ClaraWideProvider delivery receipt QA
v0.12.30 · PROVIDER RECEIPT + KEY ATTRIBUTION

“Submitted” is not the same thing as “actually delivered.”

This release keeps provider submission evidence separate from authenticated delivery receipts. Signed callbacks can advance delivery truth; bad signatures and replayed event IDs are rejected, while contradictory terminal receipts are quarantined instead of silently rewriting history.

SCHEMA + ATTACK PATHS

Automated receipt checks

Confirms schema v29, callback-key attribution, HMAC verification, replay rejection, forward-only receipt state, immutable callback evidence and contradictory-terminal-event quarantine.

NOT RUNSchema check has not run yet.
NOT RUNSelf-test has not run yet.
VISIBLE CALLBACK FLOW

Submit → authenticate → reconcile

Use the staging simulator to prove the callback trust boundary without connecting a real provider.

READYStart with a QA Provider Admin session.
PROVIDER MESSAGE TRUTH

Submission vs final provider state

No provider-message evidence loaded yet.

AUTHENTICATED RECEIPTS

Immutable callback evidence

No callback receipts loaded yet.

RECONCILIATION

What Clara did with each receipt

No reconciliation events loaded yet.

CONFLICT QUARANTINE

Contradictory provider truth

A terminal receipt that contradicts prior terminal truth is retained and quarantined for review; it does not overwrite the earlier state.

No reconciliation conflicts loaded yet.

PRODUCTION GATE — DO NOT FAKE

Production provider receipt evidence

These stay open until a real provider, real signing key, real callback traffic and real bounce/complaint operations exist.

Recent receipt QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence does not rewrite server-owned provider messages, signed receipts, reconciliation events or conflicts.