How registration works

The one-time terminal registration (attestation) flow, and the single most important integration rule.

Before a terminal can process payments it must complete a one-time registration (also called attestation) with Blinc. Understanding the flow is the key to integrating correctly:

  1. Fetch a challenge. Your backend obtains a one-time challenge (nonce) from Blinc and returns it to your app. The challenge is single-use and short-lived. The endpoint, request/response shape, and sandbox test credentials are documented in the Challenge (Nonce) API reference.

  2. Register. You hand the challenge to the SDK. The SDK generates a hardware-backed key and completes attestation with the Blinc backend. Once attestation succeeds, the terminal's merchant profile is saved on-device.

The single most important rule

Fetch a challenge and register only when the terminal is not already registered. Calling your backend on every app launch is the most common integration mistake. The ensureRegistered() entry point exists precisely so you never have to write that check yourself. It fetches a challenge only when registration is genuinely missing.

A challenge nonce is single-use

Never cache or persist a challenge. If registration needs to run again, fetch a fresh one. ensureRegistered() does this for you.


Did this page help you?