUTH = distance(actual, planned) < max_deviation_radius_meters
AND timestamp within allowed_arrival_window
AND telemetry consistent (score >= threshold)
AND claim matches observed event
AND evidence present and validated
AND geofence rules satisfiedAnything less decomposes into partial or false, with the exact failing signals returned as deltas, flags, and scenario tags. No black boxes — every verdict is reconstructible from the response.
GeoVerify is the truth layer for delivery networks. Your routing engine provides the plan, your driver provides the claim, your devices provide the telemetry — GeoVerify tells you what actually happened. Every event you ingest is evaluated by three deterministic engines (truth, compliance, anomaly) and sealed into an immutable, SHA-256 chained audit trail.
The typical flow: POST /event/ingest → POST /event/verify → retrieve results via GET /event/truth, GET /event/compliance, and GET /event/audit.
Production tenants authenticate with an API key sent in the X-GeoVerify-Key header. Keys are scoped per tenant; every record is tenant-isolated. OAuth2/JWT federation is available on the Enterprise tier.
curl -X POST https://geoverifylogisticssoftware.com/api/v1/event/verify \
-H "Content-Type: application/json" \
-H "X-GeoVerify-Key: gvk_live_…" \
-d '{ "event": { … } }'The sandbox endpoints (/api/*) powering the public playground require no key and run against mock telemetry only. Production endpoints live under /api/v1 and reject requests without a valid key with 401.
The event object is the atomic unit of truth. Coordinates are WGS-84 decimal degrees; timestamps are ISO-8601 UTC.
{
"event_id": "evt_9f31ac02b7",
"route_id": "rt_monroe_4412",
"driver_id": "drv_8834",
"device_id": "dev_px7a_221",
"planned_coordinates": { "lat": 32.5200, "lng": -92.1100 },
"actual_coordinates": { "lat": 32.52005, "lng": -92.11003 },
"planned_eta": "2026-07-14T14:30:00Z",
"timestamp": "2026-07-14T14:31:12Z",
"claimed_event_type": "delivered",
"observed_event_type": "delivered",
"telemetry": {
"speed_kmh": 0, "heading": 212, "accuracy_m": 7, "battery": 68,
"previous_coordinates": { "lat": 32.5089, "lng": -92.1041 },
"previous_timestamp": "2026-07-14T14:24:00Z",
"photo": { "gps_embedded": true, "timestamp": "2026-07-14T14:31:10Z",
"hash": "9f2c1ab7…" }
}
}| Field | Type | Required |
|---|---|---|
| planned_coordinates / actual_coordinates | {lat, lng} | yes |
| timestamp / planned_eta | ISO-8601 UTC | yes |
| claimed_event_type / observed_event_type | string | yes |
| telemetry.speed_kmh / accuracy_m / heading | number | recommended |
| telemetry.photo.{gps_embedded, timestamp, hash} | object | per ruleset |
| route_id / driver_id / device_id | string | recommended |
An event is TRUE when every one of these holds:
truth = distance(actual, planned) < max_deviation_radius_meters (150 m)
AND |timestamp − planned_eta| <= allowed_arrival_window_minutes (10 min)
AND telemetry_score >= telemetry_consistency_threshold (0.80)
AND claimed_event_type == observed_event_type
AND photo metadata validated (GPS + timestamp + hash)
AND geofence rules satisfiedOutput includes truth_status (true / partial / false), distance_delta_m, time_delta_minutes, telemetry_score, claim_consistency_score, and scenario_tags such as late_arrival, off_route, geofence_breach, telemetry_mismatch.
The compliance engine applies regulatory-grade checks: geofence entry/exit (point-in-polygon over your registered polygons), arrival window compliance, proximity validation, route adherence, device-vs-driver claim consistency, and required evidence presence (photo, signature, telemetry).
Output: compliance_flags (e.g. arrival_window_met, geofence_breach), a normalized compliance_score, and human-readable regulatory_notes suitable for audit packets.
| Anomaly | Trigger | Severity |
|---|---|---|
| impossible_travel_speed | speed > 160 km/h at event time | 0.95 |
| location_jump | implied speed between fixes > 160 km/h | 0.90 |
| claim_contradiction | claimed ≠ observed event type | 0.80 |
| gps_drift_suspected | accuracy_m > 100 at event time | 0.60 |
| missing_evidence | required photo metadata absent | 0.40 |
Each anomaly ships with a severity score and a recommended action — quarantine the event, freeze the claim payout, or request re-verification.
Every verification writes an append-only audit record. Records are SHA-256 chained (each signature covers the previous one), timestamped, and exportable — ready to hand to insurers, regulators, and internal audit.
{
"event_id": "evt_9f31ac02b7",
"chain_length": 2,
"records": [{
"seq": 4182,
"signature": "3f9a…c21d",
"previous_signature": "a01b…77e4",
"algorithm": "SHA-256 chain (GV1)",
"reconciliation_log": [
"planned vs actual distance delta: 6.1 m",
"arrival time delta: 1.2 min",
"telemetry consistency score: 1.0",
"compliance score: 1.0 (4 checks)"
],
"immutable": true,
"created_at": "2026-07-14T14:31:13.104Z"
}]
}GET /event/audit/{event_id}/export downloads a signed, self-contained audit packet (JSON attachment) combining the truth evaluation, compliance record, and full chain — with an export_signature and a chain_valid integrity check. Built to hand directly to insurers and regulators.
/event/ingestSend raw delivery events — coordinates, timestamps, route IDs, and driver claims. Returns an ingestion signature. Idempotent per event_id.
POST https://geoverifylogisticssoftware.com/api/v1/event/ingest
{
"event_id": "evt_9f31ac02b7",
"route_id": "rt_monroe_4412",
"driver_id": "drv_8834",
"device_id": "dev_px7a_221",
"planned_coordinates": { "lat": 32.5200, "lng": -92.1100 },
"actual_coordinates": { "lat": 32.52005, "lng": -92.11003 },
"planned_eta": "2026-07-14T14:30:00Z",
"timestamp": "2026-07-14T14:31:12Z",
"claimed_event_type": "delivered",
"observed_event_type": "delivered",
"telemetry": {
"speed_kmh": 0, "heading": 212, "accuracy_m": 7, "battery": 68,
"previous_coordinates": { "lat": 32.5089, "lng": -92.1041 },
"previous_timestamp": "2026-07-14T14:24:00Z",
"photo": { "gps_embedded": true, "timestamp": "2026-07-14T14:31:10Z",
"hash": "9f2c1ab7…" }
}
}{
"event_id": "evt_9f31ac02b7",
"ingested_at": "2026-07-14T14:31:12.8Z",
"signature": "b7c1…9a0e"
}/event/verifyRun truth + compliance + anomaly engines over a single event. Optionally pass a rules object to override tenant defaults. Writes an audit record.
POST https://geoverifylogisticssoftware.com/api/v1/event/verify
{
"event": { …event object… },
"rules": { "max_deviation_radius_meters": 150 }
}{
"event_id": "evt_9f31ac02b7",
"truth_status": "true",
"distance_delta_m": 6.1,
"time_delta_minutes": 1.2,
"telemetry_score": 1.0,
"claim_consistency_score": 1.0,
"scenario_tags": ["clean_delivery"],
"compliance_flags": [
"arrival_window_met", "deviation_radius_ok",
"proximity_validated", "evidence_complete"
],
"compliance_score": 1.0,
"regulatory_notes": [],
"anomaly_tags": [],
"severity_score": 0.0,
"recommended_actions": [],
"audit_signature": "3f9a…c21d",
"audit_seq": 4182,
"evaluated_at": "2026-07-14T14:31:13.104Z"
}/event/verify/batchVerify up to 100 events in a single call. Each event runs the full truth, compliance, and anomaly pipeline and writes its own audit record. Returns per-event packets plus fleet-level tallies.
POST https://geoverifylogisticssoftware.com/api/v1/event/verify/batch
{
"events": [ { …event… }, { …event… } ],
"rules": { "allowed_arrival_window_minutes": 15 }
}{
"total": 100,
"verified_true": 91,
"partial": 6,
"flagged_false": 3,
"results": [ { …verification packet per event… } ]
}/event/truth/{event_id}Retrieve the stored truth evaluation for an event — distance delta, time delta, integrity scores, and scenario tags.
{
"event_id": "evt_9f31ac02b7",
"truth_status": "true",
"distance_delta_m": 6.1,
"time_delta_minutes": 1.2,
"telemetry_score": 1.0,
"claim_consistency_score": 1.0,
"scenario_tags": ["clean_delivery"]
}/event/compliance/{event_id}Retrieve compliance flags, the normalized compliance score, and regulatory notes for an event.
{
"event_id": "evt_9f31ac02b7",
"compliance_flags": ["arrival_window_met", "deviation_radius_ok"],
"compliance_score": 1.0,
"regulatory_notes": []
}/event/audit/{event_id}Pull the immutable, chained audit trail for an event — signatures, reconciliation log, evidence hashes, truth and compliance summaries. Append /export for a signed downloadable packet.
/rules · PUT /rulesRead or update your tenant ruleset — arrival window, deviation radius, proximity threshold, telemetry threshold, and named zones (service_area, depot, no_go) the compliance engine enforces. Editable visually in the Zone Editor (/geofences).
PUT https://geoverifylogisticssoftware.com/api/v1/rules
{
"max_deviation_radius_meters": 150,
"allowed_arrival_window_minutes": 10,
"geofence_polygon": [ { "lat": 32.51, "lng": -92.12 }, … ]
}{
"ok": true,
"tenant_id": "tn_4f2c9a01b3",
"rules": { …merged ruleset… }
}/webhooks/registerRegister an HTTPS endpoint for signed deliveries — choose from event_verified, compliance_failed, anomaly_detected. The signing secret is returned exactly once. GET /webhooks lists subscriptions, DELETE /webhooks/{subscription_id} removes one.
POST https://geoverifylogisticssoftware.com/api/v1/webhooks/register
{
"url": "https://your-system.example/geoverify-hook",
"events": ["anomaly_detected", "compliance_failed"]
}{
"subscription_id": "sub_7a19c2e04d",
"secret": "whsec_… (shown once)",
"events": ["anomaly_detected", "compliance_failed"]
}GeoVerify pushes verification outcomes to your systems the moment they happen. You register an HTTPS endpoint; we call it with a signed payload.
POST https://your-system.example/geoverify-hook
X-GeoVerify-Signature: hmac-sha256=…
X-GeoVerify-Event: event_verified
{
"event_id": "evt_9f31ac02b7",
"truth_status": "true",
"compliance_score": 1.0,
"anomaly_tags": [],
"audit_signature": "3f9a…c21d",
"occurred_at": "2026-07-14T14:31:13.104Z"
}Verify every delivery with the X-GeoVerify-Signature HMAC header — an HMAC-SHA256 of the raw request body using your subscription secret. Rotate secrets anytime via POST /webhooks/{subscription_id}/rotate-secret — signing switches immediately and the previous secret remains acceptable for a 24h grace period, so rotation causes no downtime. Failed deliveries retry automatically with backoff (+10s, +30s, +90s) and every attempt is logged for audit. Registration is live: POST /api/v1/webhooks/register (see Endpoint Reference).