HTTPS operations
Signed-in reads and changes go through the Ysend API, limited to the right account, warehouse, device and user.
Connectivity and continuity
Supported applications connect directly to Ysend over HTTPS and realtime hubs. Offline queues and the handheld peer mesh preserve bounded work; desktop bridge, equipment tunnel and store-and-forward edge remain distinct optional components.
Default route
A warehouse application server is not a prerequisite. Each enrolled client keeps its own identity, scope and cloud session.
Signed-in reads and changes go through the Ysend API, limited to the right account, warehouse, device and user.
Hubs carry fresh operational updates without transferring business authority to a local relay.
When no local bridge is configured or reachable, the handheld continues with its direct cloud path.
Device custody
Each event gets a unique ID so it is never recorded twice, and the related task details are stored locally.
The interface does not call the operation cloud-accepted yet.
Retries keep the same event identity so duplicate delivery is safe.
The device’s record does not replace confirmation by Ysend.
Warehouse peer mesh
Supported handheld instances listen for peers, discover one another and exchange operation events plus signed reference records.
Peers exchange bounded events while cloud access is unavailable; a desktop station may join as an optional peer.
When the WAN returns, each device normally uploads its own work directly to SaaS.
An idle peer may upload a replicated event for an origin device that is no longer available.
Account, warehouse, device, key period, signature and expiry are checked; reusable logins or API keys are never accepted in messages between devices.
Optional local components
Per station
The bundled station agent connects scanners, printers and cameras and may act as a mesh peer or WAN relay.
Per equipment site
A vendor-enrolled agent carries authorised TCP adapter streams through outbound-only cloud tunnels.
Per warehouse, opt-in
The separate local edge software is off by default and must be configured and installed for each warehouse.
NAT-behind equipment
The enrolled site agent establishes an outbound WebSocket to SaaS.
The site allowlists exact endpoints and pairing credentials are stored as hashes.
Each authorised equipment connection receives a separate duplex binary channel.
TCP machine or robot traffic crosses the tunnel while SaaS remains authoritative.
Cloud reconciliation
Origin uploads, peer rescue and local relays can overlap. The SaaS validates identity and deduplicates rather than asking the warehouse to choose a winner.
The same operation keeps the same unique ID through retries and copies, so it is never applied twice.
Scope, sequence, age, signature and workflow state are checked before acceptance.
The cloud response establishes accepted, rejected or already-recorded state.
Fleet supervision
Device identity and warehouse assignment are explicit and revocable.
Connectivity, version, health and workflow signals support remote diagnosis without granting unlimited control.
Managed devices can receive approved app updates and keep their access limits.
A removed or expired identity fails closed across cloud, mesh and bridge paths.
List applications, equipment endpoints, WAN failure modes and custody requirements. We will keep direct SaaS, peer mesh, equipment bridge and optional edge separate.