{"templateId":"markdown","versions":[{"version":"1.0","label":"1.0","link":"/omni-api/1.0/overview/issuer-setup","default":false,"active":false,"folderId":"6bec560c"},{"version":"1.1","label":"1.1","link":"/omni-api/1.1/overview/issuer-setup","default":false,"active":false,"folderId":"6bec560c"},{"version":"1.2","label":"1.2","link":"/omni-api/overview/issuer-setup","default":true,"active":true,"folderId":"6bec560c"}],"sharedDataIds":{"sidebar":"sidebar-omni-api/@1.0/overview/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Issuer setup"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"issuer-setup","__idx":0},"children":["Issuer setup"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Every Omni request is scoped to the issuer associated with the authenticated entity. Percents completes issuer setup during onboarding. Clients do not send an issuer ID or a scope override in a request."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-percents-configures","__idx":1},"children":["What Percents configures"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Percents completes these steps separately in sandbox and production:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create or identify the issuer account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create or identify its entity and issue an API token owned by that entity."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enable Omni catalog access and any agreed file-upload content contracts."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Configure the selected network-access path and the entity webhook destination."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Issue a separate webhook signing token owned by the same entity."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The API token authenticates the entity. Percents resolves its current issuer association and checks that issuer's enabled capabilities on each request. The issuer determines which merchants, offers and agreed transaction-file formats are available."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"request-behavior","__idx":2},"children":["Request behavior"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Issuer scope is intentionally absent from request parameters:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"http","header":{"controls":{"copy":{}}},"source":"GET /api/v1/omni/offer\nAuthorization: token tok_...:api_...\n","lang":"http"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The same entity-to-issuer authorization applies to resource-by-ID endpoints. If an offer or merchant UUID is not available to that issuer, the API returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["404"]}," instead of revealing it."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For file uploads, the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["content"]}," query parameter selects an agreed processing contract and expected schema; it does not change the issuer scope."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"onboarding-information-to-provide","__idx":3},"children":["Onboarding information to provide"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For each environment, provide Percents with:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the legal issuer and program name;"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["a public HTTPS webhook URL; and"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the file content contract required by the integration."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Then select one network-access path:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For source-IP allowlisting, provide stable outbound IP addresses or CIDR ranges."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For mTLS, provide a CSR and follow ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/omni-api/overview/mtls-access"},"children":["Trusted Server Connection"]},". Do not send the associated private key."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Percents returns the API token and webhook signing token through an approved secure channel. Store them separately."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"validate-issuer-scope","__idx":4},"children":["Validate issuer scope"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use sandbox credentials to list merchants and offers, then compare the returned catalog with the expected issuer configuration. Complete this check before accepting transaction files or launching production traffic."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the catalog is empty or unexpected, stop and contact Percents. Do not try another issuer's token or add undocumented parameters to the request."]}]},"headings":[{"value":"Issuer setup","id":"issuer-setup","depth":1},{"value":"What Percents configures","id":"what-percents-configures","depth":2},{"value":"Request behavior","id":"request-behavior","depth":2},{"value":"Onboarding information to provide","id":"onboarding-information-to-provide","depth":2},{"value":"Validate issuer scope","id":"validate-issuer-scope","depth":2}],"frontmatter":{"seo":{"title":"Issuer setup"}},"lastModified":"2026-10-02T20:53:32.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/omni-api/overview/issuer-setup","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}