ClaraWideProvider connection + safe egress QA
v0.12.32 · PROVIDER CONNECTION + SAFE EGRESS

Approve where Clara may talk before Clara is allowed to talk there.

ClaraWide now separates provider identity from provider credentials, pins outbound work to an approved HTTPS origin, accepts relative endpoint paths only, collapses duplicate idempotency keys, and records immutable egress evidence. This build intentionally does not make a real external provider request.

SCHEMA + ATTACK PATHS

Automated provider-egress checks

Confirms schema v31, unsafe/local origin rejection, unknown secret-name rejection, strong-auth provider approval, approved-origin immutability, absolute-URL blocking, idempotency collapse and immutable egress evidence.

NOT RUNSchema check has not run yet.
NOT RUNSelf-test has not run yet.
VISIBLE APPROVAL FLOW

Draft → step-up → approve → seal egress

The intentional blocks prove that neither an unsafe origin nor an unapproved/overridden destination can become outbound work.

READYStart with a QA Provider Admin session.
APPROVED DESTINATIONS

Provider registry

No QA provider connection loaded yet.

Sealed outbound intents

No sealed egress intents loaded yet.

IMMUTABLE EVIDENCE

Provider-egress history

No provider-egress events loaded yet.

PRODUCTION GATE — DO NOT FAKE

Production provider / egress evidence

These remain open until a real provider is selected, its exact production origin and secret references are approved, a bounded adapter is connected, provider failures are exercised and QA controls are disabled publicly. Checking a box here does not turn on provider traffic.

Recent provider QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence does not rewrite server-owned provider registry, egress intents or event evidence.