Kiosk clock-in
Dedicated tablet PWA for shared clock-in stations — front desk, warehouse, job site.
The kiosk PWA is a separate installable app pinned to a single physical tablet. Employees walk up, tap their name + 4-6 digit PIN, and clock in or out. A single tablet can host multiple kiosk PWAs (one per location) — each with its own home-screen icon and its own scope.
When to use kiosk vs web / mobile
Office kiosk
Field-service kiosk
Web / mobile
Register a kiosk
Settings → Kiosks → Register. Fill in a display name ("Front Lobby") + optional location. Server returns a one-time device token shown ONCE in the create dialog — copy it before you dismiss. Admin then walks over to the tablet, opens the kiosk URL in a browser, pastes the token, and taps Install as app in the top bar to add the PWA to the home screen.
Identity + proof-of-work capture
Kiosks capture identity + work proof orthogonally. Selfies answer who; job photos answer what. The capture cadence depends on the kiosk's location context and the user's proof-of-work policy.
- ✓Office kiosk + selfie required — first-of-day identity capture at clock-in (Alice's next 4 clock-ins today skip the selfie)
- ✓Field kiosk + require_proof_of_work=true — job photos at clock-out (per site visit); selfie skipped
- ✓Kiosk-only users on field context — job photos are HARD-required (no skip button)
- ✓Kiosk-preferred / any users — job photos are SOFT (entry flagged proof_of_work_pending, admin follows up)
Recovery PIN — for stuck tablets
If a tablet's storage gets wiped (browser upgrade, IT policy reset, factory restore), the device token is gone and the shell drops to the provisioning screen. Without a recovery mechanism, admin would need to physically visit the tablet + paste a fresh token. The recovery PIN closes this gap: admin sets a 4-8 digit PIN per kiosk at registration (Settings → Kiosks → Set PIN); the on-site tech taps "Lost your token? Recover with PIN" on the provisioning screen, enters the PIN, and the server issues a fresh device token — no admin round-trip.
- ✓Bcrypt-hashed on the server (nobody can read the PIN back)
- ✓Rate-limited: 5 failed attempts per rolling 1-hour window per device
- ✓Every attempt (success, fail, lockout) written to the audit log
- ✓Rotate the PIN independently of the device token whenever needed
Session-integrity guards
16-hour max session
Cross-device concurrency
Single window per kiosk
Rotate the device token
Suspected leak? Employee offboarded? Scheduled rotation? Settings → Kiosks → Rotate token issues a fresh token without changing the device ID — historical time entries, installed PWA scope, and previously-emailed setup URLs all keep working. Only the token itself changes. The next launch on the tablet drops to provisioning; paste the new token and continue.
Kiosk-only enforcement
Set a user's clockInSource to kiosk_only on Edit User → Access & Time Entry. From that point on the server rejects any web / mobile / timer clock-in attempts from that user — the ONLY legal path is a physical tap on a kiosk. Combined with field-context job photos, this is the auditable per-session proof pattern used by staffing agencies and field-service firms.
Version pill + support
The kiosk top bar shows a small version pill (v0.1.27 etc.) baked in at build time. Support can ask "what version is this kiosk running?" without needing DevTools. The version pill also lets admin confirm a rollout succeeded at a specific tablet after a Deploy Live workflow.