S2 — bin locations (pp_bln): where stock sits inside a store

The bin locations workspace in Desk: the bins on their aisles, and what is in each bin.
S2 records only where items sit inside a store — locations (back room, shop floor), aisles, bins and what is in each bin — and answers the cashier's "Where is it?" key. The shop's stock and valuation stay in iVendNext. It is for a developer who wants to add their own records and screens to a shop, kept up to date by their own service.
When to use it: your product keeps its own data beside the shop's (here, bins) and staff should see it in Desk and at the till.
What it looks like
| Step | Frame | Screenshot |
|---|---|---|
| 1. The workspace the manifest installs: locations, bins, what is in each bin | Desk, 1440 wide | ![]() |
| 2. The bins, each on its aisle | Desk | ![]() |
| 3. What is in each bin: the quantities the service keeps from booked sales and stock movements (the shop-floor bin reads 0 after earlier test sales) | Desk | ![]() |
The names are the sample's own placeholders (PP Durban Floor F1, SF-F1-01). The till key "Where is it?" is not shown: it is installed switched off (see below).
Its form (outsiders never write Python inside a customer's site)
| Piece | What |
|---|---|
manifest.json (v2) |
the data: five record types, the Item.pp_bln_default_bin field, display setters, a bin label, a workspace, two signed webhooks to the service — and the till key as a remote key (remote_keys: "Where is it?", calling the partner's own service over HTTPS, installed switched off with consent not given) |
service/ · core.py |
the partner's own service: keeps the bins up to date from booked sales and answers the remote key from the pure core |
The "Where is it?" key arrives switched off, with consent not given: the shop turns it on. It has not yet been pressed on a till; the same kind of key has been, for S1 (through the till's press endpoint) and S6 (on the till's screen).
What is refused, and why
A shop whose iVendNext POS app does not yet have the released remote till key refuses this manifest at install: the manifest carries a remote key, which such a shop cannot install.
Run it
python3 tools/manifest/validate.py samples/s2_bins/manifest.json
python3 -m unittest discover -s samples/s2_bins/tests -p 'test_core.py' -v
python3 samples/s2_bins/service/app.py samples/s2_bins/service/.env.local
The env file (never committed), kept at samples/s2_bins/service/.env.local, holds PP_BASE, PP_KEY, PP_SECRET, PP_WEBHOOK_SECRETS (the manifest's two webhooks, comma-separated), PP_ADMIN_TOKEN, PP_POINT_SECRET (the remote key's signing secret), PP_COMPANY, and optionally PP_PORT (8123), PP_DB and PP_SINCE.
Technical notes
The walk
The GIF shows what the manifest installs, as staff see it in Desk: the workspace, the bins with their aisles, and what is in each bin — the quantities the partner's service keeps up to date from booked sales. Frame: Desk, 1440 wide. Walked on our test bench on 2026-10-07, iVendNext POS app at 8dc36aab8. Built from the same screens as the stills below, uncropped.
In step 3, the shop-floor bin reads 0 after the bench's earlier test sales.
What was proven where
On our test bench the manifest now installs with its remote key, switched off and with no consent, as a shop receives it (before the bench's POS app had the released key, the installer refused it, and that refusal is tested); the till key was driven by our stand-in caller with the till's real context and the till's real validator. UNPROVEN: a press of Where is it? on a till. The released key has answered presses for S1 (through the till's own press endpoint, called from the bench's console as the cashier: row BUMP, G5b, run pp-20261007T014940Z-64695) and S6 (pressed on the till's screen, the iVendNext POS app in a desktop browser: row SHOTS2, run pp-20261007T105308Z-98631); a physical till device was not tried.
The env file's path
service/app.py opens the path it is given from the current directory (_env(sys.argv[1])), so from the kit's root the command passes samples/s2_bins/service/.env.local. With no argument it reads .env.local beside app.py, the same file. Our test bench runs it from the sample's own folder as python3 service/app.py service/.env.local.


