Scoped credentials
Keys are restricted to an organisation and declared permissions; service credentials never enter browser bundles.
Developers
Use stable contracts instead of private database coupling. The checked-in foundation is not a production webhook service: receiver-secret handoff, DNS/IP egress enforcement, key issuance, endpoint and delivery certification remain required.
Keys are restricted to an organisation and declared permissions; service credentials never enter browser bundles.
Stable request and external IDs support safe retries for currently permitted operations. Financial mutation commands remain closed until separately governed and certified.
The dispatcher models signatures, stable event IDs, retry and status history. One-time receiver-secret provisioning and redirect-safe DNS/IP egress controls are not implemented, so delivery must stay disabled.
Responses use explicit definitions and states. Exact monetary transport remains a production-certification requirement; current API consumers must not assume decimal-string money.