SMPs and Access Points
Arratech supports whitelabeling of access points (APs): an organisation can run its own accredited access points on Arratech's platform. What makes an access point accredited is the certificate Peppol issues for it. Organisations register their participants in Arratech's SMPs. Running your own SMP through the API is not available yet.
Modes and certificates
Every organisation starts in Demo (sandbox) mode. Only on request, and with Arratech's approval, can it run in Whitelabel or Shared mode. See Users, Members and Organisations.
- Shared mode. The organisation does not need its own certificates. It uses certificates from Arratech, or from a parent organisation if it has one.
- Whitelabel mode. The organisation uploads its own Peppol certificates. For production it must upload its own production certificate, then create an access point linked to it. Even in Whitelabel mode it can use Arratech's test certificates.
- Demo mode. Certificates cannot be uploaded.
Each certificate is flagged for one environment (test or production) and for one kind of service (access point or SMP).
Access points
The access point (AP) API gives you one interface for exchanging business documents securely across eDelivery networks. Peppol is the first supported network. The API is designed to support others later, such as DBNA and EESPA.
Every transaction follows the four-corner model of the network and travels over a standards-based transport, currently AS4, so delivery is signed and traceable. When you submit a transaction, the platform:
- validates the document, checking that the SBD and its header are well-formed and compliant
- resolves the recipient through network mechanisms such as Peppol's SML and SMP
- delivers it using the right certificate: yours in Whitelabel mode, Arratech's in Shared mode
- tracks delivery with message identifiers, status updates and evidence receipts where the network supports them
Each transaction belongs to one organisation. Transactions are logged and can be queried for auditing, reporting and operations.
Creating and managing access points matters in Whitelabel mode, where the organisation has to create its own. In every mode you can list the access points you may use, including Arratech's shared ones. Use that list to choose the access point when you create participants and send transactions.
SMPs
The Service Metadata Publisher (SMP) is a decentralised registry that publishes which document types a participant can receive and through which access point. Arratech hosts two SMPs, one for production and one for test. The list of SMPs your organisation may use is in the API reference.
An SMP has two parts.
Discovery APIs
These are read-only endpoints defined by the OpenPeppol SMP specification. Access points and service providers use them to find out what a participant can receive. Arratech's production SMP is at http://smp.arratech.com/.
Peppol requires an SMP's public address to be plain HTTP on port 80, and answers are XML as the specification defines. This address is separate from the Arratech API address.
Management APIs
These are specific to Arratech. You use them to register participants and manage their details.
Peppol describes service groups and service metadata, but it has no "participant". The Arratech API adds the participant as its own entity. It brings together everything about a participant: the access point documents go to, the document types it can receive, and details such as its business card, KYC data and status. You manage the supported document types on the participant. Behind the scenes Arratech keeps a fully Peppol-compliant SMP data model, so SML and standard XML discovery keep working.