ClaraWideCallback signing-key lifecycle QA
v0.12.30 · CALLBACK KEY LIFECYCLE

Rotate the key without creating a blind spot.

This release keeps raw callback secrets outside D1 while ClaraWide owns the key-version metadata, bounded overlap, strong-auth rotation authorization, retirement evidence and exact key attribution used by provider receipt verification.

SCHEMA + ATTACK PATHS

Automated key-lifecycle checks

Confirms schema v29, one-time strong-auth rotation authorization, dual-key overlap, expiry, forward-only retirement and immutable lifecycle evidence.

NOT RUNSchema check has not run yet.
NOT RUNSelf-test has not run yet.
VISIBLE ROTATION FLOW

v1 → overlap → v2 → retire v1

The unsafe step is intentional: rotation must fail before the current session has strong-auth step-up and a one-time authorization.

READYStart with a QA Callback Key Admin session.
KEYRING

Metadata only — never raw secrets

No key state loaded yet.

LIFECYCLE EVIDENCE

Immutable rotation history

No key events loaded yet.

PRODUCTION GATE — DO NOT FAKE

Production callback-key evidence

These remain open until a real provider, real external secret storage, real callback traffic and a rehearsed rotation/recovery procedure exist.

Recent key QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence does not rewrite server-owned callback-key metadata or lifecycle events.