diff --git a/static/docs/errors.html b/static/docs/errors.html new file mode 100644 index 0000000..af8f9ff --- /dev/null +++ b/static/docs/errors.html @@ -0,0 +1,98 @@ + + + + + +bitSpire — Dispenser error glossary + + + +

Dispenser error glossary

+

Every dispense failure a machine reports carries an error code (the family — which driver), a raw code (what the hardware said), and a class that decides what the machine did next:

+
+
terminal
+
The transport path is compromised. The machine has taken cash-out out of service and will stay that way until you open it. Clear the path, then record a Recount (which also fixes the bay count) or press Resume cash-out. Re-initialising the dispenser does not move a stuck note, so a restart will not clear this.
+
recoverable
+
This bay or this note. The customer still sees a fault screen if they were short-changed, but the machine stays in service. Check the bay named in the report and the reject tray.
+
inventory
+
Nothing was asked of the hardware — the request could not be met from the bays. Not a hardware fault. If this happens after payment, the customer is still owed (see the worklist).
+
+

Whatever the class, a report that is not dispense_confirmed after a payment means a customer is owed money. The worklist shows it as Cash owed (nothing dispensed) or Partial dispense (some notes out). Nothing has been distributed; the funds are in the machine wallet. Resolve by dispensing the shortfall at the machine (the machine reports the remediation and the settlement completes) or by paying the customer by hand and recording it with Settle off-machine.

+ +

Fujitsu F53 / F56 (error code F56DispenseError)

+

Codes are the two bytes the BDU returns after a failed bill count. Source: Fujitsu Frontech F56-BDU Error Code List (K3KD03234–K3KD03236-0001, ed. E02) and field observations. An unknown code is treated as terminal until it has been decoded.

+ +
+

78 42 — note stopped at the cassette exit terminal

+

A note left the bay and stopped in the transport just past the cassette. The counters report 0 dispensed, 0 rejected because the note completed neither path — so the bay count is also one high until you recount.

+

What to do: open the unit, remove the note from the transport path, check the cassette is seated, then Recount the bay (this releases the cash-out hold and corrects the count). First seen: sintra, 2026-10-09 — a 20 EUR note, customer paid 40 EUR and received nothing.

+
+ +
+

82 00 — bill length check failed (long) recoverable

+

The BDU measured a note longer than the accept window configured for that denomination and rejected it. Repeated on every pick from one bay, it is almost always the configured window, not the notes: a GTQ Tejo rejected 5 of 5 on every pick in 2026-09 because the window was ±5 mm where the identical-size USD note has ±10.

+

What to do: empty the reject tray and look at the notes. Single notes → window too narrow; report it. Pairs → the separator is worn (offset double-pick) and the narrow window is doing its job.

+
+ +
+

83 00 — bill length check failed (short) recoverable

+

As above, measured short. Torn or folded notes, or the wrong denomination loaded in the bay.

+
+ +
+

84 00 — bill thickness check failed recoverable

+

Two notes stuck together, or a taped/damaged note. Check the reject tray.

+
+ +
+

85 0n — pick from another safe recoverable

+

A note arrived from a bay other than the one commanded (n = which). Usually a cassette not fully latched.

+
+ +
+

86 00 — bill spacing error recoverable

+

Notes too close together on the transport. Often follows a worn feed roller.

+
+ +
+

B5 .. — reject box overflow terminal

+

The reject tray is full; nothing more can be rejected, so nothing more can be dispensed safely.

+

What to do: empty the reject tray, count what is in it (those notes left a bay), Recount.

+
+ +
+

Unrecognised code terminal

+

A code not yet in this table. The machine treats it as a jam — cash-out held — until someone decodes it. Please report the raw code with what you found inside the unit so it can be added.

+
+ +
+

DispenseTimeout — dispenser did not answer terminal

+

No frame came back within the dispense timeout (serial timeout, port closed, framing error). The transport state is unknown; the bay counts are flagged unverified.

+
+ +

Puloon LCDM (error code PuloonDispenseError)

+

No decode table yet; every Puloon fault is treated as terminal. The raw code is whatever the driver returned — report it.

+ +

Software-side codes

+
+

InsufficientInventory / NoCassetteForDenomination inventory

+

The request could not be met from the bays as the machine believes them to be. After a payment this still leaves the customer owed; before one, the sale is simply refused. If the bays physically hold more than the machine thinks, Recount.

+
+
+

DispenseShort inventory

+

The dispenser returned fewer notes than requested and reported no error. The customer is owed the difference.

+
+ +

Reference: bitspire docs/adr/005-cash-out-dispense-outcome.md, Decisions 3–7.

+ + diff --git a/static/docs/operator-guide.html b/static/docs/operator-guide.html new file mode 100644 index 0000000..363af30 --- /dev/null +++ b/static/docs/operator-guide.html @@ -0,0 +1,75 @@ + + + + + +spirekeeper — Operator guide + + + +

spirekeeper — operator guide

+

spirekeeper is the operator side of a bitSpire ATM: it pairs machines, publishes their fee and cassette configuration, receives every cash-out's outcome, and distributes each settlement. Everything between you and a machine travels over Nostr relays — there is no HTTP endpoint on the machine and none it needs on you.

+ +

1. Setting up a machine

+
    +
  1. Register it under Machines with a name, location and fiat currency, and pick the LNbits wallet that receives its payments.
  2. +
  3. Pair it: Pair mints a one-shot spire-seed QR. Show it to the machine's camera (an unpaired machine boots into the pairing wizard). Pairing gives the machine its signing identity through the bunker; no key is ever typed into the machine.
  4. +
  5. Fees: your per-machine cash-in / cash-out commission plus the platform fee are published to the machine automatically whenever either changes, and delivered again on every boot.
  6. +
+ +

2. Bays and cassettes — who decides what

+

The machine owns its bay layout and its running counts. How many bays it has is hardware; which denomination sits in each and how many notes are there is something only the person at the machine knows. So:

+ + + + + +
FactWhere it comes fromHow you change it
Number of baysThe machine's installation (VITE_BITSPIRE_CASSETTES in its .env on first boot, then its own database). spirekeeper adopts whatever the machine reports and deletes bays it stops reporting.Re-provision the machine. There is no dashboard control for bay count.
Denomination per bayYou.Set denomination op.
Count per bayThe machine's running total: refills add, dispenses subtract.You publish operations, never counts: Refill +N, Empty, Recount. A recount is the only absolute — it is what you do when you open the bay and count it.
+

Never set a count from a form you loaded before a dispense happened — that is exactly why counts are not editable. If the number on screen is wrong, open the bay, count, and record a Recount.

+

Each operation carries an id the machine deduplicates on, and the machine echoes the ids it has applied back in its state report; an op shows as acknowledged only when the machine says so. The machine republishes its state on every change and on a heartbeat, so a dashboard that disagrees with a machine heals itself within minutes.

+ +

3. What a cash-out looks like now

+

Payment is the authorization; the machine's dispense report is the capture. A customer's payment lands as awaiting_dispense and nothing is distributed until the machine reports what physically came out:

+ + + + + + +
Machine reportsSettlementWhat happens
Everything dispensedprocessedDistribution runs — platform fee, your splits, DCA.
Some notes out, value shortpartial_pendingHeld whole until you record how the shortfall was resolved.
Nothing outcash_owedNothing moves. The customer is owed. You are alerted.
No report within 30 mindispense_unreportedThe machine never said. Check it.
+

Those last three are the first thing on the Worklist. Every one means a human is owed money or a machine needs eyes.

+ +

4. When the machine takes itself out of service

+

A terminal dispenser fault — a jam, a motor or sensor error, a dispense that never answered — makes the machine refuse further cash-out and show the customer that it is temporarily unavailable. The machine's card in spirekeeper shows a red Cash-out is held banner with the code and the reason. It stays held until:

+ +

Restarting the machine does not clear it: re-initialising a dispenser does not move a stuck note. See the error glossary for what each code means and what you will find inside.

+ +

5. Resolving owed cash

+

Two ways, both audited, both close the machine's ledger as well as this one:

+ +

For a partial, Record the resolution opens the partial-dispense dialog pre-filled from the machine's own count of what came out: confirm it if you are writing the shortfall off (the settlement distributes the scaled amount), or use one of the two routes above if you made the customer whole.

+ +

6. Alerts

+ +

When a settlement lands in cash_owed or partial_pending you receive a Nostr direct message (NIP-17) addressed to the pubkey on your LNbits account — a note to self, readable in any client that speaks NIP-46 (the aiolabs webapp, Amber, nsec.app). You do not need your private key for this. To receive alerts on a different identity, set Alerts pubkey in the platform settings.

+ +

7. Reconciling a machine

+

On the machine, atm-reconcile re-derives each bay from its last recount plus refills minus dispenses and reports any gap. A bay that has never been recounted cannot be reconciled — its starting number is unrecorded. Recount every bay once after installation; after that, any gap is real.

+ +

Design record: bitspire docs/adr/004-cassette-state-synchronization.md and docs/adr/005-cash-out-dispense-outcome.md.

+ +