Back to FitmentIndustries.com
Part of the Enthusiast Enterprises Family Sign In
Board briefing · The full integration plan · companions: Architecture · Team & Ops · Costs · Data Map
01 · The Full Integration Map

Where the Exchange plugs into EEI.

Five groups, ordered by launch criticality. Direction says who calls whom; everything server-to-server is authenticated service-to-service — the browser never touches these APIs directly.

Identity — one enthusiast, every site

IntegrationDirectionHowPhase
Single sign-onExchange → EEI IdPEEI identity provider speaking OpenID Connect; Sharetribe consumes it natively. One login for FI, CO & Exchange.Launch
Account linking (existing customers)One-time migrationFirst SSO login matches on verified email → links or creates the marketplace account; unverified emails get a claim flow, never silent merges.Launch
Profile & garage syncEEI → ExchangeDisplay name, avatar, saved vehicles → Sharetribe user extended data (powers "fits my car" + gallery links).Launch
Session / logout policyDecisionSingle credential, per-site sessions. Decide: does logging out of FI end the Exchange session? (Recommend: no — independent sessions, shared login.)Decide wk 1

Money — the wallet (see §02) + settlement

IntegrationDirectionHowPhase
Store-credit walletBoth waysTHE decision — two architectures compared below. Either way: Sharetribe Integration API event on sale completion → credit accrues; EEI checkouts redeem.Launch
Settlement & reconciliationExchange → EEI financeNightly ledger export (sales, escrow state, credits issued/redeemed, cash-outs) → data warehouse; three-way reconcile vs Stripe + Sharetribe.Launch
Tax feedExchange → tax engineMarketplace-facilitator sales into the existing engine/filings; confirm current state registrations cover P2P (they likely do).Launch
Refund / claims money-pathOps runbookClaims resolve inside Stripe (escrow never released); credit clawbacks only for post-release reversals — rare, dual-control required.Fast follow

Data — our moat feeding their platform

IntegrationDirectionHowPhase
Catalog spec serviceExchange → EEI catalogRead API: brand/model → size, offset, bolt pattern, bore, weight, MSRP. Powers listing prefill AND the automated spec-check bot.Launch
Fitment / YMMExchange → EEI fitmentThe same engine FI/CO use — called as a service, not copied. Vehicle → spec envelope → marketplace search filters at launch; fast-follow: spec-check stamps per-listing fitment metadata for instant "fits your car" chips + gallery-verified-on-your-chassis badges.Launch
Plate / VIN decodeExchange → vendorSame third-party decode service class retail uses; feeds the YMM finder.Fast follow
Gallery cross-linksBoth waysListing stores gallery build ID; gallery builds show "parts for sale" chips. Deep links both directions.Fast follow
Sold-comps pricing dataInternalExchange sale history → "what's it worth" bands; seeded from retail pricing until organic volume exists.Post-launch

Commerce — the flywheel touchpoints

IntegrationDirectionHowPhase
Cross-site navigationStaticSuperheader links both ways (already designed in this demo).Launch
Email / ESP audience syncExchange → ESPExchange signups + saved-search alerts into the existing email platform; suppression lists honored both ways.Fast follow
Analytics & attributionBoth → warehouseShared analytics property or rollup; tag credit-funded retail orders so the flywheel is measurable ("Exchange drove $X of new-parts revenue").Launch
Checkout add-on upsells (FI-fulfilled items in a peer order)Exchange → FI OMSCustom line items + order relay into FI fulfillment — real integration work, scoped separately.Roadmap

Operations — the humans and the boxes

IntegrationDirectionHowPhase
Shipping labels + trackingBoth waysEasyPost/Shippo on our carrier accounts; purchase on payment, tracking webhook fires the delivered→inspection transition.Launch
Support toolingEEI support → ExchangeExisting support team gets Sharetribe Console access + order-lookup; one phone number, both businesses (as the demo's help page already promises).Launch
Fraud & risk signalsBoth waysShared device/email blocklists across properties; Exchange KYC status visible to risk tooling.Fast follow
02 · The Wallet Decision

Universal wallet: two ways to build it.

Sellers earn credit on the Exchange and spend it at FI, CO, and every EEI storefront. The question is who owns the ledger.

Option A · Central EEI Wallet Service

One ledger, every property integrates

A new standalone wallet service inside EEI infrastructure. FI cart, CO cart, and the Exchange all call it. The Exchange is just one credit source among future ones (returns, promos, loyalty).

  • Cleanest long-term: one balance, one truth, every future program plugs in
  • Cost: new service PLUS integration into both retail carts before launch
  • Puts the wallet on the critical path of the shared cart — the codebase we're deliberately not touching
Option B · Exchange-side Wallet + Balance API (recommended start)

We own the ledger, EEI sites call our API

The Exchange's server-side service owns the credit ledger (it's the only credit source at launch anyway). EEI checkouts call our API to check balance, place a hold, and capture on order completion.

  • Fastest to launch: retail carts only add a "redeem credit" call at checkout — no new shared infrastructure
  • Exchange accrual is internal (same service that hears the Sharetribe webhook)
  • Risk to manage: don't let it fragment — see the callout
Recommendation

Build B with A's contract. Ship the Exchange-side ledger, but design the API as if it were the universal wallet from day one — property-agnostic endpoints (balance · authorize-hold · capture · release · statement), no Exchange-specific assumptions. If EEI later stands up a central wallet service, it adopts the same contract and the retail carts never change a line. The decision that must be made this week: does the shared cart already have any store-credit/gift-card ledger? If yes, Option B's API wraps it instead.

03 · Wallet Security Model

"Insanely secure," specified.

Store credit is cash-equivalent. These aren't nice-to-haves — they're the build spec for the wallet API, whichever option wins.

Server-to-server only

Browsers never call the wallet API. Only site backends do, over mTLS + short-lived, audience-scoped JWTs (OAuth2 client-credentials, one client per property, least-privilege scopes).

Append-only double-entry ledger

No balance field to overwrite — balance is derived from immutable entries. Every entry carries actor, source event, and hash-chain to its predecessor. Adjustments are new entries, never edits.

Two-phase redemption

Authorize-hold → capture on order completion; auto-release on timeout or cancel. Idempotency keys on every mutation — a retried request can never double-spend or double-credit.

Signed webhooks, replay-proof

Credit accrual fires from the Sharetribe completion event: HMAC-signed, timestamped, nonce-tracked — a replayed or forged webhook mints nothing.

Human controls

Manual adjustments require dual approval; full audit log of every read and write; secrets in a vault with rotation; access reviews. SOC2-style controls even before a SOC2.

Fraud & abuse limits

Velocity limits on accrual and redemption, anomaly alerts, device fingerprint on redemption, KYC-gated accrual (already required for payouts). Breakage & liability accounting defined with finance on day one.

04 · Answers We Need This Week

Open questions for our team.

Does the shared FI/CO cart have any store-credit or gift-card ledger with an API today? This single answer sizes the wallet at ~2 weeks (wrap it) vs. a build (Option B fresh).→ Cart/platform lead
Can our current auth stack front an OpenID Connect IdP, or do we put one in front of it? Sizes SSO at 1–2 weeks vs. more.→ Platform/infra
Do our marketplace-facilitator tax registrations cover peer-to-peer sales in the states we're registered in?→ Tax/finance
Which carrier accounts and rates do we expose for prepaid labels, and does our insurance cover P2P shipments at declared value?→ Ops/logistics
Is the catalog spec data exposed as a service (or can the §14 pipeline output feed one) for prefill + spec-check?→ Data/catalog (Scott)
Is the fitment engine callable as an internal service today, or embedded in the cart code? Service → ~a week of glue for "fits my car"; embedded → service-ize it first (which benefits FI/CO too).→ Cart/platform lead
ESP + analytics: one property or rollup, and how do we tag credit-funded retail orders for flywheel attribution?→ Marketing/analytics