by Intelliverse X

Operator for Android, iPhone and iPad

Open the illustrated installation atlas and cabinet checklist.

Install the approved Operator app on the phone and sign into the intended account.

Instructional illustration; screens and device details vary. Follow the exact steps and approved release record below.

Operator manages the fleet from your phone or tablet. The vending cabinet runs a separate controller-specific application. Installing Operator on a phone does not install a motor driver or establish that an unidentified machine is supported.

Operator 3.2.6: publish screen experiences

Download the verified Android 3.2.6 / build 47 APK. Android build 47 and signed Apple build 44 add Machine → Publish an app to this screen: stage a disabled draft, publish to a compatible Android 9+ ZHZN player, reload after a conflicting edit, or disable future opens. Follow the screen publishing guide. A saved mapping is not a playback receipt. Use the verified Apple 3.2.6/build 44 TestFlight release below on iPhone/iPad. The separately generated unsigned IPA remains unsuitable for normal-device installation.

CI 34147585485 passed analysis, tests and signed release assembly. The publicly downloaded APK is 88,828,413 bytes, package ai.intelliversex.operatorx, Android API 24+, target 36, from source 7cbd212f4285571256ebea4bb1f31793ac9136a5. SHA-256: bd30968aa2070eb66512fe1d2cb53dbc6ff3ed0b3bfe305ea10e59880db70f3b. Android signature verification passed with certificate f049cb52d14b1477e5a07396958180559d036fa2e207f209b6ca928df99cfed0. No physical cabinet acceptance is claimed.

The exact public build 47 APK also passed a fresh offline Android 14/API 34 ARM64 install, cold launch and synthetic login-error check on September 7, 2026 at 17:47:48 UTC. Camera permission remained denied, no default network was active, and 60 seconds of observation recorded no app fatal exception, ANR or crash-buffer entry. The login screen retained a clear network-error message. This checks startup and offline failure handling; it does not exercise an authenticated fleet or physical cabinet.

Use the current Android download above or the signed Apple build 44 through your existing TestFlight access. Historical artifact evidence remains explicitly labeled below.

Choose the correct download

Application Verified release How to install
Flutter Operator for Android 3.2.6, build 47; Android 7.0/API 24 or later; ARM32, ARM64, x86_64 Install the signed APK on the operator's Android phone/tablet. Package: ai.intelliversex.operatorx.
Operator for iPhone/iPad 3.2.6, build 44; iOS 15 or later Apple processing completed on September 7, 2026, and the build was distributed to existing internal TestFlight testers. Existing testers choose Update. New tester access still requires an assigned invitation; no public invitation is published here.
Native Android Operator 3.2.1, build 7; API 24+ Separate Kotlin/Compose app, ai.intelliversex.kioskx.operator. Includes audited money/fleet behavior; use Full console for expanded setup, MFA and refunds.
Cabinet applications Reyeah and ZHZN have different packages Choose the installer using the actual controller: machine-app selection, Reyeah, ZHZN.

Historical Android build 46 evidence

The earlier Android 3.2.5/build 46 signed file was verified on September 7, 2026. Its anonymous public download and new immutable key matched the full digest and byte size at 2026-09-07T16:38:18.994981Z. Its complete SHA-256 is:

16c4f8ebafb7d87b533b602d511354afa1e0c941adb5d3215c2f711febb18d35

Its signing-certificate SHA-256 is:

f049cb52d14b1477e5a07396958180559d036fa2e207f209b6ca928df99cfed0

Android build 46 comes from merged source 9d53547d6fd1719b1fda951811ca90a531c359a5. Main CI 34142863219 published the verified 88,746,489-byte APK targeting API 36; 922 Flutter tests, 605 web tests, the analyzer and TypeScript checks passed. It includes the explicit cash-receipt and captured-payment review workflows illustrated below. Its executable source matches the audited candidate. The exact public APK is covered by an isolated API 34 ARM64 install, cold-launch and offline-login check, with camera denied, no default network and no fatal exception/ANR or crash-buffer entries over 60 seconds. The public APK check completed at 16:40:15 UTC on September 7, 2026. No real credentials or cabinet operations were used.

Native Android build 7

Native build 7 was published from 9b661a6245f6906cfba43340402cf65c825fdb6c with the verified operator signer. Its Android source is unchanged in the newer Flutter/web integration. Its 12,985,945-byte APK SHA-256 is 99fc2f7e043a3bb60cc60593df138b3c9569749316b501856c5cd5c66822afc2; main CI 34098691373 published it. Its Android subtree retains the 9 passing unit tests and its exact bytes are covered by an isolated API 34 ARM64 install/launch/offline-login smoke. It is a separate package and does not update Flutter Operator.

Current Apple build 44

Apple 3.2.6/build 44 comes from source 7cbd212f4285571256ebea4bb1f31793ac9136a5, the same commit as Android build 47. Both have Flutter tree 3bccec063a949551d1863643b7c8b73f51104d55, including screen-experience publishing and cash/captured-payment review. CI 34148908181 produced signed artifact 10028855904; Apple processing completed September 7, 2026 at 17:54:59 UTC and distribution to existing internal TestFlight testers completed at 17:55:00 UTC.

The IPA is 26,435,316 bytes, SHA-256 57b22c071c1537ca41cdb11cb78573075683f30f4d824e4243efcfbb46fe1e88. Its bundle is com.foundrly.hotbox.operator, iOS 15+, iPhone/iPad, built with iOS SDK 26.5. Independent strict/deep signature verification passed with the original Apple Distribution certificate 9759dcbbad3e4d5544826b28707791b67983ab236a5441e47b42ebe5a3aac745, team F76FYY3Q7V. The App Store profile expires August 14, 2027 and disallows debugging. This is an internal TestFlight release; no public invitation, external distribution or physical-device acceptance is established.

Historical Apple build 43

Apple build 43 comes from source 17afaa661a71a69c13507796cc73032eff7fdd45. CI 34146600222 produced artifact 10028100010; processing completed at 17:21:37 UTC on September 7, 2026 and distribution to existing internal TestFlight testers completed at 17:21:38 UTC. New tester access still needs an assigned invitation.

Its signed IPA is 26,425,360 bytes, SHA-256 30c0c7d68b324910746b6b7dbfacc041d3e60f219d0435161d37ff8b9d3e8781. The bundle is com.foundrly.hotbox.operator, signed by Apple Distribution: Foundrly Inc, team F76FYY3Q7V, for iPhone/iPad with iOS SDK 26.5. Independent strict/deep signature verification passed and the signer matches the embedded App Store profile, which expires August 14, 2027 and does not allow debugging. This identifies a TestFlight artifact; it is not a direct-sideload invitation.

Build 43 includes the explicit cash-receipt and captured-payment review workflows as well as the earlier setup/address, money/currency, complete-fleet, crew-invitation, private remote-control and transport/refund-recovery audit repairs. Its Flutter source tree c14111fbaad4b922e9f8a76c0ecf5cff7085340a matches Android build 46; their repository commits differ because of a web-only sign-in repair. Apple processing does not establish physical device or cabinet acceptance.

Historical Apple 3.2.4/build 42 is superseded by build 43. Its retained IPA identity is 46d29513dd7b4919a12153cb1b16602c5e7759d2ee361c335e6249b7db0134d7 (26,411,053 bytes), source f2fddeb0b2a73e65d4c4163d4c9aae85f7664279, CI 34136661742. Historical 3.2.3/build 41 has IPA identity 3842d542cac5f9c78cdb054a69687ceaddef10c4595e43ff2cee2b34cc079c52, from CI 34092897551. These earlier files lack the latest payment-review changes; do not confuse them with the current build.

The unversioned Android URL may change after future releases; use the pinned file and digest when planning installation.

What works in the inspected phone releases

“Available” means the inspected source has the screen/API workflow. Physical operation still depends on the installed cabinet agent, controller profile, permissions, network and backend. Neither phone platform was exercised against a physical cabinet in this verification.

Workflow Android / Apple release status Cabinet requirement or limitation
Publish an app to this screen Android 3.2.6/build 47, Apple 3.2.6/build 44 and current web; absent from historical Apple build 43 Requires the corresponding Android 9+ ZHZN player capability. Save a disabled draft first; publish and verify on-screen behavior.
Sign in, MFA, fleet and machine identity Available Sign in under the owning operator; match the cabinet's actual machine number.
Claim/register, map location, setup status Available Claiming a record does not configure the physical controller or payment merchant account.
Review address match and separately confirm installation Android and Apple since 3.2.3; current web Compare a complete numbered address with an eligible map candidate. Attest installation only after observing the cabinet. New setup requires both confirmations before Go live; existing live cabinets retain normal operation. See address and installation checks. Postal deliverability and unit validation are not established.
View products, prices, stock and sales Available Confirm that the cabinet reports current data and displays the same price/currency.
Record stock changes and refills Available Physically fill first; a saved count does not load product.
Edit product name/code, price, age tier and lane availability Available since 3.2.1; retained in the releases above Open Machines → machine → aisle → Edit product & price. Confirm cloud and cabinet readback. Image/category edits still use the authorized web/API editor.
Inspect failed/unconfirmed delivery and refund state Available Payment success and delivery are separate. Confirm actual refund processor evidence.
Nayax reader association Available Associates reported transactions with the machine. Nayax merchant/bank settlement is configured separately; see Nayax and revenue.
Initiate a supervised test vend No test-vend button in these Flutter releases Use the approved cabinet service procedure or authorized supervised web workflow. A command acceptance is not proof of a product drop.
Reboot and OTA checks Available when the backend/agent supports them MQTT/agent delivery, installed permissions and actual post-action reports determine the result.
Tray survey, board settings and service PIN Conditional controls Reyeah OEM configuration and ZHZN/CSM configuration differ. Never apply guessed wiring settings.
Remote screenshot/live view/input Private-frame support since 3.2.2; conditional controls Requires the matching gateway and updated agent, explicit readiness and a known app/device scope. Older Operator releases cannot load the new private frames.
Network provisioning Conditional workflow Android and Linux agents differ; follow the manual matching the installed stack.
Transfers, restock ledger, payroll and host-payout records Cloud workflows These records do not enable an unsupported motor protocol or prove a bank transfer occurred.
All Silkron editions and all retrofit machines Not established No verified licensed Vendron adapter or universal retrofit hardware profile is available here.

The aisle editor, response-specific currency metadata and checked sign-in persistence were introduced in 3.2.1 and remain in the releases above. The editor reads fresh inventory before opening, retains that machine's currency while editing, and omits stock and unchanged availability from a catalog save. Unknown currency or unsupported decimal precision prevents saving. Re-enable a faulted lane only after repair and physical testing. A save error can leave its outcome unconfirmed: reopen the aisle and check the recorded values before repeating the change.

Review a disputed payment or partial cash delivery

Open Refunds in the web console, or Money → Refunds in the current Flutter app. Open the original order from the queue and compare its machine number with the cabinet.

Example Operator order shows an original USD 3.29 quote and a separate EUR 3.50 capture, with the refund decision held for review.

Open the full-size example.

Actual web-app screen with synthetic example records. The amounts explain the display; they are not a real payment, refund or acceptance result.

  1. Cash receipt needs review: keep the original reported cash amount. Check the first accepted delivered/undelivered counts, then observe the remaining stock and what cash was actually retained or returned. The refund amount stays unknown until authorized reconciliation.
  2. Payment amount needs review: compare Original quoted sale with Actual captured payment, including both currencies. Use the original processor record to resolve the discrepancy; the quote is not the amount to refund automatically.
  3. Whole-order refund controls remain unavailable during these reviews. An unavailable total is not zero. Preserve the original order and device/processor references; do not create a replacement paid order or repeat a vend.
  4. A completed refund needs evidence of the actual return. A record reporting zero captured money does not mean the original quoted sale was free, and it does not establish that money was returned.

Follow the partial-cash reconciliation procedure. Native Operator uses Full console for this expanded workflow. Android builds 46–47 and Apple builds 43–44 include these review screens.

Remote access from the phone

Use Machines → machine → Remote screen → Enable remote screen → Capture → Live → Control. See the Android cabinet remote-access guide for cabinet setup and unattended-access limits.

Operator 3.2.2 and later fetch screenshots using your operator session. After the gateway changes to private frames, older Operator builds need updating before this view works. Capture again after updating; legacy public-frame metadata is unavailable.

Control requires a decoded frame no more than 15 seconds old, an updated agent advertising normalized input, and a ready app/device scope. The ZHZN app controls its own foreground kiosk activity; Home means the app start screen, and typed text requires a supported native field. The Reyeah companion requires an already-rooted cabinet plus an explicitly configured role, machine number and credentials before it can control the whole Android device. Its text input supports printable ASCII with bounded length and execution time. This is not a remote-rooting or universal unattended-access feature.

A submitted input consumes the displayed frame. Another input is blocked until the matching execution outcome and its exact follow-up capture arrive. A failed outcome stops Control. If a response or acknowledgement is missing, review a different fresh frame and explicitly restart Control after the waiting period; the app does not automatically repeat the command. Input injection is not proof of a successful payment, vend, price update or other business action.

Machine compatibility

Machine Supported integration path Qualification still required
Confirmed Reyeah JD controller Reyeah cabinet APK, cloud device API and MQTT Controller/ROM, serial permissions, all configured lanes, payment paths, report recovery and physical acceptance.
Confirmed ZHZN / CSM controller Matching ZHZN Android APK and registered controller profile Spring versus Y-lift profile, wiring/addresses, device enrollment, permissions, lane/payment/recovery acceptance.
DFY cabinet DFY is a service/ownership arrangement, not a hardware protocol Identify the installed controller and use its corresponding integration.
Photographed VC EL cabinet / unconfirmed Silkron No verified machine integration yet Identify controller and installed software, repair screen instability, then qualify a supported adapter.

Use the Reyeah manual, ZHZN handover, ZHZN release verification, VC EL diagnosis, or Silkron integration status. Brand appearance and a successful APK installation are not hardware certification.

Android installation

  1. Download the pinned Flutter Operator APK above onto the operator's compatible Android phone/tablet. Verify its digest and match the installed application's signing certificate before an update.
  2. Open the file and permit installation from the selected download/file app if Android requests it. Do not uninstall a working installation merely to bypass a signature mismatch; that can erase local configuration/session data.
  3. A technician using a connected, explicitly selected phone can instead run:

sh adb -s '<operator-phone-adb-serial>' install -r 'operator-x-3.2.6-bd30968aa207.apk'

  1. Open Operator, sign in, complete MFA and verify the intended fleet and machine number. Camera permission supports QR scanning. Review the structured address and separately record on-site installation; a GPS fix alone does not provide that evidence.
  2. Complete the cabinet's own acceptance checklist. A phone login is not cabinet enrollment. This Android release uses version code 47, advancing code 46. Earlier 3.2.3/build 44 files remain historical releases. Always verify both version name and version code. Retain the expected signing certificate and verify updates on the intended phones before rollout.

iPhone/iPad installation

The verified IPA is signed with an App Store/TestFlight profile. It cannot be installed directly like an Android APK. The older publicly generated unsigned IPA is also not a normal-device installer.

  1. Existing internal testers can update to 3.2.6 (44). Apple processing and internal distribution are verified for this build. A new tester still needs the release owner to assign access and supply the real invitation.
  2. Install Apple's TestFlight, open the invitation, choose Accept, then Install; existing testers choose Update. See Apple's TestFlight installation guide.
  3. Open KioskX Operator, sign in and complete MFA. Confirm camera/location permissions and the correct machine record, then perform the same cabinet acceptance steps as Android.

A separately signed development/ad-hoc IPA can be used only through an authorized distribution process with the intended registered devices and matching provisioning profile. The App Store build above is not an ad-hoc build. See Apple's registered-device distribution guide.

Apple-specific feature limits

The verified build 44 provisioning profile contains neither App Groups nor Associated Domains. Its shared fleet-widget session and HTTPS universal links have not been established as operational. The widget target requires iOS 16. These features need their capabilities/profiles configured and physical-device verification before being promised.

For build 44, CI confirms completed Apple processing and distribution to internal testers. It does not establish a public invitation, new tester access, external review or an App Store public release. No external distribution or external notifications were requested. New uploads must use Apple's supported toolchain; Apple has required Xcode 26 with iOS/iPadOS SDK 26 or later since April 28, 2026. Apple requirements.

No physical phone installation, live payment or vend was performed for this artifact verification. Record successful acceptance against the exact Operator, backend, cabinet APK, controller and firmware versions before operational rollout.