{
  "openapi": "3.1.0",
  "info": {
    "title": "CWallet Merchant API",
    "version": "1.1.0",
    "summary": "Accept USDT TRC20 payments on the Tron blockchain — Stripe-style API, sandbox + live environments.",
    "description": "CWallet is a USDT-native payments platform for Argentina and LATAM. This API lets you create payment intents, receive webhooks when customers pay, and reconcile transactions. The integration model mirrors Stripe: a backend creates intents server-side using a secret API key (`cwt_test_*` or `cwt_live_*`), a customer-facing UI shows a QR code that opens in the CWallet app, and the platform delivers a signed webhook when settlement happens.  Authentication: Bearer token in the `Authorization` header. The key prefix determines the environment (`cwt_test_` = sandbox, no real funds move; `cwt_live_` = production, real USDT TRC20).  Webhook signatures: HMAC-SHA256 of the raw body, using your `webhook_secret`, delivered in the `X-CWallet-Signature` header.",
    "termsOfService": "https://getcwallet.app/legal/terms",
    "contact": {
      "name": "CWallet Developers",
      "url": "https://getcwallet.app/developers",
      "email": "developers@getcwallet.app"
    },
    "license": {
      "name": "Proprietary",
      "url": "https://getcwallet.app/legal/terms"
    },
    "x-logo": {
      "url": "https://getcwallet.app/icon",
      "altText": "CWallet logo"
    }
  },
  "servers": [
    {
      "url": "https://getcwallet.app/api/v1",
      "description": "Production API (same endpoint for sandbox + live; the key prefix decides the mode)"
    }
  ],
  "tags": [
    {
      "name": "Payment Intents",
      "description": "Create and inspect payment intents."
    },
    {
      "name": "Webhooks",
      "description": "Event types fired to your webhook URL."
    },
    {
      "name": "Demo",
      "description": "Public demo endpoint used by the `/developers` page widget."
    }
  ],
  "paths": {
    "/create-payment-intent": {
      "post": {
        "tags": [
          "Payment Intents"
        ],
        "summary": "Create a payment intent",
        "description": "Creates a new payment intent on the terminal associated with the API key. Returns the intent id and a `checkout_uri` (the QR code the customer scans with the CWallet app). The environment is auto-detected from the API key prefix.",
        "operationId": "createPaymentIntent",
        "security": [
          {
            "BearerAuth": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreatePaymentIntentRequest"
              },
              "examples": {
                "basic": {
                  "value": {
                    "amount_usdt": 25.5
                  }
                },
                "smallAmount": {
                  "value": {
                    "amount_usdt": 1
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Payment intent created",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CreatePaymentIntentResponse"
                },
                "example": {
                  "success": true,
                  "message": "Payment intent created. Customer scans QR with CWallet app to pay.",
                  "terminal": "Caja principal",
                  "environment": "live",
                  "livemode": true,
                  "intent": {
                    "id": "11111111-2222-3333-4444-555555555555",
                    "amount_usdt": 25.5,
                    "status": "pending",
                    "expires_at": "2026-05-20T15:30:00Z",
                    "environment": "live",
                    "checkout_uri": "cwallet:pay?intent=11111111-2222-3333-4444-555555555555"
                  }
                }
              }
            }
          },
          "400": {
            "description": "Invalid amount_usdt or missing body",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Invalid API key or environment mismatch",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/intent-status": {
      "get": {
        "tags": [
          "Payment Intents"
        ],
        "summary": "Get the status of a payment intent",
        "description": "Public endpoint (no auth) — used by the browser checkout widget to poll until status changes from `pending` to `paid` or `expired`. Returns minimal non-sensitive data. Intent IDs are UUIDs so there is no enumeration risk.",
        "operationId": "getIntentStatus",
        "parameters": [
          {
            "name": "id",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            },
            "description": "Payment intent id"
          }
        ],
        "responses": {
          "200": {
            "description": "Current intent state",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/IntentStatus"
                }
              }
            }
          },
          "400": {
            "description": "Missing or invalid `id`"
          },
          "404": {
            "description": "Intent not found"
          }
        }
      }
    },
    "/demo-create-intent": {
      "post": {
        "tags": [
          "Demo"
        ],
        "summary": "Create a sandbox demo intent (public, no API key needed)",
        "description": "Used by the public widget demo on `/developers`. Creates a sandbox payment intent on the CWallet demo merchant and auto-simulates the payment 6 seconds later so the dev sees the full success flow. Rate-limited to 5 requests per minute per IP.",
        "operationId": "createDemoIntent",
        "responses": {
          "200": {
            "description": "Demo intent created",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "intent_id": {
                      "type": "string",
                      "format": "uuid"
                    },
                    "amount_usdt": {
                      "type": "number"
                    },
                    "environment": {
                      "type": "string",
                      "enum": [
                        "sandbox"
                      ]
                    },
                    "expires_at": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "auto_completes_in_ms": {
                      "type": "integer",
                      "example": 6000
                    }
                  }
                }
              }
            }
          },
          "429": {
            "description": "Rate limited (max 5 demo intents / minute per IP)"
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "BearerAuth": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "cwt_test_… or cwt_live_…",
        "description": "Terminal API key from `/dashboard/business`. Prefix decides environment: `cwt_test_` for sandbox (no real funds), `cwt_live_` for production (USDT TRC20)."
      }
    },
    "schemas": {
      "CreatePaymentIntentRequest": {
        "type": "object",
        "required": [
          "amount_usdt"
        ],
        "properties": {
          "amount_usdt": {
            "type": "number",
            "minimum": 0.000001,
            "description": "Amount in USDT (TRC20). Up to 6 decimals.",
            "example": 25.5
          }
        }
      },
      "CreatePaymentIntentResponse": {
        "type": "object",
        "properties": {
          "success": {
            "type": "boolean"
          },
          "message": {
            "type": "string"
          },
          "terminal": {
            "type": "string",
            "description": "Human-readable name of the terminal"
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "intent": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string",
                "format": "uuid"
              },
              "amount_usdt": {
                "type": "number"
              },
              "status": {
                "type": "string",
                "enum": [
                  "pending",
                  "paid",
                  "expired",
                  "cancelled"
                ]
              },
              "expires_at": {
                "type": "string",
                "format": "date-time"
              },
              "environment": {
                "type": "string",
                "enum": [
                  "sandbox",
                  "live"
                ]
              },
              "checkout_uri": {
                "type": "string",
                "description": "cwallet:pay?intent=… deep link for the QR code"
              }
            }
          }
        }
      },
      "IntentStatus": {
        "type": "object",
        "required": [
          "id",
          "status",
          "amount_usdt",
          "environment",
          "livemode",
          "expires_at"
        ],
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "amount_usdt": {
            "type": "number"
          },
          "status": {
            "type": "string",
            "enum": [
              "pending",
              "paid",
              "expired",
              "cancelled"
            ]
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "Error": {
        "type": "object",
        "properties": {
          "error": {
            "type": "string",
            "description": "Human-readable error message"
          },
          "code": {
            "type": "string",
            "description": "Stable error code for programmatic handling"
          }
        }
      },
      "WebhookHeaders": {
        "type": "object",
        "description": "Headers included on every webhook POST. Verify `X-CWallet-Signature` (HMAC-SHA256 of raw body using your webhook_secret) before processing.",
        "properties": {
          "X-CWallet-Signature": {
            "type": "string",
            "description": "HMAC-SHA256 of the raw body, hex-encoded"
          },
          "X-CWallet-Event": {
            "type": "string",
            "description": "Event type (also in body.event)"
          },
          "X-CWallet-Event-Id": {
            "type": "string",
            "format": "uuid"
          },
          "X-CWallet-Environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "X-CWallet-Livemode": {
            "type": "string",
            "enum": [
              "true",
              "false"
            ]
          }
        }
      },
      "WebhookEventPaymentSuccess": {
        "type": "object",
        "description": "Fired when a payment intent is paid (live: real USDT settled; sandbox: simulated).",
        "properties": {
          "event": {
            "type": "string",
            "enum": [
              "payment.success"
            ]
          },
          "intent_id": {
            "type": "string",
            "format": "uuid"
          },
          "transfer_id": {
            "type": "string",
            "format": "uuid",
            "nullable": true
          },
          "amount": {
            "type": "number"
          },
          "currency": {
            "type": "string",
            "enum": [
              "USDT",
              "CWT"
            ]
          },
          "terminal_id": {
            "type": "string",
            "format": "uuid"
          },
          "terminal_name": {
            "type": "string"
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "simulated": {
            "type": "boolean"
          },
          "timestamp": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "WebhookEventIntentCreated": {
        "type": "object",
        "description": "Fired when a new payment intent is created (useful for syncing dashboards).",
        "properties": {
          "event": {
            "type": "string",
            "enum": [
              "intent.created"
            ]
          },
          "intent_id": {
            "type": "string",
            "format": "uuid"
          },
          "amount": {
            "type": "number"
          },
          "currency": {
            "type": "string",
            "enum": [
              "USDT"
            ]
          },
          "terminal_id": {
            "type": "string",
            "format": "uuid"
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          },
          "checkout_uri": {
            "type": "string"
          },
          "timestamp": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "WebhookEventPaymentExpired": {
        "type": "object",
        "description": "Fired when a pending payment intent reaches its expiry without being paid.",
        "properties": {
          "event": {
            "type": "string",
            "enum": [
              "payment.expired"
            ]
          },
          "intent_id": {
            "type": "string",
            "format": "uuid"
          },
          "amount": {
            "type": "number"
          },
          "currency": {
            "type": "string",
            "enum": [
              "USDT"
            ]
          },
          "terminal_id": {
            "type": "string",
            "format": "uuid"
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "timestamp": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "WebhookEventKeyRotated": {
        "type": "object",
        "description": "Fired when an API key is rotated from the merchant dashboard.",
        "properties": {
          "event": {
            "type": "string",
            "enum": [
              "key.rotated"
            ]
          },
          "terminal_id": {
            "type": "string",
            "format": "uuid"
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "rotated_at": {
            "type": "string",
            "format": "date-time"
          },
          "last4": {
            "type": "string",
            "description": "Last 4 chars of the new key"
          }
        }
      },
      "WebhookEventTestPing": {
        "type": "object",
        "description": "Sent on demand from the dashboard \"Probar webhook\" button so developers can validate their endpoint.",
        "properties": {
          "event": {
            "type": "string",
            "enum": [
              "test.ping"
            ]
          },
          "message": {
            "type": "string"
          },
          "request_id": {
            "type": "string",
            "format": "uuid"
          },
          "environment": {
            "type": "string",
            "enum": [
              "sandbox",
              "live"
            ]
          },
          "livemode": {
            "type": "boolean"
          },
          "timestamp": {
            "type": "string",
            "format": "date-time"
          }
        }
      }
    }
  }
}