Operator workspace
DEMO · seeded data
V12 PREPAID / STS LAB

Prepaid vending & meter identity

Payment, vending, CIU/meter mapping and reconnect governance without exposing STS keys.

Demo token metadata only. No STS keys and no real token generation, live valve command or actual M-PESA request is performed.

Meter / CIU identity

SerialMECH-2400188
DRN860123450001
CIUCIU-88
Supply groupSGC-01
Key revisionKRN-2
TID contextTI-2026
Current balanceKSh 620
Secure vending boundaryApplication stores identifiers and audit metadata only. Vending keys remain in approved secure/HSM boundary.

Top-up flow

Each economic credit must be idempotent and traceable.

ready
1
Payment verifiedProvider transaction exists; allocation separate.
2
Identity validatedAccount ↔ meter ↔ DRN ↔ CIU checked.
3
Vending requestSecure boundary receives authorized request.
4
Token/credit metadataNo plaintext key enters app state.
5
Meter acknowledgementCredit/valve state confirmed or exception queued.

Migration blockers & acceptance tests

Current installed model/firmware, key custody and API/export access must be confirmed before production replacement.

Research gates
01Exact model + firmwareBlocked / verify
02Product-specific STS certificateBlocked / verify
03SGC/KRN/TI/TID ownershipBlocked / verify
04Vending key custody / secure moduleRequired test
05Legacy DB/API exportRequired test
06Token replay/duplicate behaviorRequired test
07M-PESA reference semanticsRequired test
08Valve/reconnect acknowledgementRequired test
09Opening balances and outstanding creditRequired test
10Dual-run reconciliation + rollbackRequired test