Skip to main content
Metrics type: Key MetricsCategory: Shipping & Courier

At a glance

Number of days until the API credential the merchant is using to talk to APC Overnight expires. APC’s integration uses a token (typically API key + secret bound to the merchant account, with rotation cadence agreed at contract signing) and that credential has a finite lifetime. When it ticks past zero, label generation breaks, tracking webhook ingestion stops, and the entire APC integration goes dark.

Calculation

Calculated automatically from your APC Overnight data. See the At a glance summary above for what the metric tracks and the worked example below for a typical reading.

Worked example

A UK luxury jewellery brand selling £450 average-order-value pieces direct-to-consumer, plus a B2B wholesale book of 22 stockists across the UK. APC NextDay-12 is the consumer carrier (signature-required, insurance to £2,500 per parcel); APC Pallet 24 ships replenishment to wholesale accounts. The integration was set up 24 Sep 24 with a 12-month API token. Reading taken at 09:00 GMT on 12 Mar 26.
Five things to notice for this card class:
  1. 191 days is comfortable, but not “set and forget”. APC tokens have rotated underneath merchants without notification before, the silent kind, where APC’s backend regenerates a key for security reasons after a configuration change. Cross-check against apc_api_error_rate. A token that “should” be valid but is throwing 401s has rotated server-side.
  2. The 14-day alert is the prep warning, not the panic warning. Two weeks gives ops time to (a) raise a request through APC’s developer portal or account manager, (b) schedule the rotation outside dispatch peak (avoid Tuesday and Wednesday afternoons), (c) brief the warehouse on a 30-minute label-print pause window.
  3. Brand the 14-day alert as a calendar event. The most reliable rotation pattern is to put a recurring reminder on the operations team’s shared calendar 21 days out and 14 days out. Vortex IQ alerts the dashboard at 14; the calendar reminder ensures someone owns it.
  4. At 7 days remaining, escalate to the APC account manager directly. Self-serve token rotation through APC’s developer portal is reliable but not always fast on a Friday. If <7 days falls over a weekend, do not assume Monday morning is enough lead time.
  5. At 0 days, stop the integration before APC stops it for you. A controlled pause (manifest “do not dispatch via APC until token rotated”) is preferable to mid-afternoon error storms when warehouse-floor staff hit “print label” 50 times before someone reads the error message. Switch to a manual fallback (APC’s web booking portal) for the brief window.

Sibling cards merchants should reference together

This card is paired tightly with the operational-health cluster. Read it next to:

Reconciling against the vendor’s own dashboard

Where to look in APC’s own portal: APC Overnight Customer Portal → log in to My Account → API Credentials (or Developer Portal for self-serve API customers). The portal lists active credentials with their issue date and expiry date. Compare the expiry date displayed there against the value Vortex IQ has cached. For account-managed customers, your APC account manager can confirm the expiry on file. They will also know if APC has scheduled a backend rotation (rare but happens during platform upgrades or security incidents). Why our number may legitimately differ from APC’s portal: Internal identity (within APC): This card has no internal identity, the value is read directly from credential metadata, not derived. The only “reconciliation” is “is the cached expiry the same as APC’s portal expiry”. Cross-connector reconciliation:

Known limitations / merchant FAQs

Why is the alert at 14 days, not 7? Premium UK express merchants cannot afford same-day disruption. APC’s network is structured around tight dispatch cutoffs (last collections at 16:00 to 16:30 in many depots); a token that lapses mid-afternoon means the day’s NextDay-9am parcels miss collection entirely, which means day-2 deliveries on contracts that promised by-9am. 14 days is “have a sensible meeting”; 7 days is “act this week”; 0 days is the fire. Most general-purpose connectors use 7-day; APC justifies the 14-day default. What happens if my token actually expires? Label generation through the API stops returning 200s; warehouse staff see “Cannot create APC consignment” errors on the floor. Tracking webhooks signed by the old token are rejected, so customer tracking pages stop updating in real time (the customer-facing “where is my parcel” experience breaks even on parcels already in the network). Existing in-transit parcels still deliver, the depot scans don’t depend on the merchant’s token. Recovery: rotate token in APC’s portal, paste into Vortex IQ Settings → Connectors → APC Overnight → Reconnect, confirm test label prints. Typical 10 to 45 minutes end-to-end. Can Vortex IQ rotate the APC token automatically for me? No. APC does not yet support OAuth-style refresh-token flows for its standard API. Rotation is a manual generate-then-paste operation through APC’s developer portal or via the account manager. We are tracking when APC adds programmatic rotation; until then, this is a calendar discipline. My token says 191 days but my warehouse is getting 401 errors. What gives? Most likely: APC rotated the credential server-side (security event, account configuration change, or backend platform upgrade). Vortex IQ’s cached expiry is stale. Confirm by checking apc_api_error_rate, if 401s are spiking, the cached expiry is wrong. Reconnect from APC’s developer portal: generate a fresh credential, paste in Vortex IQ Settings, the cached expiry will refresh. Why does APC have multiple credentials and which one does this card track? Some larger APC accounts split credentials between label-generation and tracking-webhook ingestion (separate keys for separation-of-duty). Vortex IQ uses one credential per integration record. If the merchant set up the integration with the label-gen key, this card tracks that key only. The tracking-webhook key would expire silently from this card’s perspective, surfacing only when webhook ingestion fails. Roadmap: dual-credential tracking on the integration model. My APC contract is up for renewal, do I need to plan for token rotation? Yes. Contract renewal frequently triggers credential reset, especially if the rate card or account-manager changes. Brief ops to expect a same-week rotation on contract renewal and add an extra calendar reminder for renewal-month-end. The 14-day alert on this card will catch it but the operational team should know it is coming, not be surprised. What is the difference between this and the OAuth-token cards on other connectors? APC uses static API credentials (key + secret) with a finite contract-managed lifetime, not OAuth refresh tokens. The “expiry” is calendar-based, not refresh-based. Other connectors (Shopify, Google Ads) use OAuth where the access token refreshes silently every hour and the refresh token is what has a multi-month expiry. The cards look the same on the dashboard but the underlying credential model is different; APC has no auto-refresh path. Should I rotate the token before it expires, or wait? Rotate proactively at the 7-day mark, on a Tuesday or Wednesday morning, never on a Friday. APC support response times stretch over weekends and rotation issues caught at 14:00 on a Friday can leave the warehouse without label printing through Monday morning’s dispatch. The 14-day alert is your “schedule the rotation” trigger; do not aim for the deadline.

Tracked live in Vortex IQ Nerve Centre

Days to Token Expiry is one of hundreds of KPI pulses Vortex IQ tracks across APC Overnight and 70+ other ecommerce connectors. Nerve Centre runs the detection layer; Vortex Mind investigates the cause when something moves; Ask Viq lets you interrogate any number in plain English. Start for free or book a demo to see this metric running on your own data.