Automated key-lifecycle checks
Confirms schema v29, one-time strong-auth rotation authorization, dual-key overlap, expiry, forward-only retirement and immutable lifecycle evidence.
ClaraWideCallback signing-key lifecycle QAThis release keeps raw callback secrets outside D1 while ClaraWide owns the key-version metadata, bounded overlap, strong-auth rotation authorization, retirement evidence and exact key attribution used by provider receipt verification.
Confirms schema v29, one-time strong-auth rotation authorization, dual-key overlap, expiry, forward-only retirement and immutable lifecycle evidence.
The unsafe step is intentional: rotation must fail before the current session has strong-auth step-up and a one-time authorization.
No key state loaded yet.
No key events loaded yet.
These remain open until a real provider, real external secret storage, real callback traffic and a rehearsed rotation/recovery procedure exist.
Clearing browser evidence does not rewrite server-owned callback-key metadata or lifecycle events.