# Development Requirements - Getnet App2App

This document consolidates all mandatory requirements, security best practices, prohibitions, and technical constraints for developing applications integrated with POS Getnet terminals.

## Mandatory Requirements
To ensure certification and operational stability, the following rules must be strictly followed:

- Applications must support Android 5.1 (22), Android 7.1 (25), and Android 10 (29).

- Development can be Native or Hybrid (e.g., Xamarin), provided it compiles to "Android Runtime (ART)", as if it were a native application.

- The application must be using the Getnet Hardware SDK.

- The following attributes must be added to the `build.gradle` file in order to sign your application for the TecToy Sunmi P2 terminal model. See below:

    * `v1SigningEnabled true`
    * `v2SigningEnabled true`
    * `signingConfig signingConfigs.config`

Examples:

```
android {
    //START - This method must be inserted into Android.{}
    signingConfigs {
        config {
            v1SigningEnabled true
            v2SigningEnabled true
        }
    }
//END - This method must be inserted into Android.{}
    buildTypes {
        debug {
            debuggable true
            testCoverageEnabled true
            signingConfig signingConfigs.config //This line should be inserted into buildTypes.
            crunchPngs false
        }
        release {
            minifyEnabled false
            debuggable false
            signingConfig signingConfigs.config //This line should be inserted into buildTypes.
            proguardFiles getDefaultProguardFile('proguard-android.txt','proguard-rules.pro')
            crunchPngs true
        }
    }
}
```

- The app should have a "**Contact Us**" section providing customers with the necessary contact information for support in case of problems or questions. This section should be clearly visible and reachable in few taps.

- The app **must** use the **serial number provided by the Getnet API**. Using the native Android serial number or application-generated IDs is prohibited.

- Use dynamic layouts, considering that in the future the application may be installed on other hardware with different resolutions and densities.

- Navigation through all screens must be seamless without crashes or "breaking" the application.

- The app must contain query metadata in the manifest to interact with the Getnet SDK. This information is necessary for communication between apps on devices with Android version 11 or higher (SDK 30), such as the TecToy Sunmi P3.

Example:

```
    <queries>
        <package android:name="com.getnet.posdigital.service" />
    </queries>
```

## Security and best practices

Developers are responsible for the information security within their applications.

- Use Android programming best practices.

- It is the developer's responsibility to ensure the security of information within the application.

- Avoid exposing sensitive customer data, such as passwords and personal information.

- Data integrity.

- Review your project and delete images and data that are not used.

- Avoid features with infinite timeouts that may leave your application frozen or waiting for an event.

- Do not keep the Mifare antenna on; only turn it on when it is to be used.

- Conscious use of data consumption.

- Conscious use of printing paper – avoid large images, too much white space, large spaces between lines, and spaces at the beginning and end of receipts.

- Conscious use of memory and CPU consumption.

## Prohibitions

The following are strictly prohibited and will cause immediate rejection during integration:

- WebApps and WebView are expressly prohibited due to security measures. Developments using WebView-based technologies are prohibited. Example: Ionic, Cordova. During the application certification process, our certification team will use tools to verify if your application has WebView.

- Google Play Services will not be available.

- The application cannot communicate with any direct or indirect competitor of Getnet or the Santander Group (including banks, acquirers, sub-acquirers, and wallets).

- The application cannot be run in full-screen mode.

- The application cannot make changes to Android system settings (e.g., date, time, location, etc.).

- Access to inappropriate external resources (USB, Google Play...).

- The application's icon, logo, and name cannot be linked to the visual identifications of the following items:

   * Getnet and its products;
   * Banco Santander;
   * Direct or indirect competitors of Getnet or the Santander Group (including banks, acquirers, sub-acquirers, and wallets).

## Next steps

* [Quick Start](/en/app2app/first-steps-a2a/create-quick-start-guide) - build the integration that has to meet these requirements.
* [Architecture and flow](/en/app2app/first-steps-a2a/architecture-flow) - see how the Intent exchange works end to end.