the future of IoT is HTTPS with client side X.509 authentication. you don’t need internet to make that happen. but if you are web based and not using HTTPS... i can only ask why not? internal CAs are free
sign the certificate in the manufacturing plant and put it in the coffee maker l. give the CA cert out in the app or the installer. now you can verify if the coffee maker talking to you over HTTPS is legit and probably get it’s serial number off the cert too. your CA keys never see the public. you could go even more secure and use that as a bootstrap to a per customer CA and generate a new cert on install, but this is a coffee maker right?
you don’t need to install any certificates in any case. the server just needs to validate the client is well signed