# Switstack > Switstack builds software-defined EMV acceptance infrastructure for physical retail. Three products: switstack moka > (a source-available EMV Level 2 kernel stack with brand Letters of Compliance), Switcloud (hosted estate + EMV > configuration + payment APIs that abstract L2 execution), and Swittest (a managed EMV functional test-automation > service). The platform is terminal-agnostic and L2-stack agnostic: one L3 application runs across Android COTS > tap-to-pay devices and PCI-PTS terminals through a GLA adapter layer. GENERATED by API Evangelist on 2026-08-17. Switstack does not publish an llms.txt of its own (https://www.switstack.io/llms.txt and https://docs.switstack.io/llms.txt both return 404), so this file is assembled from the company's public documentation and the two OpenAPI documents harvested from its API reference. It is a third-party summary, not a Switstack artifact. ## What to know before calling anything - Two REST APIs are published as complete OpenAPI 3.1.0 documents: **Switcloud API 2.28.0** (106 operations, 40 paths) and **Swittest API 0.13.0** (22 operations). Both are FastAPI-generated and share one convention set. - Auth is OAuth 2.0 bearer on both. `POST /auth/token` with `grant_type=password` (or `client_credentials` for machine users) returns `access_token` / `token_type: bearer` / `expires_in: 3600`. Send `Authorization: Bearer `. `/auth/refresh-token` and `/auth/revoke-token` complete the lifecycle. There are **no OAuth scopes** — authorization is role-based (Super Admin / Organization Admin / Simple User on Switcloud; Data / Full on Swittest). - Neither API is self-serve. You need an organization and user provisioned by Switstack, and the Switcloud sandbox plus the Switstack packages repository are granted by sales/support. Requests go to contact@switstack.io. - The documented Switcloud base URL is `https://switcloud.switstack.io` — it did not resolve in public DNS when probed on 2026-08-17. Swittest runs as separate per-customer instances with no shared base URL. The **contracts** are public; the **runtime** is per-tenant. - **No idempotency key** is published, including on `create_payment`. A retry creates a second Payment. - The only declared error is **HTTP 422** with the FastAPI envelope `{"detail":[{"loc","msg","type"}]}`. 401, 403, 404, 409, 429 and 5xx are undeclared. Transaction failure arrives in a 200 body via `Payment.outcome_status` (DECLINED / END_APPLICATION / TRY_AGAIN / TRY_ANOTHER_INTERFACE) and `Payment.state`. - **No rate limits** are documented and no rate-limit headers are declared. - Switcloud collections page with `page` + `size` and return `{items,total,page,size,pages}`. `with_related=true` expands nested objects; `organization_id`, `search` and `order_by` are available on every list operation. - The homepage advertises an "MCP-based Payment Workflow" for agent-initiated payments. **No MCP server exists**: no endpoint, no docs page, and every candidate host is NXDOMAIN. Treat the REST APIs as the only callable surface. ## APIs - [Switcloud API](https://docs.switstack.io/switcloud/): estate (merchants, stores, POIs), EMV L2 configuration (BINs, CAPKs, CRs, EMV parameter sets, and the POIConfig bundle a terminal fetches at runtime), and payments (lifecycle plus log data sets with trace/APDU/telemetry). - [Switcloud API reference](https://docs.switstack.io/api/switcloud/api/switcloud-srv/): the full Redoc reference. - [Swittest API](https://docs.switstack.io/swittest/): test-suite/test discovery, streaming test execution (SSE), scope verification, and TLV/tag/Eval+ log parsers. - [Swittest API reference](https://docs.switstack.io/api/swittest/api/swittest-srv/): the full Redoc reference. - [moka API reference](https://docs.switstack.io/api/moka/moka/): Doxygen reference for the on-device EMV L2 stack (C), including the Generic Level 2 API (GLA). ## Specs (harvested by API Evangelist) - [Switcloud OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/switstack/refs/heads/main/openapi/switstack-switcloud-openapi.yml) - [Swittest OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/switstack/refs/heads/main/openapi/switstack-swittest-openapi.yml) - [Verbatim Switcloud source document](https://raw.githubusercontent.com/api-evangelist/switstack/refs/heads/main/openapi/_original/switstack-switcloud-openapi.json) - [Verbatim Swittest source document](https://raw.githubusercontent.com/api-evangelist/switstack/refs/heads/main/openapi/_original/switstack-swittest-openapi.json) ## Docs - [Switstack knowledge base](https://docs.switstack.io/) - [Switcloud getting started](https://docs.switstack.io/switcloud/getting_started/) - [Switcloud security & authentication](https://docs.switstack.io/switcloud/security_authentication/) - [Switcloud architecture](https://docs.switstack.io/switcloud/architecture/) - [Switcloud key concepts](https://docs.switstack.io/switcloud/key_concepts/) - [Processing payments](https://docs.switstack.io/switcloud/processing_payments/) - [Estate management](https://docs.switstack.io/switcloud/estate_management/) - [Certification overview](https://docs.switstack.io/switcloud/certification_overview/) - [Switcloud FAQ](https://docs.switstack.io/switcloud/faq/) - [Swittest setup](https://docs.switstack.io/swittest/setup/) - [Swittest CLI](https://docs.switstack.io/swittest/cli/) - [Swittest architecture & integration](https://docs.switstack.io/swittest/architecture/) - [moka getting started](https://docs.switstack.io/moka/getting_started/) - [moka security](https://docs.switstack.io/moka/security/) - [switstack moka license](https://docs.switstack.io/moka/license/) ## Packages Switstack publishes nothing to npm, PyPI or Maven Central. Its Kotlin/Android artifacts live in a first-party Sonatype Nexus at `https://public-nexus.switstack.io/repository/switstack-mvn`, which serves `maven-metadata.xml` and POM/JAR anonymously. - `io.switstack.switcloud:switcloud-clt-kt` — Switcloud Client (configure/startPayment/completePayment) — 2.4.0, 2026-07-30 - `io.switstack.switcloud:switcloud-l2-kt` — GLA adapter to the device's EMV L2 framework — 2.2.0, 2026-07-29 - `io.switstack.switcloud:switcloud-api-kt` — REST wrapper — 2.28.6, 2026-05-13 - Python/TypeScript wrappers and `swittest-cli` are distributed from the same Nexus behind credentials; versions are not publicly readable. ## Repositories - [GitHub org](https://github.com/switstack) - [switstack-issues](https://github.com/switstack/switstack-issues) — the public support channel - [switcloud-l2-template-kt](https://github.com/switstack/switcloud-l2-template-kt) — implement ISwitcloudL2 / IGlase against your own kernels - [switcloud-l3-template-kt](https://github.com/switstack/switcloud-l3-template-kt) - [swittest-l3-template-kt](https://github.com/switstack/swittest-l3-template-kt) — the device-under-test app - [switcloud-l2-demo-kt](https://github.com/switstack/switcloud-l2-demo-kt) ## Company - [Website](https://www.switstack.io/) - [About](https://www.switstack.io/about) - [Use cases](https://www.switstack.io/use-cases) - [Blog](https://www.switstack.io/blog) ([RSS](https://www.switstack.io/blog/rss.xml)) - [Get started / contact](https://www.switstack.io/get-started) ## Not published Recorded so an agent does not hunt for them: no pricing page (`/pricing` returns 404), no terms of service, no privacy policy, no changelog or release notes, no status page, no SLA, no security.txt, no vulnerability-disclosure page, no trust center or named certifications (SOC 2 / ISO 27001 / PCI DSS), no `/.well-known/*` document on any host, no agent card, no MCP server, no GraphQL, no gRPC/protobuf, no AsyncAPI, no webhooks, no Postman collection, and no published rate limits.