🔐 Configure Terminal Trust
The POS terminal has two distinct trust boundaries:
- The terminal backend authenticates the POS app using device attestation and the configured app package/signing-certificate digest.
- The records server verifies the payment credential's issuer chain and the holder's signature over the payment transaction data.
Keeping the payment-processor key on the terminal backend is essential: distributing it in every POS application build would allow a compromised terminal to impersonate the merchant.
Connect to the terminal backend
RpcAuthorizedDeviceClient
establishes the authenticated app-to-backend connection. The backend validates the
device attestation
before it exposes the payment RPC interface.
- Here we open an attested RPC session and retains the generated payment client only when registration succeeds. Put the backend URL and merchant account in configuration, rather than hard-coding them throughout UI code.
- The configruration is kept in the default-configuration.json file
Keep the payment key out of the app
The backend forwards approved calls to the records server, signing as the payment processor. This is where the money-moving key belongs.
- It accepts only calls authorized by the terminal backend, then forwards them to the records server using the backend's
PAYMENT_PROCESSORidentity. The POS client never receives that identity's private key.
For production, require hardware-backed attestation, use TLS, store the processor key in managed key storage or an HSM, and enroll the terminal with the records server's real trust hierarchy.