Agent skill

Yalidine Delivery Integration

by bighadj22 in bighadj22/codflow

Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks.

Apache-2.0Auto-check passedBackend & APIs

Install Yalidine Delivery Integration

skills CLI
$ npx skills add bighadj22/codflow --skill yalidine-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bighadj22/codflow yalidine-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bighadj22/codflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/yalidine-integration-skill-main/yalidine-integration .claude/skills/yalidine-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
yalidine-integration
GitHub stars
350
Token cost
~2.5k tokens
SKILL.md length
1,252 words
Files
8 (incl. scripts, references, assets)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks.

  • Works in 6 steps: Confirm the user has generated… → Set up configuration, not hardcoded values → Build the API client layer first using → …
  • Adding Yalidine or Guepex shipping to an e-commerce app
  • SKILL.md covers Before you write any code, The integration workflow, Non-negotiable security rules and Key domain gotchas (read…, plus 3 more sections
  • Runs TypeScript scripts from its folder; calls curl; reaches api.guepex.app; needs YALIDINE_API_TOKEN and YALIDINE_WEBHOOK_SECRET

What it does

This skill gives a coding agent what it needs to connect a platform to Yalidine, which also operates under the Guepex brand, without ever seeing the user's real credentials. It covers creating and tracking parcels, looking up wilayas, communes and stop-desk centers, calculating delivery fees and reacting to delivery-status changes through webhooks, including cash-on-delivery parcel creation and home or stop-desk delivery.

The agent reads only the reference file that fits the task: an API reference for every REST endpoint, a webhooks reference for event types, CRC challenge validation, HMAC signature verification and retry policy, a human-only-steps file for dashboard actions that only the account owner can take, and a troubleshooting file. Two TypeScript implementations are bundled, a dependency-free typed API client with pagination and rate-limit handling and a Supabase Edge Function webhook handler that can be adapted to Express or Next.js, plus an .env.example. The API ID, token and webhook secret must come from the user's own dashboards.

When your agent uses it

  • Adding Yalidine or Guepex shipping to an e-commerce app
  • Creating and tracking cash-on-delivery parcels
  • Calculating delivery fees for a wilaya or commune
  • Receiving and verifying delivery-status webhooks
  • Debugging failed Yalidine calls or rejected webhook signatures

Example prompts

  • “Add Yalidine parcel creation to our checkout, with cash on delivery.”
  • “Hook up delivery-status webhooks and verify their signatures.”
  • “Calculate the delivery fee from Algiers to Oran for a small parcel.”
  • “My Yalidine webhook signature check rejects real deliveries, so find out why.”

Requirements

  • A Yalidine (Guepex) account with an API ID, API token and webhook secret key

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the user has generated credentials. You cannot get an API ID,
  2. Set up configuration, not hardcoded values
  3. Build the API client layer first using
  4. Cache static lookup data. Wilayas, communes, and centers change
  5. Build the webhook endpoint last, once parcel creation works, using
  6. Tell the user what to do in the dashboard once your code is ready —

What it can do on your machine

Read from SKILL.md and the folder at commit ed79aa9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.guepex.app

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • YALIDINE_API_TOKEN
    • YALIDINE_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Yalidine Delivery Integration loads about 2.5k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 1,252 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from bighadj22/codflow at commit ed79aa9, republished under its Apache-2.0 licence (© bighadj22). 1,252 words, ~2,516 tokens.

Download SKILL.mdSave it as .claude/skills/yalidine-integration/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
yalidine-integration
description
Integrate the Yalidine (Guepex) Algerian delivery/courier API and webhooks into any codebase — creating and tracking parcels, looking up wilayas/communes/stop-desk centers, calculating delivery fees, and receiving real-time delivery-status webhooks. Use this whenever the user asks to integrate Yalidine, Guepex, or an Algerian shipping/courier API, add cash-on-delivery parcel creation, stop-desk/home delivery, parcel tracking, or delivery-status webhooks to their app — even if they just say "add Yalidine" or "hook up shipping" without more detail.

Yalidine (Guepex) Delivery Integration

Yalidine is Algeria's largest courier network. Its API is exposed under the brand name Guepex (base URL api.guepex.app, dashboard guepex.app) — same company, same API, same webhooks. Treat "Yalidine" and "Guepex" as the same integration.

This skill gives a coding agent everything needed to wire a platform up to Yalidine end-to-end: creating parcels, looking up delivery zones, calculating fees, and reacting to delivery-status changes via webhooks — without ever needing to see the user's real API credentials.

Before you write any code

Read the reference file(s) that match what you're building. Don't load both up front if the task only needs one — this keeps context lean.

  • references/api-reference.md — every REST endpoint (parcels, wilayas, communes, centers, fees, histories): params, filters, fields, full request and response shapes.
  • references/webhooks-reference.md — event types, payload formats, CRC challenge validation, HMAC signature verification, retry policy.
  • references/human-only-steps.md — the dashboard actions only the account owner can do. Read this first if the user hasn't mentioned having credentials yet.
  • references/troubleshooting.md — check here before improvising a fix when a call fails, a webhook doesn't fire, or a signature check rejects a real delivery. Most "weird" failures map to a known cause.

assets/.env.example — copy this into the project as a starting point for the required environment variables.

Two ready-to-adapt implementations are in scripts/:

  • scripts/yalidine-client.ts — typed API client (fetch-based, no dependencies) covering all endpoints, pagination, and rate-limit headers.
  • scripts/webhook-handler.ts — a Supabase Edge Function (Deno) implementing CRC validation + signature verification + event routing. Adapt the request/response wrapper for Express/Next.js/etc. if the project isn't on Supabase — the validation and security logic underneath is identical.

The integration workflow

  1. Confirm the user has generated credentials. You cannot get an API ID, API TOKEN, or webhook secret key yourself — these only exist inside the user's own Guepex Developer Dashboard and Webhooks Dashboard. If they haven't mentioned having them, point them to references/human-only-steps.md and wait. Never ask them to paste a screenshot of their dashboard or the raw key values into chat — have them put the values straight into an env file instead (see Security below).

  2. Set up configuration, not hardcoded values:

    YALIDINE_API_ID=...
    YALIDINE_API_TOKEN=...
    YALIDINE_BASE_URL=https://api.guepex.app/v1/
    YALIDINE_WEBHOOK_SECRET=...   # only needed if implementing webhooks

    Add these to .env.example with empty values so the user knows what to fill in, and to the project's actual env file (gitignored) if the user gives you the real values directly (not via screenshot).

  3. Build the API client layer first using references/api-reference.md — start with whichever endpoints the feature needs (usually: wilayas/communes for address forms, fees for a checkout price preview, parcels for order creation, histories for tracking pages).

  4. Cache static lookup data. Wilayas, communes, and centers change rarely. Don't call these endpoints on every request — fetch once, store in the app's DB or a cache with a daily/weekly refresh, and read from there. This also protects the user's rate-limit quota (see below).

  5. Build the webhook endpoint last, once parcel creation works, using references/webhooks-reference.md. The endpoint must exist and pass CRC validation before the user can create the webhook in their dashboard — tell them the order of operations if they ask you to "just set up the webhook."

  6. Tell the user what to do in the dashboard once your code is ready — see references/human-only-steps.md for the exact list, in order.

Non-negotiable security rules

  • Never put YALIDINE_API_TOKEN in front-end/client-side code (browser JS, mobile app bundles). It's a backend-only secret — every Yalidine call must go through the user's own server or edge function, never directly from a browser.
  • Always verify the X-YALIDINE-SIGNATURE header (HMAC-SHA256 of the raw request body, keyed with the webhook secret) before trusting any webhook payload. Reject anything that doesn't match with a 400 — see references/webhooks-reference.md for the exact algorithm.
  • Always keep the CRC challenge-response check (?subscribe=...&crc_token=... → echo crc_token back, 200 status) live in the webhook endpoint permanently. Yalidine re-validates it periodically; if it ever fails, the webhook is auto-disabled and the user stops getting delivery updates silently.
  • Never write real API IDs, tokens, secret keys, webhook URLs, or alert emails into code comments, example files, or documentation you generate — use env var references only, even in "here's an example" snippets.
  • The webhook endpoint must respond within 10 seconds. If the user's business logic (sending SMS, updating other systems, etc.) might be slow, have the endpoint just persist the raw payload and return 200 immediately, then process it in a background job/queue.
Show full SKILL.md (540 more words)Show less

Key domain gotchas (read before generating parcel-creation code)

  • Addresses are matched by name, not ID, when creating/editing a parcel. from_wilaya_name and to_wilaya_name/to_commune_name must exactly match a name from the wilayas/communes endpoints. Validate against your cached list before sending — a typo fails the whole parcel.
  • Personal data comes back masked (firstname, familyname, contact_phone, address, and the phone segment of qr_text) on every GET and PATCH response — e.g. "M*****d". This is intentional privacy protection on Yalidine's side. Never overwrite your own stored values with these masked ones. POST (creation) responses are not masked.
  • Stop-desk deliveries require a real stopdesk_id. Look it up from the centers endpoint (filter by wilaya_id/commune_id) — don't let a user type one in freely.
  • Edit and delete only work while the parcel's last_status is "En préparation." Once Yalidine picks it up, both PATCH and DELETE fail. Surface this constraint in the UI rather than letting users hit an API error.
  • Exchange parcels: if has_exchange is true, product_to_collect is required.
  • Oversize fee applies past 5kg billable weight, where billable weight = max(actual_weight, length*width*height*0.0002). Formula and worked examples are in references/api-reference.md under Fees.
  • Rate limits (default): 5/sec, 50/min, 1000/hour, 10000/day. Every response includes x-second-quota-left, x-minute-quota-left, x-hour-quota-left, x-day-quota-left headers — read them, and back off before hitting 429. Repeated 429s extend the ban period.
  • Bulk creation: POST /v1/parcels takes an array of parcels, even for one. The response is keyed by order_id, and partial failure is normal — some parcels in a batch can fail while others succeed. Always check each entry's success field individually rather than assuming an all-or-nothing result.

If something looks like it needs a dashboard action mid-build

Stop and tell the user — don't guess or fabricate a credential/URL/ID to keep going. Point them at references/human-only-steps.md.

If a call or a webhook doesn't behave as expected

Check references/troubleshooting.md before improvising — most failures (401s, rejected commune names, signature mismatches, silently-stopped webhooks) have a known cause and fix there rather than needing a guess.

Definition of done — verify before calling the integration finished

Don't declare the integration complete on "the code compiles." Actually run these checks, and tell the user which ones you could/couldn't verify yourself (some need their real credentials or a live deployment):

  • A real call to GET /v1/wilayas succeeds with the user's credentials (proves auth is wired correctly).
  • Wilaya/commune names used in parcel creation are validated against a cached lookup, not typed freely.
  • Stop-desk flows resolve stopdesk_id from /v1/centers, never from free user input.
  • Parcel creation handles partial batch failure — each entry's success field is checked individually, not just the HTTP status.
  • The API token/ID never appear in any client-side/browser-reachable code path — grep the frontend bundle for the env var names if unsure.
  • If webhooks are in scope: the CRC endpoint returns the exact token for a manual curl "<url>?subscribe=1&crc_token=test123" check, and this logic has no code path that could ever be removed by mistake.
  • If webhooks are in scope: signature verification uses the raw request body, not re-serialized JSON, and rejects on mismatch.
  • If webhooks are in scope: the endpoint returns 200 well under 10 seconds even under real processing load (heavy logic deferred to a queue/background job).
  • Event event_id values are deduplicated before side effects run (e.g. don't send a "your parcel shipped" SMS twice for a retried delivery).

© bighadj22, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in .agents/skills/yalidine-integration-skill-main/yalidine-integration of bighadj22/codflow.

  • SKILL.md
  • assets/.env.example
  • references/api-reference.md
  • references/human-only-steps.md
  • references/troubleshooting.md
  • references/webhooks-reference.md
  • scripts/webhook-handler.ts
  • scripts/yalidine-client.ts

Open the folder on GitHubat commit ed79aa9

Compare with similar skills

Yalidine Delivery Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Yalidine Delivery Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Yalidine Delivery Integration this skillbighadj22/codflow350—~2.5kAutomated safety check: PassApache-2.0
Polar Integrationchmonitor/chmonitor299—~4.3kAutomated safety check: PassGPL-3.0
Edgeone Pages Website SkeletonTencentEdgeOne/awesome-website-prompts-and-skills183—~2.2kAutomated safety check: NotesMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Supabasecurvenote/curvenote1705 repos~2.2kAutomated safety check: PassCustom licence
Golivemikehasa/golive-skill1.2k—~13kAutomated safety check: NotesMIT

Similar skills

  • Polar Integration

    chmonitor/chmonitor

    Add Polar billing to a TypeScript/JavaScript app using the @polar-sh/sdk package.

    299 GitHub stars~4.3k tokensUpdated 4 days ago
    Data & AnalyticsAuto-check passed
  • Edgeone Pages Website Skeleton

    TencentEdgeOne/awesome-website-prompts-and-skills

    基于 EdgeOne Pages 的全栈网站生成方案。用户说一句话(如「帮我建一个电商站」「做一个AI客服站」「做个管理后台」),AI 自动组合 Auth、Cart、Payment、AI Chat、Admin 五大模块,生成完整 Next.js 前后端代码并部署到 EdgeOne Pages 全球 CDN。支持电商、AI 助手、SaaS 管理后台三大模板。底层使用 Edge…

    183 GitHub stars~2.2k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    170 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.2k GitHub stars~13k tokensUpdated 5 days ago
    Backend & APIsAuto-check: notes
  • Nubase

    OtterMind/Nubase

    A skill your agent uses when the user mentions Nubase broadly, wants a backend for an AI-generated app, or needs to deploy/publish generated code online — across Database, Auth, Storage, Assets…

    623 GitHub stars~2.2k tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes

More from bighadj22/codflow

All 11 skills in this repo
  • Bundles Meta's official Pixel and Conversions API documentation so tracking changes, event deduplication and conversion events are checked against the real spec.

    350 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • CodFlow Change Workflow

    bighadj22/codflow

    A step-by-step workflow for changing the CodFlow repository: read the AGENTS.md contract, respect package boundaries, verify before claiming done and keep PRs small.

    350 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed
  • Guides an agent through eight customer tools in a cash-on-delivery CRM for Algerian e-commerce: search, profiles, phone lookup, order history, groups, tags and deletion.

    350 GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • Guides connecting and maintaining the EcoTrack courier adapter in CodFlow, one API shared by 82 Algerian couriers, using the official API reference and a rollout plan.

    350 GitHub stars~2.3k tokensUpdated 3 days ago
    Auto-check passed
  • defineRoute Route Builder

    bighadj22/codflow

    Creates new API endpoints, and converts older ones, with the defineRoute() pattern used in cod-server, including auth strategies, scopes and OpenAPI output.

    350 GitHub stars~924 tokensUpdated 3 days ago
    Auto-check passed
  • Runbook for deploying or redeploying the CodFlow Astro storefront to Vercel, with required environment variables, CLI or Git methods and checks afterwards.

    350 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Yalidine Delivery Integration

What does Yalidine Delivery Integration do?

Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks. This skill gives a coding agent what it needs to connect a platform to Yalidine, which also operates under the Guepex brand, without ever seeing the user's real credentials. It covers creating and tracking parcels, looking up wilayas, communes and stop-desk centers, calculating delivery fees and reacting to delivery-status changes through webhooks, including cash-on-delivery parcel creation and home or stop-desk delivery.

When should I use Yalidine Delivery Integration?

Yalidine Delivery Integration fits situations like: adding Yalidine or Guepex shipping to an e-commerce app; creating and tracking cash-on-delivery parcels; calculating delivery fees for a wilaya or commune; receiving and verifying delivery-status webhooks.

How do I install Yalidine Delivery Integration in Claude Code?

Run `npx skills add bighadj22/codflow --skill yalidine-integration -a claude-code`. Or copy the skill folder (.agents/skills/yalidine-integration-skill-main/yalidine-integration in bighadj22/codflow) into .claude/skills/yalidine-integration in your project. Claude Code loads it when a task matches its description.

How do I install Yalidine Delivery Integration in Codex?

Run `npx skills add bighadj22/codflow --skill yalidine-integration -a codex`. Or copy the skill folder (.agents/skills/yalidine-integration-skill-main/yalidine-integration in bighadj22/codflow) into .agents/skills/yalidine-integration in your project. Codex loads it when a task matches its description.

Can I use Yalidine Delivery Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bighadj22/codflow --skill yalidine-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/yalidine-integration, .gemini/skills/yalidine-integration, .github/skills/yalidine-integration and .opencode/skills/yalidine-integration in your project.

What does Yalidine Delivery Integration need to run?

Going by SKILL.md and its folder, Yalidine Delivery Integration needs TypeScript for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named YALIDINE_API_TOKEN and YALIDINE_WEBHOOK_SECRET. Our summary lists: A Yalidine (Guepex) account with an API ID, API token and webhook secret key.

Does Yalidine Delivery Integration access the network?

SKILL.md names 1 domain. In commands or code: api.guepex.app; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Yalidine Delivery Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Yalidine Delivery Integration use?

Yalidine Delivery Integration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Yalidine Delivery Integration use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.8k tokens, read only when the agent opens those files.

What are the alternatives to Yalidine Delivery Integration?

Skills that share tags, products or a category with Yalidine Delivery Integration: Polar Integration (chmonitor/chmonitor, 299 stars), Edgeone Pages Website Skeleton (TencentEdgeOne/awesome-website-prompts-and-skills, 183 stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars) and Supabase (curvenote/curvenote, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Yalidine Delivery Integration?

bighadj22 (a GitHub user) maintains it in bighadj22/codflow, which has 350 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 6, 2026.

Source: bighadj22/codflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.