Payment Terminal
Pronunciation: PAY-munt TUR-muh-nul
Definition
A payment terminal is a physical or software-based point-of-interaction device used to capture payment credentials, amount, approval, or authentication and submit a transaction. Examples include attended and unattended card terminals, mobile point-of-sale devices, kiosks, and software terminals. Payment Terminal requires named ownership and auditable controls for payment authorization, execution, fulfillment, and financial posting. Payment Terminal records must retain authoritative identifiers, timestamps, state changes, exceptions, owners, and the final operational and accounting outcome.
Overview
A payment terminal is a physical or software-based point-of-interaction device used to capture payment credentials, amount, approval, or authentication and submit a transaction. Examples include attended and unattended card terminals, mobile point-of-sale devices, kiosks, and software terminals.
For Payment Terminal, the interface or route should clearly present the merchant, obligation, amount, currency or asset, expiry, fees, destination, consent, security cues, status, and recovery options without acting as the authoritative settlement record. The operational record should capture session, merchant, order, server amount, payment option, expiry, return state, and backend outcome for Payment Terminal, including the handoff to Payment Terminal ID . The operating record should preserve the original obligation, participants, amount, currency or asset, authoritative identifiers, timestamps, state history, exceptions, and final financial effect.
Payment Terminal should remain distinct from Payment Terminal ID, because the two records can carry different authority, timing, and financial effects.
The failure model should include phishing, altered amounts, credential leakage , inaccessible forms, confusing timers, unsupported devices, abandoned redirects, bot impersonation, customer error, and fulfillment based on browser state rather than server evidence. Important failure modes include duplicate or delayed events, wrong destinations or currencies, stale instructions, unavailable providers, unsupported retries, and customer-facing status that differs from authoritative records.
Controls should validate inputs server-side, authenticate external events, make irreversible actions idempotent, and reconcile provider, network, settlement, and ledger evidence. For Payment Terminal, the authoritative record and completion rule should be documented before any irreversible operational, customer, or accounting action is released. Teams using Payment Terminal should preserve the evidence behind each decision so retries, corrections, support reviews, and audits can reproduce the final outcome.
Key Takeaway
A payment terminal is a physical or software-based point-of-interaction device used to capture payment credentials, amount, approval, or authentication and submit a transaction. Its authoritative records, controls, exceptions, and final financial effect must be explicit.
Sources
- W3C Payment Request API — W3C (2026-08-01)
- OWASP API Security Project — OWASP (2026-08-01)