Skip to content
Skillv1.0.0

flexport-security-basics

Apply Flexport API security best practices including webhook signature verification, API key rotation, and least-privilege access patterns. Trigger: "flexport security", "flexport webhook signature",

by jeremylongshore(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from jeremylongshore/tons-of-skills-marketplace (skills/.curated/flexport-security-basics/SKILL.md). Install upstream with npx skills add jeremylongshore/tons-of-skills-marketplace --skill flexport-security-basics. Copyright stays with the author (MIT).

Flexport Security Basics

Overview

Flexport manages global freight logistics containing shipping manifests, customs declarations, commercial invoices, and supply chain partner data. A breach exposes trade routes, commodity values, importer/exporter identities, and customs brokerage details. Secure API credentials, webhook endpoints, and any pipeline that processes shipment tracking or purchase order data.

Prerequisites

  • A named security owner, scoped secret-manager integration, access-review cadence, and approved destinations for logistics data.
  • Synthetic shipment fixtures and a defined incident/revocation path.

Instructions

  1. Issue least-privilege credentials per environment and integration; never put keys or secrets in source, tickets, shell history, or support bundles.
  2. Verify webhook signatures using raw bodies, record opaque event identifiers only, and enforce idempotency before downstream processing.
  3. Restrict access to shipping, customs, invoice, and partner data; review connected systems and remove access when the business need ends.
  4. Redact diagnostics, encrypt approved exports, and rotate/revoke credentials immediately after suspected exposure.

Output

Maintain a security receipt with access owner, secret reference, approved integration, review date, rotation/revocation outcome, and redacted incident status. Never include data, documents, or keys.

Examples

Use a fictional booking event and scoped staging credential to verify that an invalid signature is rejected, a duplicate is suppressed, and revoking the credential blocks future requests. Keep only the opaque event ID and control outcome in the evidence.

API Key Management

function createFlexportClient(): { apiKey: string; baseUrl: string } {
  const apiKey = process.env.FLEXPORT_API_KEY;
  if (!apiKey) {
    throw new Error("Missing FLEXPORT_API_KEY — store in secrets manager, never in .env in production");
  }
  // Never log the key; log only a hash suffix for debugging
  console.log("Flexport client initialized (key suffix:", apiKey.slice(-4), ")");
  return { apiKey, baseUrl: "https://api.flexport.com/v2" };
}

Webhook Signature Verification

import crypto from "crypto";
import { Request, Response, NextFunction } from "express";

function verifyFlexportWebhook(req: Request, res: Response, next: NextFunction): void {
  const signature = req.headers["x-hub-signature"] as string;
  const secret = process.env.FLEXPORT_WEBHOOK_SECRET!;
  const expected = "sha256=" + crypto.createHmac("sha256", secret).update(req.body).digest("hex");
  if (!signature || !crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected))) {
    res.status(401).send("Invalid signature");
    return;
  }
  next();
}

Input Validation

import { z } from "zod";

const ShipmentQuerySchema = z.object({
  shipment_id: z.string().regex(/^FLEX-\d+$/),
  container_number: z.string().regex(/^[A-Z]{4}\d{7}$/).optional(),
  origin_port: z.string().length(5).optional(),
  destination_port: z.string().length(5).optional(),
  hs_code: z.string().regex(/^\d{6,10}$/).optional(),
});

function validateShipmentQuery(data: unknown) {
  return ShipmentQuerySchema.parse(data);
}

Data Protection

const FLEXPORT_SENSITIVE_FIELDS = ["customs_value", "commercial_invoice", "importer_tax_id", "broker_credentials", "hs_code"];

function redactFlexportLog(record: Record<string, unknown>): Record<string, unknown> {
  const redacted = { ...record };
  for (const field of FLEXPORT_SENSITIVE_FIELDS) {
    if (field in redacted) redacted[field] = "[REDACTED]";
  }
  return redacted;
}

Security Checklist

  • API keys stored in secrets manager, .env files in .gitignore
  • Webhook signatures verified on every inbound request
  • Different keys for dev/staging/prod environments
  • Key rotation scheduled quarterly with dual-key transition
  • Git history scanned for leaked keys
  • HTTPS enforced for all API calls
  • Request/response logging redacts auth headers and customs values
  • Least-privilege access: read-only tokens for dashboards, run tokens for operations

Error Handling

Vulnerability Risk Mitigation
Leaked API key Full shipment and customs data exposure Secrets manager + quarterly rotation
Unverified webhooks Spoofed shipment status updates HMAC-SHA256 signature verification
Customs data in logs Trade compliance violation Field-level redaction pipeline
Overly broad API scope Access to unrelated shipment data Role-scoped tokens per team
Unencrypted commercial invoices Financial data breach TLS 1.2+ in transit, AES at rest

Resources

Next Steps

See flexport-prod-checklist.

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/jeremylongshore-tons-of-skills-marketplace-flexport-secu-90f542/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

jeremylongshore-tons-of-skills-marketplace-flexport-secu-90f542.ocm.jsonjson
{
  "ocm": "1",
  "id": "jeremylongshore-tons-of-skills-marketplace-flexport-secu-90f542",
  "kind": "skill",
  "name": "flexport-security-basics",
  "description": "Apply Flexport API security best practices including webhook signature verification, API key rotation, and least-privilege access patterns. Trigger: \"flexport security\", \"flexport webhook signature\", \"secure flexport API key\".",
  "publisher": "jeremylongshore",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "coding"
    ],
    "tags": [
      "skill-md",
      "saas",
      "logistics",
      "flexport",
      "skills-sh"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Apply Flexport API security best practices including webhook signature verification, API key rotation, and least-privilege access patterns. Trigger: \"flexport security\", \"flexport webhook signature\", \"secure flexport API key\"."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "skills.sh",
      "repository": "https://github.com/jeremylongshore/tons-of-skills-marketplace",
      "path": "skills/.curated/flexport-security-basics/SKILL.md",
      "ref": "HEAD",
      "url": "https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/HEAD/skills/.curated/flexport-security-basics/SKILL.md",
      "key": "jeremylongshore/tons-of-skills-marketplace/skills/.curated/flexport-security-basics/SKILL.md"
    },
    "compatibility": "Designed for Claude Code",
    "allowed_tools": [
      "Read,",
      "Write,",
      "Grep"
    ],
    "license": "MIT"
  },
  "instructions": "# Flexport Security Basics\n\n## Overview\n\nFlexport manages global freight logistics containing shipping manifests, customs declarations, commercial invoices, and supply chain partner data. A breach exposes trade routes, commodity values, importer/exporter identities, and customs brokerage details. Secure API credentials, webhook endpoints, and any pipeline that processes shipment tracking or purchase order data.\n\n## Prerequisites\n\n- A named security owner, scoped secret-manager integration, access-review cadence, and approved destinations for logistics data.\n- Synthetic shipment fixtures and a ",
  "cost": {
    "context_tokens": 1238
  }
}

Fetch it by URL: GET /api/v1/registry/jeremylongshore-tons-of-skills-marketplace-flexport-secu-90f542/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.