Installing CAP on R700
Step-by-step guide to installing Titan CAP on an Impinj R700 reader.
Prerequisites
- Reader: Impinj R700 rev 2 (64-bit ARM)
- Firmware: 10.0.0 or later
- Access: Reader's web UI at
https://<reader-ip>/(default username:root) - CAP Mode: Set to "Open" (Settings → CAP)
Before You Start
CAP requires identity files in /cust/rw_dir/ to connect to Titan's MQTT broker. You have two paths:
- Wonder-Shipped Reader: Identity already installed at bench before shipping. Skip to step 4.
- BYO (Bring-Your-Own): Identity must be provisioned. See Provisioning Identity after CAP install.
Step 1: Download CAP
Get the latest CAP .upgx file:
- From Wonder: Contact support for latest build
- From Titan: (future) Published release artifacts distributed with your Titan package or support portal
Current version: CAP 0.1.6.0 (titan-agent-0.1.6.0.upgx)
Step 2: Set CAP Install Mode to Open
- Open reader web UI:
https://<reader-ip>/ - Log in (default: username
root, password from reader label) - Navigate to Settings → CAP
- Set CAP Install Mode to Open
- Click Save
What this does: Allows unsigned CAP applications to install. Titan CAP is not Impinj-signed.
Step 3: Upload CAP
- In reader web UI, go to Apps → Custom Applications
- Click Upload Application
- Select
titan-agent-0.1.6.0.upgxfile - Application Name:
Titan Agent - Persistent Data: Select rw_dir (critical - this makes identity files survive upgrades)
- Click Upload
Upload takes ~30 seconds. Reader will show CAP in the applications list.
Step 4: Start CAP
- In Apps → Custom Applications, find Titan Agent
- Click Start
- Status changes to Running
First start will fail if identity files are missing. CAP log will show:
ERROR: Cannot read /cust/rw_dir/titan.json
ERROR: Cannot read /cust/rw_dir/ca.crt
This is expected if you haven't provisioned identity yet.
Step 5: Verify CAP is Running
Check CAP log in reader web UI:
- Apps → Titan Agent → View Log
Healthy log shows:
INFO: Titan Agent 0.1.6.0 starting
INFO: Read identity from /cust/rw_dir/
INFO: Connecting to mqtt.titanrfid.com:8883
INFO: Connected, subscribing to titan/v1/370-xx-xx-xxxx-xxxx/commands
INFO: Ready
If CAP crash-loops (restarts every few seconds):
- Check firmware version (must be 10.0.0+)
- Check libstdc++ compatibility (0.1.6.0 should work; earlier versions had issues)
- Check that Persistent Data is set to
rw_dir(notnone)
Provisioning Identity
CAP is installed but won't connect without identity files in /cust/rw_dir/.
Option A: Wonder-Shipped (Current Model)
If reader was shipped by Wonder, identity is already installed. Skip this section.
Option B: BYO Manual Provisioning (For Lab/Dev)
For lab or development readers, manually create identity files:
- Generate or obtain from Titan Cloud:
ca.crt- Titan Cloud CA certificate (PEM)client.crt- Reader's client cert (CN is reader serial / device identity)client.key- Matching private keytitan.json- Reader REST credentials
-
Copy to reader (via reader's REST API or file upload):
# Example using reader REST API (requires admin credentials)curl -k -u root:<password> -X POST \https://<reader-ip>/api/v1/files/cust/rw_dir/ca.crt \--data-binary @ca.crtcurl -k -u root:<password> -X POST \https://<reader-ip>/api/v1/files/cust/rw_dir/client.crt \--data-binary @client.crtcurl -k -u root:<password> -X POST \https://<reader-ip>/api/v1/files/cust/rw_dir/client.key \--data-binary @client.keycurl -k -u root:<password> -X POST \https://<reader-ip>/api/v1/files/cust/rw_dir/titan.json \--data-binary @titan.json -
Set permissions (client.key must be 0600):
curl -k -u root:<password> -X PUT \https://<reader-ip>/api/v1/files/cust/rw_dir/client.key \-d '{"mode":"0600"}' -
Restart CAP:
- In reader web UI: Apps → Titan Agent → Restart
Option C: BYO Claim-and-Pull (Designed, Not Built)
Future: Customer will claim reader via hub.titanrfid.com, receive a claim token, and CAP will pull identity automatically.
Planned architecture is documented in the internal security design (not published on this site). Not available yet - awaiting Security approval.
Step 6: Confirm CAP Connects
Once identity is provisioned:
- Restart CAP (web UI → Restart)
- Check CAP log - should show:
INFO: Connected to brokerINFO: Subscribed to titan/v1/{serial}/commands
- In Titan hub UI, reader status should show Online
- Start/Stop buttons should work (if not, see Troubleshooting)
Upgrading CAP
To upgrade to a new version:
- Download new
.upgxfile - In reader web UI: Apps → Titan Agent → Upload New Version
- Select new
.upgxfile - Persistent Data: Ensure rw_dir is selected (keeps identity files)
- Upload → Reader will stop old version, install new, start new
Identity files are preserved because Persistent Data = rw_dir. No need to re-provision after upgrade.
Uninstalling CAP
To remove CAP:
- In reader web UI: Apps → Titan Agent → Uninstall
- Confirm uninstall
If Persistent Data = rw_dir, identity files remain on reader. To fully wipe:
- Use reader config-image mode
removecap - OR manually delete files via REST API:
DELETE /api/v1/files/cust/rw_dir/*
Troubleshooting
CAP Won't Start
- Check firmware version: Must be 10.0.0 or later
- Check CAP log: Look for
libstdc++errors (upgrade to CAP 0.1.6.0) - Check install mode: Must be "Open"
CAP Running But Not Connecting
- Check identity files: All 4 must exist in
/cust/rw_dir/ - Check ca.crt: Must be Titan Cloud CA, not reader's self-signed cert
- Check client.crt CN: Must match reader's serial number
- Check firewall: Reader must reach
mqtt.titanrfid.com:8883(outbound TLS)
Start/Stop Buttons Don't Work
- Check CAP is running: Web UI → Apps → Status should be "Running"
- Check CAP log: Should show
Subscribed to titan/v1/{serial}/commands - Check hub UI: Reader status should be "Online" (not "Degraded" or "Offline")
- Check command topic: CAP subscribes to
titan/v1/{serial}/commands(serial in topic must match reader's actual serial)
Reader Offline After Reboot
- Check Persistent Data setting: Must be
rw_dir(notnone) - Check identity files survived reboot: SSH or REST API to verify
/cust/rw_dir/still has files
"Permission Denied" on client.key
- Fix: Set file mode to 0600:
curl -k -u root:<password> -X PUT \https://<reader-ip>/api/v1/files/cust/rw_dir/client.key \-d '{"mode":"0600"}'
Next Steps
- CAP Identity - Understanding how identity files are provisioned
- CAP Operations - Day-to-day management, logs, upgrades
- Troubleshooting - Full troubleshooting guide