Your terminal app calls your backend to obtain a one-time challenge (nonce) from Blinc, your backend calls this endpoint to get the one-time challenge (nonce). Your backend signs and encrypts the request’s data field before sending it to Blinc. Your backend will get the one-time challenge (nonce) from the response and return to the terminal app. The terminal app will use the returned nonce for SDK initialization.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
A nonce is single-use and short-lived. Never cache or persist one; if registration needs to run again, fetch a fresh nonce.
IP allowlisting
Before requesting a challenge, provide Blinc with your server's public outbound (egress) IP address. Blinc must whitelist this IP address.
flowchart TD A["Terminal app"] --> B["Terminal Backend"] B --> C["Blinc get-challenge API"] W["Public outbound IP<br/>must be whitelisted by Blinc"] -.-> B
Test credentials (Sandbox)
Use the following pair when testing against the sandbox endpoint. These credentials are for sandbox use only and will not work in production.
| terminalId | merchantId |
|---|---|
| T0001 | 00000001 |
Blinc will provide your paymentFacilitatorId.
End-to-End encryption
The backend must encrypt the request’s data field before calling Blinc API. See Guide on How to Encrypt and Decrypt Data
Request Signature
The plain request payload is signed using ECDSA-SHA256 and the signature is passed in the header as x-signature. See Guide on How to Generate and Verify a Signature