Skip to main content

Installing CAP on R700

Step-by-step guide to installing Titan CAP on an Impinj R700 reader.

Prerequisites​

  • Reader: Impinj R700 rev 2 (64-bit ARM)
  • Firmware: 10.0.0 or later
  • Access: Reader's web UI at https://<reader-ip>/ (default username: root)
  • CAP Mode: Set to "Open" (Settings → CAP)

Before You Start​

CAP requires identity files in /cust/rw_dir/ to connect to Titan's MQTT broker. You have two paths:

  1. Wonder-Shipped Reader: Identity already installed at bench before shipping. Skip to step 4.
  2. BYO (Bring-Your-Own): Identity must be provisioned. See Provisioning Identity after CAP install.

Step 1: Download CAP​

Get the latest CAP .upgx file:

  • From Wonder: Contact support for latest build
  • From Titan: (future) Published release artifacts distributed with your Titan package or support portal

Current version: CAP 0.1.6.0 (titan-agent-0.1.6.0.upgx)

Step 2: Set CAP Install Mode to Open​

  1. Open reader web UI: https://<reader-ip>/
  2. Log in (default: username root, password from reader label)
  3. Navigate to Settings → CAP
  4. Set CAP Install Mode to Open
  5. Click Save

What this does: Allows unsigned CAP applications to install. Titan CAP is not Impinj-signed.

Step 3: Upload CAP​

  1. In reader web UI, go to Apps → Custom Applications
  2. Click Upload Application
  3. Select titan-agent-0.1.6.0.upgx file
  4. Application Name: Titan Agent
  5. Persistent Data: Select rw_dir (critical - this makes identity files survive upgrades)
  6. Click Upload

Upload takes ~30 seconds. Reader will show CAP in the applications list.

Step 4: Start CAP​

  1. In Apps → Custom Applications, find Titan Agent
  2. Click Start
  3. Status changes to Running

First start will fail if identity files are missing. CAP log will show:

ERROR: Cannot read /cust/rw_dir/titan.json
ERROR: Cannot read /cust/rw_dir/ca.crt

This is expected if you haven't provisioned identity yet.

Step 5: Verify CAP is Running​

Check CAP log in reader web UI:

  • Apps → Titan Agent → View Log

Healthy log shows:

INFO: Titan Agent 0.1.6.0 starting
INFO: Read identity from /cust/rw_dir/
INFO: Connecting to mqtt.titanrfid.com:8883
INFO: Connected, subscribing to titan/v1/370-xx-xx-xxxx-xxxx/commands
INFO: Ready

If CAP crash-loops (restarts every few seconds):

  • Check firmware version (must be 10.0.0+)
  • Check libstdc++ compatibility (0.1.6.0 should work; earlier versions had issues)
  • Check that Persistent Data is set to rw_dir (not none)

Provisioning Identity​

CAP is installed but won't connect without identity files in /cust/rw_dir/.

Option A: Wonder-Shipped (Current Model)​

If reader was shipped by Wonder, identity is already installed. Skip this section.

Option B: BYO Manual Provisioning (For Lab/Dev)​

For lab or development readers, manually create identity files:

  1. Generate or obtain from Titan Cloud:
  • ca.crt - Titan Cloud CA certificate (PEM)
  • client.crt - Reader's client cert (CN is reader serial / device identity)
  • client.key - Matching private key
  • titan.json - Reader REST credentials
  1. Copy to reader (via reader's REST API or file upload):

    # Example using reader REST API (requires admin credentials)
    curl -k -u root:<password> -X POST \
    https://<reader-ip>/api/v1/files/cust/rw_dir/ca.crt \
    --data-binary @ca.crt

    curl -k -u root:<password> -X POST \
    https://<reader-ip>/api/v1/files/cust/rw_dir/client.crt \
    --data-binary @client.crt

    curl -k -u root:<password> -X POST \
    https://<reader-ip>/api/v1/files/cust/rw_dir/client.key \
    --data-binary @client.key

    curl -k -u root:<password> -X POST \
    https://<reader-ip>/api/v1/files/cust/rw_dir/titan.json \
    --data-binary @titan.json
  2. Set permissions (client.key must be 0600):

    curl -k -u root:<password> -X PUT \
    https://<reader-ip>/api/v1/files/cust/rw_dir/client.key \
    -d '{"mode":"0600"}'
  3. Restart CAP:

    • In reader web UI: Apps → Titan Agent → Restart

Option C: BYO Claim-and-Pull (Designed, Not Built)​

Future: Customer will claim reader via hub.titanrfid.com, receive a claim token, and CAP will pull identity automatically.

Planned architecture is documented in the internal security design (not published on this site). Not available yet - awaiting Security approval.

Step 6: Confirm CAP Connects​

Once identity is provisioned:

  1. Restart CAP (web UI → Restart)
  2. Check CAP log - should show:
    INFO: Connected to broker
    INFO: Subscribed to titan/v1/{serial}/commands
  3. In Titan hub UI, reader status should show Online
  4. Start/Stop buttons should work (if not, see Troubleshooting)

Upgrading CAP​

To upgrade to a new version:

  1. Download new .upgx file
  2. In reader web UI: Apps → Titan Agent → Upload New Version
  3. Select new .upgx file
  4. Persistent Data: Ensure rw_dir is selected (keeps identity files)
  5. Upload → Reader will stop old version, install new, start new

Identity files are preserved because Persistent Data = rw_dir. No need to re-provision after upgrade.

Uninstalling CAP​

To remove CAP:

  1. In reader web UI: Apps → Titan Agent → Uninstall
  2. Confirm uninstall

If Persistent Data = rw_dir, identity files remain on reader. To fully wipe:

  • Use reader config-image mode removecap
  • OR manually delete files via REST API: DELETE /api/v1/files/cust/rw_dir/*

Troubleshooting​

CAP Won't Start​

  • Check firmware version: Must be 10.0.0 or later
  • Check CAP log: Look for libstdc++ errors (upgrade to CAP 0.1.6.0)
  • Check install mode: Must be "Open"

CAP Running But Not Connecting​

  • Check identity files: All 4 must exist in /cust/rw_dir/
  • Check ca.crt: Must be Titan Cloud CA, not reader's self-signed cert
  • Check client.crt CN: Must match reader's serial number
  • Check firewall: Reader must reach mqtt.titanrfid.com:8883 (outbound TLS)

Start/Stop Buttons Don't Work​

  • Check CAP is running: Web UI → Apps → Status should be "Running"
  • Check CAP log: Should show Subscribed to titan/v1/{serial}/commands
  • Check hub UI: Reader status should be "Online" (not "Degraded" or "Offline")
  • Check command topic: CAP subscribes to titan/v1/{serial}/commands (serial in topic must match reader's actual serial)

Reader Offline After Reboot​

  • Check Persistent Data setting: Must be rw_dir (not none)
  • Check identity files survived reboot: SSH or REST API to verify /cust/rw_dir/ still has files

"Permission Denied" on client.key​

  • Fix: Set file mode to 0600:
    curl -k -u root:<password> -X PUT \
    https://<reader-ip>/api/v1/files/cust/rw_dir/client.key \
    -d '{"mode":"0600"}'

Next Steps​