Every Omni request is scoped to the issuer associated with the authenticated entity. Percents completes issuer setup during onboarding. Clients do not send an issuer ID or a scope override in a request.
Percents completes these steps separately in sandbox and production:
- Create or identify the issuer account.
- Create or identify its entity and issue an API token owned by that entity.
- Enable Omni catalog access and any agreed file-upload content contracts.
- Configure the selected network-access path and the entity webhook destination.
- Issue a separate webhook signing token owned by the same entity.
The API token authenticates the entity. Percents resolves its current issuer association and checks that issuer's enabled capabilities on each request. The issuer determines which merchants, offers and agreed transaction-file formats are available.
Issuer scope is intentionally absent from request parameters:
GET /api/v1/omni/offer
Authorization: token tok_...:api_...The same entity-to-issuer authorization applies to resource-by-ID endpoints. If an offer or merchant UUID is not available to that issuer, the API returns 404 instead of revealing it.
For file uploads, the content query parameter selects an agreed processing contract and expected schema; it does not change the issuer scope.
For each environment, provide Percents with:
- the legal issuer and program name;
- a public HTTPS webhook URL; and
- the file content contract required by the integration.
Then select one network-access path:
- For source-IP allowlisting, provide stable outbound IP addresses or CIDR ranges.
- For mTLS, provide a CSR and follow Trusted Server Connection. Do not send the associated private key.
Percents returns the API token and webhook signing token through an approved secure channel. Store them separately.
Use sandbox credentials to list merchants and offers, then compare the returned catalog with the expected issuer configuration. Complete this check before accepting transaction files or launching production traffic.
If the catalog is empty or unexpected, stop and contact Percents. Do not try another issuer's token or add undocumented parameters to the request.