KIOWARE API INTEGRATION CENTER

KioWare API integration for applications, devices and enterprise systems

Normalize Kiosk peripheral control, sessions, security and evidence through an API-first middleware layer.

API-FIRST KIOSK MIDDLEWARE

One consistent API surface for Kiosk applications and peripherals

Applications call business capabilities rather than device drivers. KioWare Agent enforces policy, timeout, idempotency, masking, telemetry and audit at the edge.

REST / JSONWebSocket EventsmTLSOAuth 2.0 / JWTIdempotencyTrace ID
EDGE API READYv1 · local secure endpoint
POST /v1/sessions/{sessionId}/capabilities/identity-card/read
Authorization: Bearer {access_token}
Idempotency-Key: idem-4821
X-KioWare-Policy: BANK-ONBOARDING-V4

{
  "requestId": "REQ-KW-7F2A",
  "deviceRole": "PRIMARY_ID_READER",
  "timeoutMs": 30000,
  "evidenceRequired": true
}
202 ACCEPTEDpolicy-enforcedtraceableno direct driver access
CAPABILITY CATALOG

Clearly structured API groups for integration teams

Session API

/v1/sessions

Create, lock, extend, terminate and recover controlled sessions.

Audit enabled

Device Capability API

/v1/capabilities/{name}

ID/NFC, camera, QR, printers, scanners, signature pads and optional devices.

HAL normalized

Policy API

/v1/policies/evaluate

Authorization by application, tenant, session, device and risk state.

Least privilege

Telemetry API

/v1/events/stream

Device events, transaction progress, health, SLA and alerts.

Near real-time

Evidence API

/v1/evidence

Receipts, traces, consent references and audit evidence.

Integrity protected

Admin API

/internal/v1/fleet

Inventory, desired state, release rings, commands and recovery.

Control plane
REFERENCE ARCHITECTURE

Four architecture views for CTOs and architects

Business ChannelWeb application, native application, workflow và service journey.
KioWare AgentSession manager, policy enforcement, secure storage, event bus và recovery checkpoint.
HAL / AdapterCapability abstraction, driver isolation, calibration và device attestation.
Trust ServicesSSO, consent, step-up authentication, remote signing và evidence.
Edge NodeKiosk runtime, local-only API, offline policy cache và encrypted temporary data.
Secure ChannelOutbound mTLS, signed command, TTL và không mở cổng inbound công khai.
Control PlaneFleet inventory, tenant, release, telemetry, incident và audit.
Identity BoundaryUser identity, application identity và device identity được xác minh độc lập.
Policy BoundaryLeast privilege, masking, maker-checker và short-lived authorization.
Evidence BoundaryTrace ID, consent reference, immutable audit và retention policy.
Desired StateConfiguration baseline, drift detection, canary và rollback.
Remote OperationsCommand queue, expiry, idempotency, approval và incident response.
ContinuityGolden image, backup, recovery mode, failover và DR testing.
INTEGRATION JOURNEY

From workshop to production with acceptance criteria

01

Discovery

Use case, thiết bị, dữ liệu, SLA và security boundary.

02

Sandbox

App identity, policy profile, sample app và test device.

03

Build

API/SDK, connector, adapter và event contract.

04

Security

Threat review, negative tests, recovery và audit.

05

UAT

Happy path, exception, performance, accessibility và evidence.

06

Scale

Pilot, release ring, telemetry, SLA và handover.

FAQ

KioWare API integration FAQ

Must applications call device drivers directly?

No. Applications call normalized capabilities through KioWare Agent; Device Adapters isolate vendor SDKs and drivers.

Can the API run within a private network?

Yes. The edge API can be restricted to the Kiosk or site network; Control Plane connectivity depends on the On-premise, Hybrid or Managed Service model.

Which devices does KioWare support?

The standard scope includes ID/NFC, camera, QR/barcode, printers, scanners, touch displays and audio; additional devices are integrated through Device Adapters.

How do I request a sandbox?

Submit the use case, devices and backend systems. Mobile-ID reviews the scope and provides an app identity, policy profile and PoC/UAT plan.

EXECUTIVE BRIEFING · TECHNICAL WORKSHOP

Turn a Kiosk requirement into an auditable delivery scope

Assess TCO, APIs, HAL, IAM, peripherals, PoC, UAT and the production roadmap with the KioWare team.