Open-source POS development
Build, inspect and contribute to Posnic POS
Start with the stable source, reproduce the API evidence or choose a bounded contributor task. Roadmap issues are not shipped integration promises.
Externally preserved source: Software Heritage completed a full archival visit of the public Posnic/POS repository on 24 August 2026. Open snapshot swh:1:snp:1e711359375fbfd76a3b67aecc085bfe2be4ca8d. This records that repository visit; it is not a review, endorsement, security audit, adoption result or promise that later commits are already preserved.
How the local application is assembled
Electron starts the local services
The Electron main process starts the bundled MongoDB service and the in-process Express API, then serves the desktop user interface. This describes the source at the pinned release, not every future build.
Ports are derived, not fixed at 5555
The release searches MongoDB ports 47000-47899 and API ports 42000-42899, then saves the selected pair in .ports.json. Stock documentation examples use MongoDB 47590 and API 42590. Integrations should read the installation's selected port instead of assuming a universal number.
The desktop screens use the local API
The repository contains an Express API with route groups for sales, products, inventory, customers, reports and administration. Authentication, authorization and request shape still matter; source availability is not a promise that every route is a supported external integration contract.
Verify the implementation in local-ports.js, the API source and the API document.
Reproduced API test result
We installed the exact stable release API dependencies and ran its curated Jest suite on 17 August 2026. These numbers report that one command and should not be read as an independent security audit or a full installed-shop acceptance test.
204 total; two skipped.
7,966 total; 13 skipped.
The command exited successfully.
Node 24.19.0 and npm 11.17.0.
Reproduction command
git checkout
npm --prefix api ci --ignore-scripts --no-audit --no-fund
npm --prefix api test
The run emitted Mongoose validateSync() deprecation warnings. It did not run the repository's hosted functional or Playwright paths, did not provision a real shop database, and did not prove hardware, installer or cloud behavior.
Public POS research files and synthetic test data
These files make Posnic's terminology, official pricing-model review, buyer requirements, reusable acceptance fixture and release evidence easier to inspect, cite and reproduce. They contain no real merchant sale, customer, employee, payment-card or production-shop record.
| Resource | Published scope | Files | Do not infer |
|---|---|---|---|
| POS terminology source map | Nine working definitions linked to primary terminology or standards sources and paired with evaluation boundaries. | Download CSV | Read the definitions | No product ranking, market-volume estimate or replacement for each source owner's full guidance. |
| Free POS official pricing-model snapshot | Five dated official-page records separating each stated zero-price entry point from subscriptions, processing, hardware, add-ons and other operating costs. | Five-product CSV | Read the buyer guide | No complete market list, feature score, runtime test, independent recommendation, country-wide availability or promise that pricing has not changed. |
| POS requirements and procurement package | A 48-question RFP, 144 coded source-category observations from twelve public procurement records in six countries, a field-level Data Package descriptor, and a twelve-control scorecard. | RFP CSV | Evidence CSV | Data package JSON | Scorecard CSV | Nine full documents and three public notice, overview or opportunity records; no market-frequency, legal, compliance or current procurement requirement for another buyer. Review the method. |
| Vendor-neutral POS acceptance fixture | Four fictional items and thirteen ordered inputs across ten scenarios, with independently recomputable expected financial and stock results. | Manifest JSON | All four files and method | No real customer data, product pass, speed result, tax approval, payment certification or universal score. |
| Open-source POS official-source snapshots | Five core product records, a separate three-project watchlist and seven exact public GitHub default-branch heads, each pinned to a dated official source. | Five-product CSV | Three-project CSV | Seven-repository activity CSV | No competitor installation, runtime benchmark, recency ranking, maturity score or claim that one product is best. Read the method. |
| Posnic archived evidence coverage | Twenty-four protocol records mapped to observed scope, references, unestablished claims and the next required test. | Download CSV | Review every record | No independent hands-on result, customer outcome, production approval or certification. |
Machine-readable catalog and change detection
The catalog records each public URL, byte length, SHA-256 fingerprint, method and limitation. A changed hash means the file must be reviewed again; it does not identify whether the change improved the evidence.
Download the JSON catalog Cite this catalog (CFF) Review the editorial method
Publisher and usage boundary: Posnic Innovations Private Limited prepared this catalog and the Posnic-specific records. Public access does not create an additional data licence. Review the site terms and every cited source or software licence before reuse or redistribution.
API documentation has a count conflict
Three files in the same stable commit publish different endpoint totals. Until the source inventory and documents are reconciled, Posnic does not use one of these counts as a marketing fact.
| Source | Published total | How to use it |
|---|---|---|
| docs/API.md | 487 endpoints, 24 route groups and 102 request schemas | Useful as the most detailed API inventory, but still documentation rather than a generated contract. |
| README.md | 484 endpoints | Conflicts with the detailed API document. |
| docs/ARCHITECTURE.md | 478 endpoints | Conflicts with both other totals. |
Practical rule: inspect the route and schema at the exact release you deploy, test the calls you depend on, and pin your integration to a release commit.
App, connector and integration roadmap
The public repository now splits the app system into small, reviewable tickets. These issues are useful for contributors who want to help with POS ecommerce links, accounting exports, local connectors, marketplace review, hybrid mode and Community Edition apps.
Parent platform epic
One issue holds the boundaries: external API connections, sandboxed app pages and signed local connectors, with no third-party code loaded into the POS money path.
Contributor roadmap
New developers can choose small tasks with acceptance criteria before attempting bigger connector work. This keeps PRs narrow enough for review.
App platform starters
Starter issues cover connector manifests, SDK examples, health checks, scoped permissions, install audit events and safe settings storage.
Ecommerce connector tasks
WooCommerce, Shopify, Magento, WordPress, osCommerce, OpenCart, PrestaShop and other platform tickets start with research and synthetic fixtures.
Community Edition boundary
Local registry, import/export and signed sidecar connector work must remain useful when a shop runs without Posnic Cloud.
Marketplace review
Marketplace work starts with permission copy, review checklists, uninstall behavior, support ownership and screenshot evidence before paid distribution.
These are contribution and validation paths, not shipped compatibility claims. Do not infer accepted support for Shopify, WooCommerce, Magento, WordPress, payment providers or tax filing until the relevant issue has merged evidence and a release note.
What is not a published contract
No public sync protocol specification
The archived evidence run tree does not contain the previously advertised SYNC-PROTOCOL.md. Posnic therefore does not claim that any third-party server can implement a supported sync provider from a public specification.
Roadmap issues are not shipped integrations
Public issues now describe app, connector and marketplace work. They are contribution plans and acceptance criteria, not a live support promise, platform certification or delivery commitment.
Contribute with the same evidence standard
Follow the public roadmap
Released, reproduced, in-validation and planned work are kept separate. The roadmap names missing counter, recovery, hardware, security and integration evidence without promising delivery dates.
Build app and connector pieces
Start with issue slices for manifests, scoped permissions, local bridge rules, webhook fixtures, ecommerce mappings and marketplace review. Each ticket names the boundary before code.
Run the transaction fixture
Use the same fictional catalog and ten ordered scenarios, then report the exact package, environment, observed totals, failures and limits. A submission is not a certification or customer result.
Open the fixture | Review the publisher run | Inspect source supplement | Submit a Posnic run
Report an exact device
Name the manufacturer, model, driver, cable, operating system, test method, observed failures and untested paths. One report does not create universal compatibility.
Report real operation
Operators, installers and evaluators can record a live use, pilot, stopped install or production-like evaluation. Reports welcome failures and can explicitly refuse marketing reuse; submission is not an automatic testimonial or customer result.
Submit deployment evidence | Read the policy | Browse issues
Follow the contribution guide
Contributors retain copyright and sign commits using the Developer Certificate of Origin. Include focused tests and explain operator-visible behavior.
Report security privately
Do not publish a suspected vulnerability as a normal issue. Use the support route first so sensitive details are not exposed in a public tracker.
Product evidence reviewed 17 August 2026 against an archived evidence snapshot at archived source snapshot; public contribution paths reviewed 2 September 2026. See the product facts, runtime benchmark and organization record for the other evidence layers. Unaffiliated evaluators can use the 24-control independent review protocol to publish a separate hands-on result.