Overview

Touchpoint API

The Touchpoint API is the member-facing API used by TRIFFT mobile apps, web widgets, and other customer touchpoints. Unlike the server-to-server Trifft API (API keys / OAuth), Touchpoint endpoints authenticate end-users with JWT access tokens.


Base URL

https://touchpoint-api.trifftloyalty.com

Authentication

Touchpoint endpoints authenticate members with JWT access tokens (ROLE_USER). Login and token refresh are public; all other endpoints require a valid member JWT.

Login

Call POST /v1/user/login with the member username and password. Include X-Trifft-ProjectId so the API can resolve the project (member emails and phones are unique per project, not globally):

X-Trifft-ProjectId: <project_id>

The response includes a JWT token and refresh_token. Subsequent protected requests send:

Authorization: Bearer <token>

The access token includes a project claim. When that claim is present, protected Touchpoint calls do not need X-Trifft-ProjectId.

When the access token expires, call POST /v1/user/token/refresh with the refresh token. Refresh still needs X-Trifft-ProjectId because the refresh request does not send the access token.

Session tokens from the Member API

You can issue the same JWT from the server-to-server Get a Member Session Tokens endpoint (GET /v1/member/{member_id}/session-tokens on the Trifft API). Use that token as Authorization: Bearer <token> on Touchpoint. Because the project is already in the JWT, those requests do not need X-Trifft-ProjectId.


Sections

SectionControllers / scope
AuthLogin, token refresh
UserProfile, registration, verification, addresses, identities
CardsPhysical/virtual cards, Apple/Google Wallet passes
CouponsList, detail, redeem/activate, deactivate
ContestsContest detail, tokens, draw, history
ConsentsList, HTML text, sign
NotificationsInbox list, mark read
PrivacyGDPR deletion / data export
TransactionsPOS/receipt history
Wallet TransactionsPrimary wallet point history
ParamsPublic custom-parameter definitions
PromoPromo-event code redemption

Response envelope

Most JSON endpoints return:

{
  "status": 200,
  "success": true,
  "data": {}
}

Error responses typically use:

{
  "status": 400,
  "success": false,
  "error": {
    "code": 1002,
    "message": "Human-readable message",
    "exception": "ExceptionClassName"
  }
}

A few endpoints intentionally differ:

EndpointNotes
POST /v1/user/loginReturns { "token", "refresh_token" }
POST /v1/user/token/refreshReturns refreshed JWT tokens
POST|PATCH /v1/notification/{id}/readHTTP 202 empty body
Consent text GET routesReturn text/html
Apple Wallet passReturns .pkpass binary

Deprecated endpoints

Prefer the dedicated resources below:

DeprecatedReplacement
POST /v1/user/wallet/transactionsPOST /v1/wallet-transactions
POST /v1/user/receiptsPOST /v1/transactions
GET /v1/user/receipt/{transactionId}GET /v1/transaction/{transactionId}
GET /v1/{entity}/paramsGET /v1/params