Skip to main content

🔐 Configure Terminal Trust

The POS terminal has two distinct trust boundaries:

POS Trust POS Trust

Source (.excalidraw)

  • The terminal backend authenticates the POS app using device attestation and the configured app package/signing-certificate digest.
  • The records server verifies the payment credential's issuer chain and the holder's signature over the payment transaction data.

Keeping the payment-processor key on the terminal backend is essential: distributing it in every POS application build would allow a compromised terminal to impersonate the merchant.

Connect to the terminal backend​

RpcAuthorizedDeviceClient establishes the authenticated app-to-backend connection. The backend validates the device attestation before it exposes the payment RPC interface.

  • Here we open an attested RPC session and retains the generated payment client only when registration succeeds. Put the backend URL and merchant account in configuration, rather than hard-coding them throughout UI code.
  • The configruration is kept in the default-configuration.json file

Keep the payment key out of the app​

The backend forwards approved calls to the records server, signing as the payment processor. This is where the money-moving key belongs.

  • It accepts only calls authorized by the terminal backend, then forwards them to the records server using the backend's PAYMENT_PROCESSOR identity. The POS client never receives that identity's private key.

For production, require hardware-backed attestation, use TLS, store the processor key in managed key storage or an HSM, and enroll the terminal with the records server's real trust hierarchy.