NEXUS
APIs

WAVit APIs

WAVit is a client: it serves no API of its own. This page lists what it calls — MiCamp's own services first, then Clover, the dealer management systems and the payment partners. Paths are relative to the base URL named in each group; hosts are set per build flavor and are not published here.

Environments

Base URLs are buildConfigFields. Their values live in the ext block of the root build.gradle and are mapped into the two flavors in app/build.gradle.

BuildConfig fieldWhat it points atdevelopmentproduction
TOKEN_API_BASE_URLMiPoint APIDev instanceProd instance
SIGNALR_AGENT_ADDRESSPaymentsAgentTest instanceProd instance
CLOVER_PLATFORM_BASEClover RESTClover sandboxClover production
ORDER_BASE_URLClover ecommerceClover sandboxClover production
CITCON_BASE_URLCitcon POSP RESTCitcon UATCitcon production
DEALER_TRACK_BASE_URLDealerTrack OpenTrackStagingProduction
REMOTE_APP_IDClover remote app id for PaymentConnectorSandbox appProduction app
IS_PRODUCTIONFlagfalsetrue

Authentication

Label belowWhat the app sends
Device API keyThe device serial and an app API key in the body of POST api/authenticate
Device tokenAuthorization: Bearer <token> from api/authenticate, held in memory (Constants.TOKEN). Inventory calls may use their own token from the same endpoint.
Clover OAuthA bearer token from the Clover SDK's CloverAuth.authenticate, for the base URL the SDK returns
WS-SecurityA SOAP UsernameToken header, plus the dealer's EnterpriseCode / CompanyNumber / ServerName from settings
Client credentialsAn app credential exchanged for a token: the OAuth client-credentials grant against Fortellis identity, or the API key and secret from settings for Fincretive
Fortellis tokenAuthorization: Bearer <token> plus Subscription-Id from settings
Citcon store tokenA token form field, taken from the QR tender's settings
FCL tokenAuthorization: Bearer <jwt> from the Fincretive store-token call, held in memory

Any 401 from MiPoint API (other than the Fortellis-token and billing calls) triggers a fresh api/authenticate. Only a pending final payment record, a pre-transaction on the Review screen and the Transactions status call are replayed afterwards; other requests are dropped.

How requests are made

  • Almost every call goes through the WebApiCaller singleton: Retrofit with an RxJava 2 adapter, a JSON or SimpleXML converter, and 60-second timeouts. Results are routed back by an integer purpose code from AppConstants.
  • Single flight: starting a request cancels the one in flight, and a cancelled request calls back nothing. MiPoint order create and update are exempt.
  • Offline: if there is no network the request is not sent and the caller's offLine() fires. Nothing is queued at this layer.
  • Non-2xx responses fire both onError and onSuccess with the status code, so callers check the code themselves.
  • No automatic retry or backoff. Retries come from hand-written timers (Citcon, tethered status), user retry dialogs, or the two offline queues below.
  • WAVit Pro, Twilio, email and FTP bypass WebApiCaller with their own clients.

Offline queues

Two independent queues keep MiPoint API in step with Clover when the network drops.

Final payment recordPost-transaction update
CallPOST api/MiTransactionPUT api/mitransaction/Clover/{id}
StoreRoom table EntityPayment in wav_dbSharedPreferences post_transaction
WrittenEvery Clover payment or refund result, before sendingWhen offline, on a transport error or non-200
ReplayedOn each insert and when a payment screen opens — newest row first, one at a timePostTransactionWorker (WorkManager, network required) when a screen opens — oldest item, one per run
RemovedOnly after a 200 with a bodyAfter any HTTP response

Payments Clover took offline are completed from the outbox: fetch the missing card details from Clover (GET …/payments/{id}), capture offline pre-auths through Clover ecommerce, set the order note, then send the record.

Clover SDK surface

Most payment work never touches HTTP: it goes to local Clover services through the SDK, wrapped by the CloverConnectivity singleton.

Clover APIUsed for
PaymentConnector.saleCard sales, tip provided, Clover signature and receipts off
preAuth + capturePreAuthPre-Auth merchants; captured immediately with no tip
tipAdjustAuthAdd Tip from Transactions
refundPayment / voidPaymentRefund and void from Transactions
manualRefundBlind refunds and negative repair-order balances
readCardData / vaultCardBenefit-card reads; EBT Settings diagnostics
OrderConnectorCash and QR orders; WAVit Pro discounts and custom-line markup
TenderConnectorFinds the cash tender; creates the custom "WAVit" tender
MerchantConnector, MerchantDevicesV2ConnectorMerchant and device serial at startup
EmployeeConnectorCashier name and id
AppsConnector.getAppBillingInfoSubscription and trial state
PrinterConnector + ViewPrintJobEvery receipt and chit the app prints
CashDrawer, cash eventsOpening the drawer and logging cash
BarcodeScannerWallet QR scanning
CustomerModeFull-screen kiosk mode on the idle screen

WAVit Pro also listens for Register's broadcasts — ORDER_CREATED, LINE_ITEM_ADDED, V1_PAY_BUILD_START and the pay-start actions — through a receiver registered by its foreground service.

Receipts and diagnostics

  • Email receipts are sent from the device over SMTP (SMTP2GO, port 465) with JavaMail. Invoice emails and texts are sent by MiPoint API instead.
  • Text receipts go straight to the Twilio Messages API from the device.
  • Both carry a link to the hosted virtual receipt for the payment id.
  • Logtail (Better Stack) receives payment-flow traces, prefixed with the current payment id.
  • The on-device log file (WAVitLog<MM_dd_yyyy>.txt, seven days kept) is uploaded by FTP nightly and on demand from the Status screen, to /{merchantId}/{serial}/{app}/.

Endpoint reference

Grouped by audience. Paths are relative to the API base URL; {id}-style segments are GUIDs unless noted.

MiPoint API — device auth and settings

Base TOKEN_API_BASE_URL. The first two calls every terminal makes.

EndpointAuthNotes
POSTapi/authenticateDevice API keyBody { DeviceID, ApiKey }, where DeviceID is the Clover serial. Returns { bearerToken, merchantID }. Called at startup and after any 401.
GETapi/SqlConfigDevice tokenThe merchant's Settings JSON, deserialised field-for-field into model/Settings.java. Drives everything — see the settings reference on Resources.

MiPoint API — transactions

Every payment is recorded three times: a pre-transaction before Clover is called, a post-transaction update once Clover has answered, and the final payment record from the Room outbox.

EndpointAuthNotes
POSTapi/mitransactionDevice tokenPre-transaction on Pay: amounts, tender, invoice, advisor, employee, custom fields, TransactionTypeId, TransactionStatus 9. The returned paymentId keys the update.
PUTapi/mitransaction/Clover/{id}Device tokenPost-transaction update with card details, auth code, reference and signature. Queued in SharedPreferences when it cannot be sent. Also used for tip adjust with { TipAmount, TransactionStatus: "1" }.
GETapi/mitransaction/Clover/{paymentId}Device tokenOne transaction, for reprint, email or text from Transactions.
GETapi/mitransactions/SearchStatusDevice tokenStatus, refund reason and amounts for the Transactions screen. Query: page, count. Merged with Clover's payment list.
POSTapi/MiTransactionDevice tokenThe final record of every Clover payment or refund, sent from the Room outbox. The row is deleted only on a 200 with a body.

MiPoint API — invoices

Pay-by-link invoices. MiPoint sends the email or text.

EndpointAuthNotes
POSTapi/Invoices/Device tokenCreate an invoice after its pre-transaction. SendMethod is Email or SMSText; SendTo is the address or number.
GETapi/Invoices/SearchDevice tokenList and filter. Query: page, count, and optionally name, amount, phone, email, date, dateto.
POSTapi/Invoices/{id}Device tokenResend.
PATCHapi/Invoices/{id}Device tokenCancel with { Status: "Cancelled" }.
GETapi/invoices/transaction/{paymentId}Device tokenThe invoice behind a payment, from Transactions.

MiPoint API — inventory and orders

The cart. Items are sent as id and quantity only; the server prices the order.

EndpointAuthNotes
GET/api/inventory/categoriesDevice tokenCategory tabs.
GET/api/inventory/itemsDevice tokenA page of items with price, SKU, stock and image URL. Query: page, size (50), optional categoryId.
POST/api/inventory/stock/updateDevice tokenOne call per cart line after a card sale: { ItemId, Quantity, MovementType: "Sale" }. A failure never blocks the sale.
POST/api/ordersDevice tokenCreate the order before Clover is called: { ticketId, cashierId, employeeId, invoiceNumber, notes, businessDate, items }. Returns totals and line snapshots.
PATCH/api/orders/{id}Device tokenStatus change — Authorized, Completed, Voided, Refunded — with Clover order and payment ids and any benefit response. Fire and forget.
GET/api/ordersDevice tokenOrder history. Query: benefit=exclude for Orders, benefitOnly=true for Benefit Transactions; page, size.
GET/api/orders/{id}Device tokenOne order with items, for the benefit transaction detail screen.

MiPoint API — Reynolds & Reynolds

The app never calls Reynolds directly; MiPoint API proxies it.

EndpointAuthNotes
GETapi/Reynolds/Service/{roNumber}Device tokenA repair order: customer, advisor, amount due.
GETapi/Reynolds/Parts/{invoiceNumber}Device tokenA parts invoice: customer and total.
PATCHapi/Reynolds/Service/{id}Device tokenClose the RO after payment: { transactionType: "Close" }. Skipped when the DMS is bypassed.
PATCHapi/Reynolds/Parts/{id}Device tokenClose the parts invoice: { transferType: "Close" }.

MiPoint API — WAVit Pro

Called with HttpURLConnection from WAVit Pro's service, outside WebApiCaller. Skipped when no device token is in memory.

EndpointAuthNotes
GETapi/wavitpro/item-baselinesDevice token[{ cloverItemId, cashBaselineCents }], merged into the local price map with the server winning. Once per service start.
POSTapi/wavitpro/accept-termsDevice tokenRecord that the merchant accepted the WAVit Pro terms. Errors are ignored.

PaymentsAgent

Base SIGNALR_AGENT_ADDRESS. Tethered payments between a merchant terminal and its customer-facing terminal, plus Fortellis lookups for the older tethered service-order path.

EndpointAuthNotes
POSTapi/PaymentsAnonymousSend a payment request to the terminal named in customerFacingTerminal. Starts a 60-second status timer.
GETapi/Payments/{paymentUuid}AnonymousStatus poll. HTTP 210 means still processing: poll again in 15 seconds.
POSTapi/Payments/{paymentUuid}/CancelAnonymousCancel a pending request.
GETapi/fortellis/{serial}/serviceadvisorsAnonymousService advisors for the service-order list.
GETapi/fortellis/{serial}/repairordersAnonymousRepair orders for one advisor. Query: serviceAdvisorId.
GETapi/fortellis/{serial}/repairorders/{orderId}AnonymousOne repair order with its amount.
GETapi/invoices/refundtransaction/{paymentId}AnonymousThe refund reason shown when opening a refunded payment.

Clover REST

Base CLOVER_PLATFORM_BASE, or the base URL the Clover SDK returns. For what the SDK does not cover: history, validation, order notes, and recording cash and QR tenders.

EndpointAuthNotes
GET/v3/merchants/{mId}Clover OAuthWith expand=gateway: whether the merchant is billable, and the MID's last four digits for receipts.
GET/v3/merchants/{mId}/paymentsClover OAuthTransactions history with expand=cardTransaction,refunds,tender,externalReferenceId and filters on reference, amount, last four and date. A 15-second watchdog offers a retry.
GET/v3/merchants/{mId}/payments/{paymentId}Clover OAuthValidate a payment after the sale; with expand=cardTransaction, fill in card details for offline payments.
GET/v3/merchants/{mId}/employees/{employeeId}Clover OAuthThe cashier's customId, used as the employee ID.
GET/v3/merchants/{mId}/orders/{orderId}Clover OAuthWith expand=payments for the receipt's payment state; with expand=lineItems for WAVit Pro's totals.
POST/v3/merchants/{mId}/orders/{orderId}Clover OAuthSet the order note to the tender caption, or "WAVit Payments <version>".
POST/v3/merchants/{mId}/orders/{orderId}/paymentsClover OAuthRecord a cash or wallet-QR payment on a Clover order, with tender, device, amount, tip and tax in cents.
POST/v3/merchants/{mId}/orders/{orderId}/discountsClover OAuthWAVit Pro fallback for adding the cash discount when the SDK path fails. Existing cash discounts are deleted first.
GET/v3/merchants/{mId}/creditsClover OAuthManual Refunds list; /credits/{creditId} with expansions for reprint, email and text.
POSTv1/charges/{paymentId}/captureClover OAuthOn ORDER_BASE_URL (Clover ecommerce). Captures a pre-auth that Clover took offline, from the Room outbox.

DealerTrack OpenTrack

Base DEALER_TRACK_BASE_URL. SOAP over HTTP POST with typed SimpleXML envelopes and a SOAPAction header per operation. Read-only: nothing is written back.

EndpointAuthNotes
POST/serviceapi.asmx · ServiceWritersTableWS-SecurityService writers, loaded at startup to validate the advisor ID.
POST/partsapi.asmx · PartsCounterPersonsTableRequestWS-SecurityParts counter persons, loaded at startup.
POST/serviceapi.asmx · OpenRepairOrderLookupWS-SecurityOne open RO by number: customer, vehicle, writer, CustomerPayTotalDue, ROStatus.
POST/partsapi.asmx · CounterTicketSearchWS-SecurityOne parts counter ticket by invoice number, with its total.

CDK Fortellis

Hard-coded Fortellis hosts, the same in both flavors. Every data call sends the Fortellis token and the merchant's Subscription-Id.

EndpointAuthNotes
POSToauth2/{authServer}/v1/tokenClient credentialsgrant_type=client_credentials. At startup, with up to three user-driven retries, and before each repair-order search.
GETcdkdrive/service/v1/repair-orders/lookups/service-advisors/Fortellis tokenService advisors, cached at startup to validate the advisor ID.
GETcdkdrive/service/v1/repair-orders/{repairNumber}Fortellis tokenThe repair order with customer and vehicle links. Status C94, C95 or C97 is payable.
GET{customerHref} and {vehicleHref}Fortellis tokenCustomer name and vehicle, followed from the repair order. Failures are tolerated.
GETcdk/payments/cdk-epayments/v2/settling/payments/status/account/{departmentCode}/invoiceId/{repairNumber}Fortellis tokenThe amount to pay.

Citcon

Base CITCON_BASE_URL. Wallet QR payments. All calls are form-encoded POSTs answered with { result, code, transaction_id, … }.

EndpointAuthNotes
POSTinitializeCitcon store tokenPrepare the store for tethered QR. Result is only logged.
POSTpayCitcon store tokenCharge a scanned wallet code: barcode, tip, total, USD. Code 09 means pending: inquire every 10 seconds, up to nine times.
POSTinquireCitcon store tokenPoll a pending payment.
POSTcancelCitcon store tokenCancel a pending payment; code E3 retries after 20 seconds.

Fincretive FCL Benefits Gateway

SNAP/EBT and HBC/OTC. Every api/fcl/process call carries a transactionType; they are listed separately here. Money fields are strings with two decimals.

EndpointAuthNotes
POSTapi/auth/store-tokenClient credentials{ api_key, api_secret, lane_id } from settings. Returns a JWT valid for about a day, kept in memory.
POSTapi/fcl/process · LoginFCL tokenOpen the lane. POS and cashier ids are currently fixed to "1".
POSTapi/fcl/process · BINLookupFCL tokenLook up a card BIN. The result is logged; routing uses a local BIN list.
POSTapi/fcl/process · AuthorizeFCL tokenCard fields, amount and tax, and orderItems with an eligibility flag each. Returns the approved amount, wallets and per-item approvals.
POSTapi/fcl/process · VoidFCL tokenVoid an authorisation the cashier declined, from the original order id, time and auth code.
POSTapi/fcl/process · RefundFCL tokenItem-level refund from Benefit Transactions.