WAVit is a client: it serves no API of its own. This page lists what it calls — MiCamp's own services first, then Clover, the dealer management systems and the payment partners. Paths are relative to the base URL named in each group; hosts are set per build flavor and are not published here.
Base URLs are buildConfigFields. Their values live in the ext block of the root build.gradle and are mapped into the two flavors in app/build.gradle.
| BuildConfig field | What it points at | development | production |
|---|---|---|---|
TOKEN_API_BASE_URL | MiPoint API | Dev instance | Prod instance |
SIGNALR_AGENT_ADDRESS | PaymentsAgent | Test instance | Prod instance |
CLOVER_PLATFORM_BASE | Clover REST | Clover sandbox | Clover production |
ORDER_BASE_URL | Clover ecommerce | Clover sandbox | Clover production |
CITCON_BASE_URL | Citcon POSP REST | Citcon UAT | Citcon production |
DEALER_TRACK_BASE_URL | DealerTrack OpenTrack | Staging | Production |
REMOTE_APP_ID | Clover remote app id for PaymentConnector | Sandbox app | Production app |
IS_PRODUCTION | Flag | false | true |
Fortellis, Logtail and Twilio hosts are hard-coded and the same in both flavors, as intended. The Fincretive gateway and the post-sale stock updates are hard-coded too — to development hosts — which is a bug (see Known issues on the overview).
| Label below | What the app sends |
|---|---|
| Device API key | The device serial and an app API key in the body of POST api/authenticate |
| Device token | Authorization: Bearer <token> from api/authenticate, held in memory (Constants.TOKEN). Inventory calls may use their own token from the same endpoint. |
| Clover OAuth | A bearer token from the Clover SDK's CloverAuth.authenticate, for the base URL the SDK returns |
| WS-Security | A SOAP UsernameToken header, plus the dealer's EnterpriseCode / CompanyNumber / ServerName from settings |
| Client credentials | An app credential exchanged for a token: the OAuth client-credentials grant against Fortellis identity, or the API key and secret from settings for Fincretive |
| Fortellis token | Authorization: Bearer <token> plus Subscription-Id from settings |
| Citcon store token | A token form field, taken from the QR tender's settings |
| FCL token | Authorization: Bearer <jwt> from the Fincretive store-token call, held in memory |
Any 401 from MiPoint API (other than the Fortellis-token and billing calls) triggers a fresh api/authenticate. Only a pending final payment record, a pre-transaction on the Review screen and the Transactions status call are replayed afterwards; other requests are dropped.
WebApiCaller singleton: Retrofit with an RxJava 2 adapter, a JSON or SimpleXML converter, and 60-second timeouts. Results are routed back by an integer purpose code from AppConstants.offLine() fires. Nothing is queued at this layer.onError and onSuccess with the status code, so callers check the code themselves.WebApiCaller with their own clients.Two independent queues keep MiPoint API in step with Clover when the network drops.
| Final payment record | Post-transaction update | |
|---|---|---|
| Call | POST api/MiTransaction | PUT api/mitransaction/Clover/{id} |
| Store | Room table EntityPayment in wav_db | SharedPreferences post_transaction |
| Written | Every Clover payment or refund result, before sending | When offline, on a transport error or non-200 |
| Replayed | On each insert and when a payment screen opens — newest row first, one at a time | PostTransactionWorker (WorkManager, network required) when a screen opens — oldest item, one per run |
| Removed | Only after a 200 with a body | After any HTTP response |
Payments Clover took offline are completed from the outbox: fetch the missing card details from Clover (GET …/payments/{id}), capture offline pre-auths through Clover ecommerce, set the order note, then send the record.
Most payment work never touches HTTP: it goes to local Clover services through the SDK, wrapped by the CloverConnectivity singleton.
| Clover API | Used for |
|---|---|
PaymentConnector.sale | Card sales, tip provided, Clover signature and receipts off |
preAuth + capturePreAuth | Pre-Auth merchants; captured immediately with no tip |
tipAdjustAuth | Add Tip from Transactions |
refundPayment / voidPayment | Refund and void from Transactions |
manualRefund | Blind refunds and negative repair-order balances |
readCardData / vaultCard | Benefit-card reads; EBT Settings diagnostics |
OrderConnector | Cash and QR orders; WAVit Pro discounts and custom-line markup |
TenderConnector | Finds the cash tender; creates the custom "WAVit" tender |
MerchantConnector, MerchantDevicesV2Connector | Merchant and device serial at startup |
EmployeeConnector | Cashier name and id |
AppsConnector.getAppBillingInfo | Subscription and trial state |
PrinterConnector + ViewPrintJob | Every receipt and chit the app prints |
CashDrawer, cash events | Opening the drawer and logging cash |
BarcodeScanner | Wallet QR scanning |
CustomerMode | Full-screen kiosk mode on the idle screen |
WAVit Pro also listens for Register's broadcasts — ORDER_CREATED, LINE_ITEM_ADDED, V1_PAY_BUILD_START and the pay-start actions — through a receiver registered by its foreground service.
WAVitLog<MM_dd_yyyy>.txt, seven days kept) is uploaded by FTP nightly and on demand from the Status screen, to /{merchantId}/{serial}/{app}/.Grouped by audience. Paths are relative to the API base URL; {id}-style segments are GUIDs unless noted.
Base TOKEN_API_BASE_URL. The first two calls every terminal makes.
| Endpoint | Auth | Notes |
|---|---|---|
POSTapi | Device API key | Body { DeviceID, ApiKey }, where DeviceID is the Clover serial. Returns { bearerToken, merchantID }. Called at startup and after any 401. |
GETapi | Device token | The merchant's Settings JSON, deserialised field-for-field into model/Settings.java. Drives everything — see the settings reference on Resources. |
Every payment is recorded three times: a pre-transaction before Clover is called, a post-transaction update once Clover has answered, and the final payment record from the Room outbox.
| Endpoint | Auth | Notes |
|---|---|---|
POSTapi | Device token | Pre-transaction on Pay: amounts, tender, invoice, advisor, employee, custom fields, TransactionTypeId, TransactionStatus 9. The returned paymentId keys the update. |
PUTapi | Device token | Post-transaction update with card details, auth code, reference and signature. Queued in SharedPreferences when it cannot be sent. Also used for tip adjust with { TipAmount, TransactionStatus: "1" }. |
GETapi | Device token | One transaction, for reprint, email or text from Transactions. |
GETapi | Device token | Status, refund reason and amounts for the Transactions screen. Query: page, count. Merged with Clover's payment list. |
POSTapi | Device token | The final record of every Clover payment or refund, sent from the Room outbox. The row is deleted only on a 200 with a body. |
Pay-by-link invoices. MiPoint sends the email or text.
| Endpoint | Auth | Notes |
|---|---|---|
POSTapi | Device token | Create an invoice after its pre-transaction. SendMethod is Email or SMSText; SendTo is the address or number. |
GETapi | Device token | List and filter. Query: page, count, and optionally name, amount, phone, email, date, dateto. |
POSTapi | Device token | Resend. |
PATCHapi | Device token | Cancel with { Status: "Cancelled" }. |
GETapi | Device token | The invoice behind a payment, from Transactions. |
The cart. Items are sent as id and quantity only; the server prices the order.
| Endpoint | Auth | Notes |
|---|---|---|
GET | Device token | Category tabs. |
GET | Device token | A page of items with price, SKU, stock and image URL. Query: page, size (50), optional categoryId. |
POST | Device token | One call per cart line after a card sale: { ItemId, Quantity, MovementType: "Sale" }. A failure never blocks the sale. |
POST | Device token | Create the order before Clover is called: { ticketId, cashierId, employeeId, invoiceNumber, notes, businessDate, items }. Returns totals and line snapshots. |
PATCH | Device token | Status change — Authorized, Completed, Voided, Refunded — with Clover order and payment ids and any benefit response. Fire and forget. |
GET | Device token | Order history. Query: benefit=exclude for Orders, benefitOnly=true for Benefit Transactions; page, size. |
GET | Device token | One order with items, for the benefit transaction detail screen. |
The app never calls Reynolds directly; MiPoint API proxies it.
| Endpoint | Auth | Notes |
|---|---|---|
GETapi | Device token | A repair order: customer, advisor, amount due. |
GETapi | Device token | A parts invoice: customer and total. |
PATCHapi | Device token | Close the RO after payment: { transactionType: "Close" }. Skipped when the DMS is bypassed. |
PATCHapi | Device token | Close the parts invoice: { transferType: "Close" }. |
Called with HttpURLConnection from WAVit Pro's service, outside WebApiCaller. Skipped when no device token is in memory.
| Endpoint | Auth | Notes |
|---|---|---|
GETapi | Device token | [{ cloverItemId, cashBaselineCents }], merged into the local price map with the server winning. Once per service start. |
POSTapi | Device token | Record that the merchant accepted the WAVit Pro terms. Errors are ignored. |
Base SIGNALR_AGENT_ADDRESS. Tethered payments between a merchant terminal and its customer-facing terminal, plus Fortellis lookups for the older tethered service-order path.
| Endpoint | Auth | Notes |
|---|---|---|
POSTapi | Anonymous | Send a payment request to the terminal named in customerFacingTerminal. Starts a 60-second status timer. |
GETapi | Anonymous | Status poll. HTTP 210 means still processing: poll again in 15 seconds. |
POSTapi | Anonymous | Cancel a pending request. |
GETapi | Anonymous | Service advisors for the service-order list. |
GETapi | Anonymous | Repair orders for one advisor. Query: serviceAdvisorId. |
GETapi | Anonymous | One repair order with its amount. |
GETapi | Anonymous | The refund reason shown when opening a refunded payment. |
Base CLOVER_PLATFORM_BASE, or the base URL the Clover SDK returns. For what the SDK does not cover: history, validation, order notes, and recording cash and QR tenders.
| Endpoint | Auth | Notes |
|---|---|---|
GET | Clover OAuth | With expand=gateway: whether the merchant is billable, and the MID's last four digits for receipts. |
GET | Clover OAuth | Transactions history with expand=cardTransaction,refunds,tender,externalReferenceId and filters on reference, amount, last four and date. A 15-second watchdog offers a retry. |
GET | Clover OAuth | Validate a payment after the sale; with expand=cardTransaction, fill in card details for offline payments. |
GET | Clover OAuth | The cashier's customId, used as the employee ID. |
GET | Clover OAuth | With expand=payments for the receipt's payment state; with expand=lineItems for WAVit Pro's totals. |
POST | Clover OAuth | Set the order note to the tender caption, or "WAVit Payments <version>". |
POST | Clover OAuth | Record a cash or wallet-QR payment on a Clover order, with tender, device, amount, tip and tax in cents. |
POST | Clover OAuth | WAVit Pro fallback for adding the cash discount when the SDK path fails. Existing cash discounts are deleted first. |
GET | Clover OAuth | Manual Refunds list; /credits/{creditId} with expansions for reprint, email and text. |
POSTv1 | Clover OAuth | On ORDER_BASE_URL (Clover ecommerce). Captures a pre-auth that Clover took offline, from the Room outbox. |
Base DEALER_TRACK_BASE_URL. SOAP over HTTP POST with typed SimpleXML envelopes and a SOAPAction header per operation. Read-only: nothing is written back.
| Endpoint | Auth | Notes |
|---|---|---|
POST | WS-Security | Service writers, loaded at startup to validate the advisor ID. |
POST | WS-Security | Parts counter persons, loaded at startup. |
POST | WS-Security | One open RO by number: customer, vehicle, writer, CustomerPayTotalDue, ROStatus. |
POST | WS-Security | One parts counter ticket by invoice number, with its total. |
Hard-coded Fortellis hosts, the same in both flavors. Every data call sends the Fortellis token and the merchant's Subscription-Id.
| Endpoint | Auth | Notes |
|---|---|---|
POSToauth2 | Client credentials | grant_type=client_credentials. At startup, with up to three user-driven retries, and before each repair-order search. |
GETcdkdrive | Fortellis token | Service advisors, cached at startup to validate the advisor ID. |
GETcdkdrive | Fortellis token | The repair order with customer and vehicle links. Status C94, C95 or C97 is payable. |
GET{customerHref} and {vehicleHref} | Fortellis token | Customer name and vehicle, followed from the repair order. Failures are tolerated. |
GETcdk | Fortellis token | The amount to pay. |
Base CITCON_BASE_URL. Wallet QR payments. All calls are form-encoded POSTs answered with { result, code, transaction_id, … }.
| Endpoint | Auth | Notes |
|---|---|---|
POSTinitialize | Citcon store token | Prepare the store for tethered QR. Result is only logged. |
POSTpay | Citcon store token | Charge a scanned wallet code: barcode, tip, total, USD. Code 09 means pending: inquire every 10 seconds, up to nine times. |
POSTinquire | Citcon store token | Poll a pending payment. |
POSTcancel | Citcon store token | Cancel a pending payment; code E3 retries after 20 seconds. |
SNAP/EBT and HBC/OTC. Every api/fcl/process call carries a transactionType; they are listed separately here. Money fields are strings with two decimals.
| Endpoint | Auth | Notes |
|---|---|---|
POSTapi | Client credentials | { api_key, api_secret, lane_id } from settings. Returns a JWT valid for about a day, kept in memory. |
POSTapi | FCL token | Open the lane. POS and cashier ids are currently fixed to "1". |
POSTapi | FCL token | Look up a card BIN. The result is logged; routing uses a local BIN list. |
POSTapi | FCL token | Card fields, amount and tax, and orderItems with an eligibility flag each. Returns the approved amount, wallets and per-item approvals. |
POSTapi | FCL token | Void an authorisation the cashier declined, from the original order id, time and auth code. |
POSTapi | FCL token | Item-level refund from Benefit Transactions. |