SKU mapping governs the floor
Merchant SKU and barcode proposals bind to canonical product, packaging, lot, serial, expiry, and prep-label rules before stock is received.
Merchant and customer workspace
Merchants prepare products and inbound stock, manage orders and inventory, compare signed shipping prices, fund purchases, buy labels, handle returns, and review spend without entering warehouse operator controls.
Beyond a standard merchant dashboard
Balance, inventory, and tracking views are baseline. The deeper mechanism preserves identity, version, exact price, funding, physical execution, and reconciliation across the client/operator boundary.
Merchant SKU and barcode proposals bind to canonical product, packaging, lot, serial, expiry, and prep-label rules before stock is received.
Submission, booking, labels, documents, receiving status, discrepancies, and amendments retain expected version instead of silently replacing warehouse work.
One idempotent purchase joins signed sell quote, wallet or card reserve, carrier transaction, capture, receipt, history, void, and confirmed refund reconciliation.
The service authorizes the artifact; the bound station or handheld checks printer profile, sends local BLE/GATT or workstation payload, and reports acknowledgement.
The client journey
The workspace exposes client-owned intent, funding, evidence, and visibility while warehouse lifecycle rules and authorization remain authoritative.
Map canonical products, merchant SKUs, barcodes, packaging, lot, serial, and expiry requirements.
Build versioned manifests, cartons, pallets, labels, booking details, documents, and discrepancy responses.
Create and follow orders, inspect inventory, compare signed quotes, confirm exact charges, and buy labels.
Track shipments, manage returns, quarantine imports, review spend and SLAs, and use scoped API/webhook tools.
Wallet and payments
The client chooses prepaid wallet or saved-card pay-as-you-go. Top-ups, holds, captures, releases, and adjustments remain visible in an append-only ledger.

Payment means and funding models
The current self-service payment instrument is a tokenized card collected by Stripe. Wallet and commercial modes define when that card is charged.
| Mode | How it works | Best for | Important boundary |
|---|---|---|---|
| Prepaid wallet | Top up a currency balance with a saved card. Confirmed purchases use available wallet funds and can create temporary holds. | Budget control, delegated operators, predictable spend | A wallet credit posts only after verified payment success. |
| Saved card pay-as-you-go | Authorize the exact purchase against the default or selected saved card, then capture it with the source transaction. | Lower frequency or just-in-time label buying | Strong customer authentication may require an additional card step. |
| Automatic top-up | When available wallet funds fall below the configured threshold, charge the selected card for a configured top-up amount. | Uninterrupted high-volume shipping | Failures remain visible and recoverable; no silent wallet credit. |
| Enterprise postpaid | Purchases follow contracted billing and invoice terms rather than self-service card funding. | Approved enterprise accounts | Configured commercially; it is not activated by a self-service toggle. |
Bank transfer, PayPal, Apple Pay, Google Pay, and cash are not presented as self-service payment methods today. They must not be promised unless provider configuration and XMS contracts explicitly support them.
Quote to label
The quote records carrier, service, expiry, price lines, total, proof hash, wallet coverage, and allowed funding sources before the client confirms a purchase.

Payment security
Provider-hosted collection, verified webhooks, idempotency, manual capture, durable recovery, and immutable ledger entries separate browser intent from money movement.
Only tokenized brand, last four, expiry, status, and provider reference are shown. PAN and CVC do not pass through XMS Cloud.
3DS/SCA steps use the provider client secret, then XMS re-reads durable payment state before completing the purchase.
Top-up, hold, capture, release, and adjustment entries retain source references, transaction groups, and immutable proof.
Inbound and catalog self-service
Catalog identity and versioned inbound plans reduce receiving ambiguity without allowing a merchant to rewrite warehouse truth.
Everything in the client workspace
Create and follow orders; review available, reserved, inbound, and held stock.
Compare prices, inspect proof, buy and reprint labels, track delivery, and retain void evidence.
Request returns, follow disposition, correct imports, and resubmit records that need attention.
Monitor integrations, issue scoped API keys, configure signed webhooks, notifications, and test events.
Plan the customer boundary
Map roles, catalog ownership, funding mode, limits, approvals, labels, returns, evidence, integrations, and support escalation.