One source of control
Multiple manufacturers connect behind a single SourceRX administration layer. Partners never manage supplier systems, credentials, or catalogs directly.
SourceRX is the distribution layer between manufacturer systems and approved businesses. We connect manufacturer supply, decide which products each partner can access, and manage the commercial relationship — so partners get one simple account instead of a dozen supplier portals.
Three things, kept deliberately separate.
Multiple manufacturers connect behind a single SourceRX administration layer. Partners never manage supplier systems, credentials, or catalogs directly.
Clinics and businesses use the same workspace. Which products you can offer is configured by SourceRX based on your business type and approval.
Storefront orders, manual orders, and shared-link orders all stay attributed to the right partner, manufacturer, and product.
Access is approval-only. Nothing is self-serve.
Tell us about your business, where you ship, the volume you expect, and how you plan to drive demand.
SourceRX reviews the application and approves the organisation. Approval sets which products you may offer.
An administrator assigns your manufacturer and sets your commercial terms. Those internal economics never appear in your portal or storefront.
Select your products, choose your DBA, and publish a tracked white-label storefront — or order directly through SourceRX.
Approved businesses only. We review every application before granting access.
Build your store, watch orders arrive, or share your unique storefront—all through one controlled partner workspace.
Offer only the SourceRX products approved for your partner account.
Select the approved products you want on your storefront.
Use your approved DBA for your partner storefront.
Shown on your storefront and on your terms and privacy pages, so your customers write to you. Leave it empty and SourceRX support is used instead.
PNG, JPEG or WebP, up to 256KB. Shown in place of your store name at the top of every page.
or drag one here
Used for buttons and highlights. Text on top is set automatically to whatever stays readable.
#1557d5
SourceRX reviews every storefront before it goes live at your tracked link.
Every order a customer has placed on your storefront, who it is going to, and its tracking once the manufacturer despatches it.
Choose quantities and send the request. SourceRX confirms it with the manufacturer, then emails you a link to pay. Nothing is charged until you pay it, and the stock lands in your inventory once the payment clears.
What you have bought and not yet sold. It is held at the manufacturer under your name and ships from there, so there is nothing for you to store or pack. Sales from your storefront draw it down automatically.
Every sale from your storefront, what it left you, and what has cleared to be withdrawn.
Card fees are taken by the payment processor before the money reaches SourceRX. They are shown here so your figures reconcile — SourceRX does not receive them.
On stock you had already bought, the whole sale is paid to you — your profit is that sale less what those units cost you.
Approving a request does not charge anybody. It opens the order for payment and emails the partner a link — they pay on the processor's own page, and their stock appears once it clears.
Approving decides it. It does not move money — you still issue the refund with your payment provider, and the books update when their confirmation arrives.
What SourceRX has earned, what is owed to partners and manufacturers, and what is still held back.
Processor fees appear as deductions. They are kept by the payment provider out of each charge and never reach this business.
Four separate cuts. The processor's is kept by the card company and reaches none of the other three.
A bundle is your own price for a set of products you already sell. It cannot be priced below what those products cost you — the floor is shown as you build it.
Pick at least two products and set one price for the set.
Fills the form below. Nothing is saved until you set a price and press Save, and every field stays editable.
Goes in front of each set name, so they read as yours.
Offer a discount to customers who want to reorder monthly. They are not charged automatically — the gateway cannot hold a card for that yet — so the checkout promises a reminder at the agreed price, which is a thing you can actually deliver. The agreement and its discount are recorded either way.
Which products get picked up and put back down. That is interest you already have and are losing, and it is the one thing your orders table cannot show you — an orders table only contains the sales that happened.
Sorted by how many people put it in a basket. A product high on this list with nothing in the last column is priced or described wrongly, not unwanted.
An average across shops that are not alike is not a reading. The useful question is always which shop is out of line with the others — so this breaks down by partner and narrows to one.
Failed sales and why, deliveries that didn't reach a supplier, errors from the server and from browsers, and controls that were pressed and did nothing. Grouped, so four thousand of one fault reads as one fault.
Sweeps every control on every screen, every readable endpoint, the catalog and the money, and the settings that only matter in production. Reads only — it never presses anything, because on a live system that would place orders and send mail. Each run is kept below.
A compound is in a supplier's sheet and not on a shelf. Type its name and this walks every gate between the two and names the one that is shut.
Payments opened and not settled. Cancel one to make its order permanently unshippable — this moves no money, so void or refund it with the processor separately.
Kept so a fault can be dated. "This appeared between Tuesday and Wednesday" is a far shorter hunt than "this is wrong".
The issuer's own reason, not ours — "declined" tells nobody whether to try again.
Settled payments with nothing in the book behind them. Nobody has been credited for these.
Two catalog entries for what looks like one molecule. Supply and prices split between them, and both look correct on every other screen.
Pressed, and then no request, no change on screen and no message. This is the failure that reports itself nowhere else.
What you supply, what is waiting to be filled, and what you have earned.
Only the lines you supply, and where each parcel goes. Report tracking against these through your API key as you do now.
Taken from your catalog feed. Change it there and it changes here on the next sync.
Your agreed price for every line you have filled. A tenth is held for thirty days against returns, and released on the date shown.
Anything about a product, a delivery, an order or your shop. Each one gets a reference and a state you can see, so you always know whether it is with us, with the manufacturer, or waiting on you.
Every problem raised, with the whole conversation. Notes you mark private stay on the thread and are never shown to the partner — which is where working something out with a manufacturer belongs.
Track authorized lead and customer activity without displaying clinical or prescription information.
Orders per week, last 8 weeks
Every product approved for your account, what it costs you, and what you keep after the card processor takes its fee. Leaving a price empty sells at cost — which is a small loss once that fee comes off, so each row names the price that breaks even.
Volume, orders and margin across the network. Revenue is what partners pay SourceRX; profit is what is left after the manufacturer's cost basis.
Units, revenue and margin by product, and which stores are ordering each one. Open a product to see the store breakdown.
A snapshot as CSV. Nothing is stored — the file is generated when you ask for it and every download is recorded in the audit trail.
Orders export one row per line item, with unit cost, unit price, margin, carrier, tracking and the address it shipped to.
Review businesses before they can access or sell through SourceRX. Approving one creates the partner workspace and issues its login.
Connect, manage, and assign product sources for the SourceRX partner network.
Manufacturer assignment, cost basis, and partner-specific markup remain private to SourceRX administrators. Partners see only their approved products and selling experience.
Every approved business, its storefront state, and the manufacturer behind it. Add one directly, or approve an application.
Every system SourceRX talks to: the processor that takes the money, the service that sends email, and each manufacturer whose catalog we read and who reports despatches back.
Invitations, approvals and sign-in codes are sent from here. The API key is held in the server environment and is never sent to this page.
A merchant account per partner, so a customer's statement names the shop they bought from. Credentials are encrypted before they are stored and are never sent back to this page.
A partner's own account is used for their orders, so their customer's bank statement names the shop they bought from. Leave it on Network default for an account any partner may fall back to.
The account reference is for your records only — it is never sent to the processor. Some processors issue a merchant ID you can put here; Eltrovox does not, so any label you will recognise is fine.
Orders only ever route to a processor matching the environment the server is running in. A sandbox account cannot take a real payment even if it is left active.
Both are encrypted with AES-256-GCM before they reach the database, so a database dump alone does not yield them. No page can read either back — only the last four characters are ever returned.
Fill in either or both. Whichever you leave empty is left untouched.
A processor cannot be activated without its credentials, cannot be moved between sandbox and live while active, and cannot be disconnected while active — all refused by the API, not just hidden here.
Two directions per manufacturer. We read their catalog on a schedule; they report despatches and tracking back using a key issued here. Their developers need the integration documentation.
What your customers hear from you automatically — order confirmations, shipping updates, and follow-ups. Each one sends from your store\'s name.
A read-only endpoint an outside dashboard can poll for one summary of this business. It exposes totals only — no partner, customer, supplier or product is named in the response.
Paste this into the portfolio hub as the company URL. It answers GET and returns JSON.
Each key is shown once, when it is made, and is stored here only as a hash. If one is lost, revoke it and make another.
Paste the raw value. Do not add Bearer in front of it.
The live response, read with your session rather than a key, so the figures can be checked before one exists.
Assign a manufacturer and control the internal margin for this approved partner.
Who at this business can sign in. A partner with no login cannot reach the platform at all.
Passwords are generated and shown once. This is a prototype — the account list is stored in the page, so these are not real credentials.
Read from what this partner sells. Each line is filled by whichever supplier can, chosen per order.
Used only where more than one manufacturer can fill a line: this partner's orders go to the preferred one rather than the cheapest. It does not change what they may sell, and a supplier we cannot reach is still passed over — preferring someone who cannot be told about the order would honour the preference by failing to fill it.
Manufacturer price → SourceRX fee → what this partner pays. Owner-only.
This partner has no tier on the dropship schedule, so they have no cost basis and nothing to select in their storefront.
The manufacturer price is yours alone. It is not sent to this partner, to any other partner, or to an admin — the API returns it to the owner account only. The fee is what SourceRX takes on top; what the partner charges their own customer is theirs to set and is not recorded here.
Powered by SourceRX
The catalog held by the API. One row per size, because a size is what carries a price.
Adding a few hundred line items through a form is not a workflow anyone follows. Upload your sheet, read the diff, then apply it.
A CSV needs a header row with product and size. Anything with price or tier in its name is read as a price, left to right. category, form and classification are optional, and so are prices.
Importing the same sheet twice changes nothing the second time — it is matched on product, size and tier, so a spreadsheet can stay the source of truth and be re-imported after every edit.
Nothing here can be sold — an order for one of these reaches dispatch and finds no manufacturer to send it to. Removing is permanent: the sizes, their prices and any partner's storefront selection go with them. Lines a supplier stops offering are cleared automatically after a sync; these are the ones left over from an import, which no feed will ever mention.
Partner accounts see only the products their business type is approved for. Changing availability here immediately changes what every partner of that type can select and order.
The onboarding form partners fill in, the service that sends your email, and the automations that fire off platform events.
These are the questions on the public apply page, in this order. Changes take effect immediately.
Exactly what an applicant sees, rendered from the list above.
Business name, business type, primary contact and work email create the partner record and issue its login when an application is approved. They can be relabelled but not removed or disabled.
Answers to every other question are stored with the application and shown to whoever reviews it.
Transactional and automation email. This reports what the server is actually configured with — it is not set from this page.
The key is read from the server environment and never from a request, so no page can submit one and no admin session can read one back. Changing it means setting RESEND_API_KEY in the Railway dashboard and redeploying.
RESEND_API_KEY in Railway, then redeployEMAIL_FROM with ResendResend issues the DNS records for step 2 — DKIM, SPF, a feedback MX and DMARC — in its own dashboard. They are shown there rather than here so the values are the real ones for your domain.
An unverified domain and an invalid key both fail every send, and they need different fixes. The test send reports whichever one Resend names.
Sends the real message to your own address, you, with sample details in place of anyone's actual credentials. One send per minute.
RESEND_API_KEY and redeploy — see Email delivery.
Every change here is confirmed before it applies.
Customer emails belong to the shop that sends them. This is what they have chosen.
Every tab is its own link, so you can send someone the one section they need rather than the whole document.
These pages are public and contain no credentials — a key is issued separately and is never in the document. Sections marked Specified describe agreed shapes that are not built yet, and say so on the page.
Admins run the network. Employees do day-to-day work and cannot reach settings, payments or this page.
Give this password. It is shown once and is not recoverable — if it is lost, use Reset below to issue a new one.
The owner is set by OWNER_EMAIL and cannot be changed here. You cannot change or remove your own access — that is what stops an organisation locking itself out.
What happens between placing an order and a parcel arriving, and who to ask when something is wrong.
Tracking appears against the order in your order history as soon as the manufacturer reports it.
Email [email protected] and a person will answer. Include the order reference if it is about an order — it is the fastest way to get a real answer rather than a request for more detail.
Your own customers should contact you, not us. They bought from your store and have never heard of SourceRX — order confirmations and tracking emails already reply to your address, so this happens by itself.
The prices you see are what you pay SourceRX, at the tier set for you. What you charge your own customers is entirely yours to decide — set it wherever you like above your cost. We do not record it and nobody else sees it.
You cannot see other partners, and no other partner can see you, your clients or your orders. The manufacturer is given the shipping address and the products, and is not told what anything cost.
Invite colleagues from Settings. Everyone you invite can do everything you can. Nobody can remove their own access, and the last remaining account cannot be removed — that is what stops a business locking itself out.
The technical reference, including the parts written for manufacturers. Opens in a new tab.
Anything about pricing, products or approvals goes to your SourceRX contact rather than the documentation.
Who at your business can sign in.
They get their own sign-in and can do everything you can — build the storefront, place orders and manage clients.
Give this password. It is shown once and cannot be recovered.
You cannot remove your own access, and the last remaining account cannot be removed — that is what stops a business locking itself out.
Your name as it appears to everyone else, and the password you sign in with.
Your email address and access level are set by an administrator and cannot be changed here.
The owner login comes from OWNER_EMAIL and OWNER_PASSWORD, and is re-applied on every boot. Editing it here would be undone at the next deploy, so the server refuses the change rather than appearing to accept it. Change those variables in Railway and redeploy.
The upside: if the owner password is ever lost, editing the environment and restarting is the way back in.
At least 12 characters. Every other browser signed in as you is signed out; this one stays.
Everything below is accurate as of this build — no button is decorative, but several are deliberately simulated.
Backed by the database. Survives a reload, a redeploy, and a different browser.
The partner workspace. These moved out of browser memory and into the database.
Cost basis and markup are still sent to the browser for any signed-in admin, so they are visible in devtools to anyone with an admin session. They are no longer visible to a signed-out visitor.
Kept honest deliberately. Everything above this line works against real services; everything below does not exist yet, and is listed so nobody discovers it at an inconvenient moment.
Trigger: —. Triggers are defined by the platform; timing and copy are yours.
Each step sends the given time after the trigger.
Merge tags like {{order_id}}, {{product_name}} and {{store_name}} are placeholders only — nothing resolves them in this prototype.
Creates the partner workspace directly, without going through an application.
Cost basis is internal. Partners never see it — they see only which products they may offer.
Shown on the product's page in every storefront. Keep it factual — presentation, purity, storage, handling. These products are sold for research, so a statement about what a compound does to a body is a claim the store cannot make.
Prices are set per tier and arrive through the import — a product can exist before it is priced. Add further sizes from the row once it is created.
Editing —.
The email address cannot be changed — it is what the account signs in with. Access level and status are changed from the row itself.
Deactivating keeps the record, its catalog products and its history. Deleting removes the record and leaves those products unassigned.