Robots & AIoT
How robots and AIoT systems identify, authenticate, and transact with Syper.
Robots and AIoT systems can hold and use money: a delivery robot paying for charging, a smart vending machine settling with suppliers, a building system paying for energy. Syper treats each machine as an Agent Account — with its own identity, permissions, and limits — owned by an accountable person or business.
IoT vs AIoT. IoT devices are connected devices that follow fixed logic. AIoT systems are connected devices that also use AI for sensing, interpretation, decision-making, automation, or autonomous behaviour. Both use the same account model; AIoT systems need tighter policy because their actions are not fully predetermined. See IoT Devices and AIoT Systems.
The machine workflow
Every machine transaction follows the same five steps.
- 1Identify
- 2Authenticate
- 3Authorize
- 4Act
- 5Observe
Identify
The machine has its own identity — an Agent Account — distinct from its owner. Its actions are attributable to it.
Authenticate
The machine proves its identity with credentials provisioned to it. See Authentication.
Authorize
Syper checks the request against the machine’s permissions, spending limits, and policy — not just its credentials.
Act
The machine performs the operation — reading a balance, paying, transferring — through whichever interface suits its hardware and connectivity (below). Every write is idempotent.
Observe
The owner and the machine receive outcomes through webhooks or WebSocket, and every action appears in activity.
Interfaces
A robot or AIoT system may use several of these. Each links to its own page rather than repeating it here.
- API
- Direct programmatic access over supported network interfaces — read balance, initiate payment, transfer funds, retrieve account state.
- SDK
- Language-specific libraries wrapping the API, e.g. conceptual pay(), transfer(), balance().
- MCP / Agent Tools
- Exposes approved Syper capabilities as tools to compatible AI-agent environments — e.g. “Pay the charging station.” The agent still operates under explicit identity, authentication, authorization, policy, and spending controls.
- USSD
- Telecom session-based interface that can work without a smartphone data connection.
- SMS
- Supported OTP, confirmations, alerts, and carefully controlled messaging flows. SMS is not in itself a secure financial command channel.
- NFC
- Short-range interaction with terminals, tags, cards, machines, or nearby devices — e.g. a robot at a charging terminal.
- QR
- Scan or present encoded payment, identity, or session information.
- Webhooks
- Asynchronous server-to-server event delivery, e.g. payment.completed.
- WebSocket
- Persistent bidirectional connectivity for live application state.
- ISO 20022
- Financial messaging standard used across many banking and payment infrastructures. It is a message format, not a payment network.
- Blockchain / RPC
- Integration with supported blockchain networks, token operations, and smart contracts.
Example: a robot pays for charging
TypeScript
// Illustrative only — not a published SDK.
const station = await readNfcTag(); // Identify the counterparty
const quote = await syper.payments.quote(station.paymentRequest);
if (quote.amount <= policy.maxChargePayment) { // Local pre-check; Syper enforces limits too
await syper.pay(quote, { idempotencyKey: station.sessionId });
}The robot’s owner receives payment.completed on its backend via webhook.