# Device

object type

A Device — the PHYSICAL hardware identity (native POS apps, the in-Office browser POS, the Pi legacy-peripheral bridge), kept separate from the logical Register it serves: the pairing ref is ONE-WAY Device→Register (0..1, re-pairable — registerId lives HERE, never on the Register). Born pending_pairing via the BESPOKE enrollDevice (the pairing code returns ONCE, TTL 15 min); completePairingDevice (PUBLIC — the code IS the auth) flips it active and returns the device credential ONCE (hash-only at rest; mandatory 12-month rotation, decision I). active ⇄ suspended is the kill-switch pair; dooms from active/suspended gate on the paired Register's open TillSession. At POS the REAL principal is COMPOSITE (decision E): device session (WHERE/trust) + user session (WHO/authority) — the auth seam. NOT searchable (infrastructure — the Register non-joiner stance).

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `id` | [ID](/types/#scalars) `ID!` | The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it. |
| `sysId` | [String](/types/#scalars) `String!` | The group-scoped human-facing system id (DE-…). |
| `type` | [String](/types/#scalars) `String!` | The kind of record — always `Device` here. |
| `caption` | [String](/types/#scalars) `String!` | The record’s display name — what people see it called. |
| `status` | [String](/types/#scalars) `String!` | The FSM state: pending_pairing \| active \| suspended \| doomed. |
| `parentId` | [ID](/types/#scalars) `ID!` | The parent LogicalFacility; rootId = the org group; parentId!== rootId always. |
| `rootId` | [ID](/types/#scalars) `ID!` | The org-group family root. |
| `createdAt` | [String](/types/#scalars) `String!` | When the record was created, as a UTC timestamp. |
| `updatedAt` | [String](/types/#scalars) `String!` | When the record last changed, as a UTC timestamp. |
| `revisionNum` | [Int](/types/#scalars) `Int!` | How many times this record has been edited; the first save is 0. |
| `revision` | [ID](/types/#scalars) `ID!` | The OCC revision token — supply it on every mutation of this record; rotates on every write. |
| `refCaptions` | [RefCaption](/types/RefCaption/) `[RefCaption!]!` | The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption. |
| `deviceType` | [DeviceType](/types/DeviceType/) `DeviceType!` | The canned hardware class — set at enrollment, IMMUTABLE. |
| `registerId` | [ID](/types/#scalars) | The 0..1 ONE-WAY Register pairing. Moves ONLY via pairDeviceToRegister/unpairDevice — never via update. |
| `code` | [String](/types/#scalars) | Optional mutable merchant reference code; uniqueness NOT enforced. |

## Used by

- [device](/reference/device/device/)
- [doomDevice](/reference/device/doomDevice/)
- [pairDeviceToRegister](/reference/device-fleet/pairDeviceToRegister/)
- [reactivateDevice](/reference/device/reactivateDevice/)
- [suspendDevice](/reference/device/suspendDevice/)
- [unpairDevice](/reference/device-fleet/unpairDevice/)
- [updateDevice](/reference/device/updateDevice/)
