Authentication & TaxCore (S3-S4) §3 — Authentication & token acquisition Access to TaxCore.API requires a bearer token obtained by authenticating with the on-card PKI certificate . XPOS ESDC performs a mutual-TLS request to /api/v3/sdc/token in which the client certificate and private key are the SE's PKI key, exposed through OpenSC PKCS#11 . The private key never leaves the card — the TLS handshake's client-certificate signature is computed on the SE. TLS renegotiation The FRCS token endpoint requests the client certificate via TLS renegotiation (the initial handshake asks for no certificate; the server then issues a HelloRequest to demand the card certificate). XPOS ESDC performs this exchange over TLS 1.2 with client-initiated renegotiation supported, using the card key via PKCS#11 for the certificate-verify signature (PKCS#1 v1.5, SHA-256). The server certificate is pinned on first use. The returned token is cached and refreshed before expiry, and presented as the TaxCoreAuthenticationToken header on all subsequent data calls (§4). §4 — TaxCore.API & command processing All communication with TaxCore uses the token from §3. XPOS ESDC receives and executes the full command set, in the order received, and reports the result of each command back to TaxCore. Command Action SetTaxRates Install/replace tax-rate groups, including future-dated groups (§6). SetTimeServerUrl Set the NTP server used for time synchronisation (§13). SetVerificationUrl Set the base verification URL used on receipts (§8). SetTaxCoreConfiguration Apply TaxCore configuration parameters. ForwardProofOfAudit Apply a proof-of-audit to the SE via End Audit (§9, §12). ForwardSecureElementDirective Relay a directive to the SE. Commands are processed consecutively (first to last); each result is reported so TaxCore has an accurate record of execution.