iVendNextDevelopers Request a sandbox

A till key that asks an AI model — the recipe

The AI tip key pressed on a real till

A cashier presses AI tip on a sale, and a short hint appears in the till's own sheet.

This recipe adds a key to the till that gives the cashier a short, AI-written hint during a sale, such as an add-on to suggest or a care note. The hint comes from an AI model the customer already has. It is for a partner, or a shop's IT team. Reference implementation: samples/s6_ai_till_key/.

Who pays for the AI. We never pay for an AI model on a customer's behalf, and never per customer question. The shop sets up its own provider: an open-weight model on its own machine (Ollama, llama.cpp, vLLM), or the assistant it already pays for. Your service calls that. The sample ships with a local stand-in, so it runs with no account at all.

When to use it. Rung 3 of the ladder, a remote till key (recipes/point_handler.md step 6), when the answer is words for the cashier. The key cannot change a price, a total, a payment or a stock figure. The answer is a message: a title of up to 60 characters and a body of up to 280. The till refuses anything else, whole.

Steps

  1. Pick the provider and run the service. samples/s6_ai_till_key/service.py is about 100 lines of standard-library Python. The logic is in core.py (no framework, no provider code) and the provider is in providers.py. Set these in the service's environment:

    • PP_POINT_SECRET: the signing secret you will give the shop.
    • PP_AI_PROVIDER: stub (no AI at all) or chat.
    • For chat only: PP_AI_URL (any service that speaks the chat-completions request), PP_AI_KEY (the customer's own key, if the service wants one) and PP_AI_MODEL.

    Put the service behind HTTPS. The till calls HTTPS only, and checks the certificate.

  2. Register the key in the shop. A System Manager does this in Desk, on a Retail Remote App Key record. Fill in: your name as the partner, an app name, the key, its label, message as the only thing it may return, your HTTPS address (…/point/ai_tip), the signing secret, and the time to answer. The time to answer is 3 seconds unless raised, and at most 10 on this record; a manifest may declare at most 5 (recipes/manifest.md). Tick the customer's consent, and paste the consent text the sample prints (core.consent_text()). That text is built from the very list of fields the prompt is built from, so the words and the data cannot drift apart.

    the key's record in Desk

    The key's record in Desk: enabled, message only, your HTTPS address.

  3. Switch the key on in the store: POS Studio → the theme → Apps → tick the key → Save, as for any till key. The key then shows among the store's keys on the till.

    the key on the till

    A sale on the till, with the AI tip key among the store's keys.

  4. Choose a model that can answer in time. The till waits at most the time you set (3 s by default, 10 s at most). If the model cannot answer that fast, the cashier reads "AI tip did not answer in time. Nothing was added to the sale." That sentence is the till's own, and the sale goes on. Use a small model, a short prompt (the sample's asks for at most 40 words), or raise the time to answer to what the counter can bear.

  5. Press it. The till's server calls your service, and the hint comes back in the till's own sheet. The till draws the sheet; your service sends only words.

    the hint

    The hint, in the till's own sheet.

What is sent, and to whom

Two hops, and the consent text (core.consent_text()) names both:

  1. The till sends your service its context on every press: the item codes, quantities and units, the store, the customer on the sale and the cashier, the sale's reference, the register's profile, the company and the currency. No prices, totals or payment details. The shop consents to this when it ticks the consent box on the key's record.
  2. Your service forwards only two things to the AI model: the item codes with quantities, and the store's name. The customer, the cashier and everything else stop at your service. A basket longer than 30 lines is cut, and control characters are stripped.

What is refused, and why

When your service is slow or down, and when the till is offline

The service never invents a tip. In each case the sale goes on:

What happens The cashier reads
The model is slow (past the time to answer) AI tip did not answer in time. Nothing was added to the sale.
The model is down, errors, or answers nonsense AI tip could not finish. Nothing was added to the sale. — the service never invents a tip
The answer breaks the message rules AI tip answered in a way this till cannot use. Nothing was added to the sale.

Offline: a remote key is online only; the sale goes on without it.

Logs and secrets

The service writes one line per request: the request id, the status and the milliseconds. It never logs the prompt, the sale, the model's reply, the customer's AI key or the signing secret. A failure logs the error's class only, because an error's message can carry a key.

What we would like to improve

Technical notes

Proven on our test bench.

What the tests check, section by section

What was proven where

This page in the kit