This seems to be an odd request. I mean, how are your users going to get through the OAuth flow? Is every merchant going to have a "server" running on their local machine?
A web app? Do you expect that the merchant will have a server running on the same host from where they run their browser?
Without knowing anything else I'd think there'd be security concerns as the browser won't be able to verify the identity of the local server.
It's designed to run locally, and of course, it's wired with limited internet access.
Security from our end won't be an issue.
The only unknown is can we set localhost as part of the PROD app. Will API endpoints work the same as in a domain.
Still not clear to me how to ensure the thing you are talking to is your server. What would stop malware from listening on the same port you expect?
So it seems it supported. Please contact appmarketbusiness@clover.com to understand if this is something that would be allowed in production.
2 People are following this question.