DEVICE LIFECYCLE

Claim, provision and operate every PalmPay terminal.

A governed device journey covering ownership, identity, mode, certificate, testing, activation, monitoring and retirement.

PALMPAY
DEVICE
CLAIMVERIFYASSIGNPROVISIONTESTACTIVATEOPERATERETIRE
DEVICE REQUEST

Register or plan a PalmPay Device

Provide model/serial only when approved for public submission. Otherwise describe quantity, locations, preferred mode and integration context.

01

Device identity

Create a trustworthy inventory record.

Required attributes

Model, serial, hardware revision, firmware, palm SDK/model, owner, warranty and support contact.

Assignment

Tenant, merchant, chain, store, location, POS/ECR, business purpose and operating hours.

Ownership evidence

Purchase, lease, transfer or deployment authorization and chain of custody.

02

Operating mode

Bind controls to the selected architecture.

HOST / USB

Host identifier, USB protocol, middleware/driver, allowed commands, callback and Dynamic UI source.

Direct Backend

Device certificate, MQTT profile, API endpoint, tenant topics, mTLS, network and remote-management policy.

Multi-application

Payment, attendance, access, identity and custom workflows remain policy-separated.

03

Provisioning and activation

Prove device trust before production.

Security bootstrap

Certificate, trust anchors, configuration signature, time sync, debug controls and secure update policy.

Functional tests

Connectivity, Dynamic UI, palm capture, identification/authentication, POS callback, result notification and heartbeat.

Go-live gate

Store acceptance, support owner, monitoring, rollback, remote disable and approved status.

04

Lifecycle operations

Manage the device beyond activation.

Operational states

Inventory, Pending Activation, Active, Degraded, Offline, Suspended, Maintenance, Revoked and Retired.

Change and OTA

Staged rollout, firmware verification, anti-rollback where supported, failure recovery and evidence.

Transfer and retirement

Unassign, secure wipe, certificate revocation, ownership transfer, disposal and retained audit.

DEVICE ASSURANCE

Terminal acceptance combines hardware, software, identity and operations

Hardware and capture

Acceptance records sensor modality, optical/IR configuration, display, scanner, ports, power, network modules, environmental limits, placement and capture quality. Reference speed and distance must be re-measured on the selected production model.

Firmware and supply chain

Document firmware identity, signed update, secure boot or equivalent capability, anti-rollback where available, default credentials, debug controls, component inventory, vulnerability reporting, support period and provenance.

Channel identity

Every Direct Backend device needs a unique certificate and topic/API identity. HOST mode needs a trusted host binding, documented USB protocol and authorization rules. Shared secrets across a fleet should be avoided.

Operational telemetry

Health, heartbeat, time sync, certificate expiry, firmware version, temperature or sensor status where available, transaction errors, palm-quality failures and connectivity should feed monitoring without collecting unnecessary biometric content.

Can a device move to another store?

Yes, through an approved transfer workflow that removes the old binding, verifies custody, reapplies configuration, tests connectivity and records the new assignment.

What if the network is unavailable?

The approved fallback depends on the architecture. The system can route customers to QR, app, card or assisted payment; offline palm authorization should not be assumed without a separately approved risk design.

Can the device be used for attendance?

Yes, if the multi-application policy separates purpose, data, user notice, access, UI and backend workflow from payment.

MOBILE-ID / TRUSTED PALMPAY

Register a device

Mobile-ID will align device inventory, terminal mode, POS/backend integration, certificate lifecycle and acceptance tests.

Register a device