The Omni CLO integration has two independent read workflows and one asynchronous write workflow.
Use the merchant and offer endpoints to synchronize the catalog available to your issuer. Every response is scoped by the issuer associated with the authenticated entity.
Issuer server -> GET /api/v1/omni/merchant -> merchant catalog
Issuer server -> GET /api/v1/omni/offer -> offer catalogList endpoints return currently relevant catalog data. ID endpoints support reconciliation and historical lookup, including an offer that has ended.
Issuer server -> GET /api/fileUpload -> file ID and presigned URL
Issuer server -> PUT presigned URL -> object storage
Percents -> validate whole file -> ingest in production
Percents -> signed terminal file-processing result -> issuer
Issuer server -> GET /api/v1/omni/files/{fileId} -> persisted progressA reservation does not mean bytes were uploaded. Native and Plaid files are automated; legacy formats are manual. Failed validation rejects the whole file before ingestion. Production reports terminal ingestion completion or failure; sandbox reports validation only. File results do not determine final transaction approval, rewards, or invoices.
Merchant and offer reads are scoped to the authenticated issuer. Uploaded files use the content format enabled for that issuer.
Sandbox and production each support two server-to-server network-access paths. Select one path for each environment. The API endpoints, request formats, and API-token authentication are the same; only the base URL and connection authentication differ.
| Environment | Source-IP allowlist URL | mTLS URL | Purpose |
|---|---|---|---|
| Sandbox | https://sandbox.percents.com | https://mtls.test.percents.com | Contract development and acceptance testing |
| Production | https://prod.percents.com | https://mtls.prod.percents.com | Live catalog and transaction processing |
With the source-IP allowlist path, Percents approves the stable public egress IP addresses or CIDR ranges that call the standard URL. With the mTLS path, your client presents an issuer client certificate to the mTLS URL instead. Do not send an mTLS request to the source-IP-allowlist URL.
Credentials, network-access configuration, upload enablement, and webhook destinations are configured separately per environment. See Authentication and Trusted Server Connection.
Sandbox does not perform live transaction processing. It is used to coordinate contract validation with Percents; see Sandbox access for the validation model.