Session API
/v1/sessionsCreate, lock, extend, terminate and recover controlled sessions.
Audit enabledNormalize Kiosk peripheral control, sessions, security and evidence through an API-first middleware layer.
Applications call business capabilities rather than device drivers. KioWare Agent enforces policy, timeout, idempotency, masking, telemetry and audit at the edge.
POST /v1/sessions/{sessionId}/capabilities/identity-card/read
Authorization: Bearer {access_token}
Idempotency-Key: idem-4821
X-KioWare-Policy: BANK-ONBOARDING-V4
{
"requestId": "REQ-KW-7F2A",
"deviceRole": "PRIMARY_ID_READER",
"timeoutMs": 30000,
"evidenceRequired": true
}/v1/sessionsCreate, lock, extend, terminate and recover controlled sessions.
Audit enabled/v1/capabilities/{name}ID/NFC, camera, QR, printers, scanners, signature pads and optional devices.
HAL normalized/v1/policies/evaluateAuthorization by application, tenant, session, device and risk state.
Least privilege/v1/events/streamDevice events, transaction progress, health, SLA and alerts.
Near real-time/v1/evidenceReceipts, traces, consent references and audit evidence.
Integrity protected/internal/v1/fleetInventory, desired state, release rings, commands and recovery.
Control planeUse case, thiết bị, dữ liệu, SLA và security boundary.
App identity, policy profile, sample app và test device.
API/SDK, connector, adapter và event contract.
Threat review, negative tests, recovery và audit.
Happy path, exception, performance, accessibility và evidence.
Pilot, release ring, telemetry, SLA và handover.
No. Applications call normalized capabilities through KioWare Agent; Device Adapters isolate vendor SDKs and drivers.
Yes. The edge API can be restricted to the Kiosk or site network; Control Plane connectivity depends on the On-premise, Hybrid or Managed Service model.
The standard scope includes ID/NFC, camera, QR/barcode, printers, scanners, touch displays and audio; additional devices are integrated through Device Adapters.
Submit the use case, devices and backend systems. Mobile-ID reviews the scope and provides an app identity, policy profile and PoC/UAT plan.
Assess TCO, APIs, HAL, IAM, peripherals, PoC, UAT and the production roadmap with the KioWare team.