{
  "contract": "sourcey.site-record/v1alpha1",
  "release_id": "sha256:f94358e3c57b6e575ca58c8031b9b7552cbfdb411f937b8ecdc3b042c4980a77",
  "snapshot_id": "sha256:0679a3f0d41c0733e76d10ab3fb1b331811893c7d428749740ec0f21ac731d3e",
  "artifact_sha256": "sha256:7472396c2449279d33e7a0fb2426f02a89991501262d1db8c04c81d57bdf9021",
  "data": {
    "entity_id": "ent_01kyygma830fqh16kvj744sk1c",
    "entity_slug": "stripe",
    "profile": {
      "projection_contract": "sourcey.agent-readiness-projection/v1alpha1",
      "agent_readiness_profile_id": "arp_01kzf0m4xk6m1tb8d5y3pr9wg2",
      "entity_id": "ent_01kyygma830fqh16kvj744sk1c",
      "scope": {
        "product": {
          "key": "stripe-payments-api",
          "name": "Stripe Payments API"
        },
        "funnel": {
          "key": "api-payment-lifecycle",
          "name": "API payment lifecycle"
        }
      },
      "catalog_binding": {
        "base_release_id": "sha256:cad9f851ab1bb553246eb2fb2b2803a4741814a33ccf28997014247439b9013d",
        "entity_revision_digest": "sha256:13a1e13a935baf054379e0920ee70976c984b5f482098bed447cd0a4554b7afe"
      },
      "declaration_revision_digest": "sha256:a81bdfbb491f2fe21afdd527f05027fbd7b85f25ea725043056eab981f9aff56",
      "declaration": {
        "declaration_id": "declaration_stripe_payments_api_lifecycle",
        "provenance": {
          "repository": "sourcey/agent-ready-services",
          "commit": "62b512f0c49352e55a399ba53866a5effa431d71",
          "path": "vendors/st/stripe.yaml",
          "git_blob_oid": "a024b676b335fce44c6cf42f8d04b0a128b0edbd",
          "blob_digest": "sha256:7bbb093090a6f3fed6496b02a1ccfafb5f054e5ed10538c4861c4d62252489f8"
        },
        "status": "community_declared"
      },
      "surface_catalog": {
        "assessment_targets": [
          {
            "target_id": "service-use",
            "name": "Create and reconcile payments through the Payments API",
            "interface_ids": [
              "payments-api"
            ]
          }
        ],
        "participants": [
          {
            "participant_id": "stripe",
            "roles": [
              "access_operator",
              "identity_provider",
              "operations_provider",
              "payment_provider",
              "provisioning_provider",
              "subject"
            ],
            "identity": {
              "entity_id": "ent_01kyygma830fqh16kvj744sk1c"
            }
          }
        ],
        "resources": [
          {
            "resource_id": "api-errors",
            "uri": "https://docs.stripe.com/api/errors",
            "roles": [
              "documentation",
              "operations",
              "recovery",
              "status"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "api-reference",
            "uri": "https://docs.stripe.com/api",
            "roles": [
              "discovery",
              "documentation",
              "operations"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "authentication",
            "uri": "https://docs.stripe.com/api/authentication",
            "roles": [
              "authentication",
              "descriptor",
              "documentation"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "credential-lifecycle",
            "uri": "https://docs.stripe.com/keys.md",
            "roles": [
              "authentication",
              "documentation",
              "operations",
              "provisioning",
              "recovery"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "dashboard-signup",
            "uri": "https://dashboard.stripe.com/register",
            "roles": [
              "access"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "idempotency",
            "uri": "https://docs.stripe.com/api/idempotent_requests",
            "roles": [
              "documentation",
              "operations",
              "recovery"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "payment-intents-create",
            "uri": "https://docs.stripe.com/api/payment_intents/create",
            "roles": [
              "documentation",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "pricing",
            "uri": "https://stripe.com/pricing",
            "roles": [
              "checkout",
              "documentation",
              "pricing"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "service-terms",
            "uri": "https://stripe.com/legal/ssa",
            "roles": [
              "terms"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "support",
            "uri": "https://support.stripe.com/",
            "roles": [
              "documentation",
              "recovery"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "resource_id": "testing",
            "uri": "https://docs.stripe.com/testing",
            "roles": [
              "documentation",
              "provisioning",
              "status"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          }
        ],
        "endpoints": [
          {
            "endpoint_id": "registration",
            "uri": "https://dashboard.stripe.com/register",
            "transport": "http",
            "roles": [
              "registration"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "endpoint_id": "stripe-api",
            "uri": "https://api.stripe.com/v1",
            "transport": "http",
            "roles": [
              "service",
              "status"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          }
        ],
        "interfaces": [
          {
            "interface_id": "api-authentication",
            "modality": "network_api",
            "functions": [
              "authentication",
              "recovery"
            ],
            "endpoint_ids": [],
            "resource_ids": [
              "authentication",
              "credential-lifecycle"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          },
          {
            "interface_id": "payments-api",
            "modality": "network_api",
            "functions": [
              "commerce",
              "service_operation"
            ],
            "endpoint_ids": [
              "stripe-api"
            ],
            "resource_ids": [
              "api-errors",
              "api-reference",
              "idempotency",
              "testing"
            ],
            "operated_by_participant_id": "stripe",
            "standard_bindings": []
          }
        ],
        "relations": [
          {
            "relation_id": "authentication-authenticates-api",
            "kind": "authenticates",
            "from": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "payments-api"
            }
          },
          {
            "relation_id": "credential-lifecycle-describes-authentication",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "credential-lifecycle"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          },
          {
            "relation_id": "idempotency-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "idempotency"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "payments-api"
            }
          },
          {
            "relation_id": "payment-intents-create-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "payment-intents-create"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "payments-api"
            }
          },
          {
            "relation_id": "reference-describes-api",
            "kind": "describes",
            "from": {
              "node_kind": "resource",
              "node_id": "api-reference"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "payments-api"
            }
          },
          {
            "relation_id": "signup-precedes-authentication",
            "kind": "precedes",
            "from": {
              "node_kind": "resource",
              "node_id": "dashboard-signup"
            },
            "to": {
              "node_kind": "interface",
              "node_id": "api-authentication"
            }
          }
        ],
        "surface_exclusions": [
          {
            "exclusion_id": "separate-eligibility-resource",
            "role": "eligibility",
            "rationale": "Applicable access conditions are published within the service terms; no separate eligibility resource is declared."
          }
        ]
      },
      "lifecycle": "active",
      "effective_from": "2026-08-20T14:33:24.000Z",
      "revision_digest": "sha256:e0d995b3da901902406f41752c7b6b80fdecc4b142b4d64c47cfe5c835608762",
      "policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
      "policy_version": "service-use-2026-08-20-public-evidence-r9",
      "policy_as_of": "2026-08-20T00:00:00Z",
      "assessment_basis": {
        "principal": "authorized_human_or_organization",
        "initial_state": {
          "product_specific_account": false,
          "product_credentials": false,
          "paid_subscription": false,
          "provisioned_resource": false,
          "external_identity": "only_when_declared_by_exact_funnel"
        },
        "permitted_human_boundaries": [
          "account_ownership_confirmation",
          "delegated_identity_consent",
          "regulated_approval",
          "final_payment_or_irreversible_commitment"
        ],
        "required_handoff_properties": [
          "exact_disclosure",
          "resumable_handoff",
          "deterministic_continuation"
        ],
        "forbidden_substitutions": [
          "captcha_solving",
          "human_password_or_session_sharing",
          "concealed_agent_identity",
          "invented_eligibility",
          "unbound_out_of_band_code",
          "vendor_policy_bypass",
          "unapproved_consequential_action"
        ],
        "success": {
          "target_coverage": "every_declared_target",
          "interface_coverage": "at_least_one_declared_alternative",
          "authority": "scoped",
          "failure_semantics": "documented",
          "recovery": "supported"
        },
        "observed_assessment": {
          "allowed_sources": [
            "public_documentation",
            "public_metadata",
            "public_endpoints",
            "non_mutating_interaction",
            "operator_attested_public_observation"
          ],
          "consequential_claims": "certification_required"
        }
      },
      "overall_outcome": "constrained",
      "public_state": "limited",
      "state_label": "Limited",
      "grade": "C",
      "grade_derivation": {
        "label": "Five-stage Agent Readiness report card",
        "explanation": "A through C grades count Limited stages; D and F reflect actual Blocked stages by lifecycle severity.",
        "coverage_rule": "Every core graded metric must have supported, fresh, non-conflicting evidence. Barrier checks constrain the report when verified and cap an otherwise higher grade at B+ while unverified.",
        "outcome_rule": "Each stage takes its worst core metric or verified barrier, and the overall grade is derived from the five stage states plus the explicit unverified-barrier cap."
      },
      "publication": {
        "visibility": "discoverable",
        "reasons": []
      },
      "primary_finding": {
        "stage": "evaluate",
        "stage_label": "Evaluate",
        "public_state": "limited",
        "finding": {
          "signal_code": "terms_access",
          "condition": "Can an agent retrieve and understand the applicable commitment terms?",
          "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
          "context": "The Stripe Services Agreement provides general terms, fee structures, and dispute terms, but notes that product-specific Services Terms apply separately based on the specific services used."
        }
      },
      "limitations": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "terms_access",
            "condition": "Can an agent retrieve and understand the applicable commitment terms?",
            "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
            "context": "The Stripe Services Agreement provides general terms, fee structures, and dispute terms, but notes that product-specific Services Terms apply separately based on the specific services used."
          },
          "remediation": {
            "signal_code": "terms_access",
            "code": "improve.evaluate.terms_access",
            "instruction": "Publish complete applicable terms at a stable public URL."
          }
        },
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "finding": {
            "signal_code": "eligibility_decidability",
            "condition": "Can an agent decide every material eligibility condition before commitment?",
            "finding": "Only some material eligibility conditions are decidable before commitment.",
            "context": "Stripe Services Agreement specifies requirements such as account country and full authority for representatives accepting on behalf of a user. However, detailed eligibility conditions depend on specific Service Terms and account details."
          },
          "remediation": {
            "signal_code": "eligibility_decidability",
            "code": "improve.evaluate.eligibility_decidability",
            "instruction": "State every material eligibility condition and required input explicitly."
          }
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "Stripe supports restricted API keys (RAKs) with limited permissions, but managing and revealing them relies on manual action via the Dashboard."
          },
          "remediation": {
            "signal_code": "delegated_identity_access",
            "code": "improve.sign_up.delegated_identity_access",
            "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
          }
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "The public commitment omits a material component until later in the flow.",
            "context": "Stripe discloses standard pay-as-you-go card processing rates (e.g., 1.7% + A$0.30 for domestic cards in AUD) and billing rates (0.7% of volume or A$930.00/month), but custom pricing packages, volume discounts, and conversion fees starting at 2% require contextual or deferred determination."
          },
          "remediation": {
            "signal_code": "commitment_disclosure",
            "code": "improve.pay.commitment_disclosure",
            "instruction": "Disclose the complete commitment before payment authorization."
          }
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "finding": {
            "signal_code": "self_service_purchase",
            "condition": "Is a direct self-service path to paid access documented?",
            "finding": "Self-service is tier- or condition-limited, or a bounded vendor review exposes status.",
            "context": "Self-service sign-up is available for the Standard pay-as-you-go pricing plan via a 'Get started' link, but the Custom pricing package requires contacting sales."
          },
          "remediation": {
            "signal_code": "self_service_purchase",
            "code": "improve.pay.self_service_purchase",
            "instruction": "Document a direct purchase path or bounded vendor review with machine-readable status."
          }
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "Stripe API keys are managed in the Dashboard. In live mode, secret keys are displayed once before saving and cannot be revealed later, requiring human copy-paste transfer."
          },
          "remediation": {
            "signal_code": "access_material_delivery",
            "code": "improve.provision.access_material_delivery",
            "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
          }
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "Stripe documents that API keys can be rotated, expired, and revoked upon compromise. However, rotation and revocation steps are documented via manual actions in the Stripe Dashboard."
          },
          "remediation": {
            "signal_code": "credential_lifecycle",
            "code": "improve.operate.credential_lifecycle",
            "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
          }
        }
      ],
      "stages": [
        {
          "stage": "evaluate",
          "stage_label": "Evaluate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "terms_access",
            "condition": "Can an agent retrieve and understand the applicable commitment terms?",
            "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
            "context": "The Stripe Services Agreement provides general terms, fee structures, and dispute terms, but notes that product-specific Services Terms apply separately based on the specific services used."
          },
          "secondary_context": [
            {
              "signal_code": "structured_evaluation_discovery",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "verified_web_agent_access",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "eligibility_decidability",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "context": "Stripe Services Agreement specifies requirements such as account country and full authority for representatives accepting on behalf of a user. However, detailed eligibility conditions depend on specific Service Terms and account details."
            },
            {
              "signal_code": "service_discovery",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "context": "The Stripe API Reference publicly documents the exact service entrypoints, including the base URL https://api.stripe.com, authentication options, and resources."
            },
            {
              "signal_code": "pricing_decidability",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "context": "Stripe discloses rates, currencies, and conditions for payment features on its pricing resource, including specific per-transaction fees (e.g., 3D Secure attempt fees and percentage-based conversion or payout fees)."
            }
          ],
          "signals": [
            {
              "signal_code": "eligibility_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent decide every material eligibility condition before commitment?",
              "finding": "Only some material eligibility conditions are decidable before commitment.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.183Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9646f036ec9ef34a8f657d9ebcb2ac97066b58450acc969a620933438bf95aa3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f6dec17564079b9bf382a4b088ef5aea2c6cad1141b0c9e481d3cdcf92555eb",
                    "sha256:56eebf88abb6669a409be2bab7f27d8ec1ad8c3ac6a825b84e2255e7eafb468c",
                    "sha256:6412d08f0e757487dc83feff2e443a5f90847467810edee43ec68add94ef37bf",
                    "sha256:ab599ba9973a60e087b8270006defb38eb2cdb869832cb754fe113cd3142bb6e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ab599ba9973a60e087b8270006defb38eb2cdb869832cb754fe113cd3142bb6e",
                      "start_byte": 11051,
                      "end_byte": 11861,
                      "value_digest": "sha256:20a0679e1447ff76d7ce952ba995c617800857ce1298cd379fd791fcb737a3a8"
                    },
                    {
                      "artifact_digest": "sha256:ab599ba9973a60e087b8270006defb38eb2cdb869832cb754fe113cd3142bb6e",
                      "start_byte": 70560,
                      "end_byte": 71382,
                      "value_digest": "sha256:7054ca5d3ccd33127cab701eb3dc6e660a6e090b5d301da518fe77087864921d"
                    }
                  ]
                }
              ],
              "note": "Stripe Services Agreement specifies requirements such as account country and full authority for representatives accepting on behalf of a user. However, detailed eligibility conditions depend on specific Service Terms and account details.",
              "remediation": {
                "signal_code": "eligibility_decidability",
                "code": "improve.evaluate.eligibility_decidability",
                "instruction": "State every material eligibility condition and required input explicitly."
              }
            },
            {
              "signal_code": "pricing_decidability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent estimate cost or confirm no-charge status before commitment?",
              "finding": "Price or no-charge status, variables, currency, and material conditions are explicit.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.632Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:75a34d0edef7d7a193b52be3060cb458693e93ed251efb4cd990bf825bf7a2c3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                    "sha256:0b65f13338f7d96f1cde0170f1469022e9e6f824da2ae1b9294d6ab9253c8405",
                    "sha256:1c7cdccf6789cdb3fab1cf56146979c6c847b2e09ea2ecf4a0f6578713f439d7",
                    "sha256:612ab598e462569eef3e88cc908da51e1ec3bf705ee5388618b5ff7a695f14ff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                      "start_byte": 27513,
                      "end_byte": 28303,
                      "value_digest": "sha256:973388bbff0f0a633b3c2691b19a51ce98f41b529a42d9d31c43883442ecbce9"
                    },
                    {
                      "artifact_digest": "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                      "start_byte": 28304,
                      "end_byte": 29100,
                      "value_digest": "sha256:cbfa96fd45e61138e166f4a71003d8af5972d5d880f830fef5fd282dd80d0174"
                    }
                  ]
                }
              ],
              "note": "Stripe discloses rates, currencies, and conditions for payment features on its pricing resource, including specific per-transaction fees (e.g., 3D Secure attempt fees and percentage-based conversion or payout fees)."
            },
            {
              "signal_code": "service_discovery",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent find the exact service and its stable entrypoints?",
              "finding": "The exact service and stable evaluation or access entrypoints are publicly discoverable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:24.008Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-reference"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:041276c1c2483840b963040292e73cbb1bde39b9c8777a04eee80c951f9c9937",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:0a99afef91dcd7665a6753043e30a4e2f503157e9df2dc29b9aa726d12b406a4",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7856d1a55d23c264c1a998db53006d9790e9c65757545a491c7e369fdd5ab289",
                    "sha256:d510a9500dad2ee0069636cfcffd6b25ff6b241d864401bc7fc20fd83fca5389"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7856d1a55d23c264c1a998db53006d9790e9c65757545a491c7e369fdd5ab289",
                      "start_byte": 10192,
                      "end_byte": 10952,
                      "value_digest": "sha256:c98946e685c7a4c5c2e237256e5c90bfeaf78b6fdfa9fa91fad2aa2a4c4a18f9"
                    }
                  ]
                }
              ],
              "note": "The Stripe API Reference publicly documents the exact service entrypoints, including the base URL https://api.stripe.com, authentication options, and resources."
            },
            {
              "signal_code": "structured_evaluation_discovery",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Are verified structured discovery artifacts available?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "terms_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent retrieve and understand the applicable commitment terms?",
              "finding": "Terms are readable but materially incomplete, ambiguous, contextual, or unstable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.183Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "service-terms"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:9646f036ec9ef34a8f657d9ebcb2ac97066b58450acc969a620933438bf95aa3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f6dec17564079b9bf382a4b088ef5aea2c6cad1141b0c9e481d3cdcf92555eb",
                    "sha256:56eebf88abb6669a409be2bab7f27d8ec1ad8c3ac6a825b84e2255e7eafb468c",
                    "sha256:ab599ba9973a60e087b8270006defb38eb2cdb869832cb754fe113cd3142bb6e",
                    "sha256:e00dd0d5fce9eab53c125e421c9db2c74adc84f4111c52115f1adf2cf3f89c6e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "service-terms"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:ab599ba9973a60e087b8270006defb38eb2cdb869832cb754fe113cd3142bb6e",
                      "start_byte": 10235,
                      "end_byte": 11050,
                      "value_digest": "sha256:c23fe0b87ff3efc672f1eccb1ee71210cb9129dd42a1d37c14c11546eda9701a"
                    },
                    {
                      "artifact_digest": "sha256:ab599ba9973a60e087b8270006defb38eb2cdb869832cb754fe113cd3142bb6e",
                      "start_byte": 97103,
                      "end_byte": 97902,
                      "value_digest": "sha256:91ef2c0a03b29b7c9b9e78858eeff147947d0e6f1ba84772c030979be2d5238d"
                    }
                  ]
                }
              ],
              "note": "The Stripe Services Agreement provides general terms, fee structures, and dispute terms, but notes that product-specific Services Terms apply separately based on the specific services used.",
              "remediation": {
                "signal_code": "terms_access",
                "code": "improve.evaluate.terms_access",
                "instruction": "Publish complete applicable terms at a stable public URL."
              }
            },
            {
              "signal_code": "verified_web_agent_access",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Does the vendor deliberately describe access for web agents?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "terms_access",
              "code": "improve.evaluate.terms_access",
              "instruction": "Publish complete applicable terms at a stable public URL."
            },
            {
              "signal_code": "eligibility_decidability",
              "code": "improve.evaluate.eligibility_decidability",
              "instruction": "State every material eligibility condition and required input explicitly."
            }
          ]
        },
        {
          "stage": "sign_up",
          "stage_label": "Sign up",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "delegated_identity_access",
            "condition": "Can an agent obtain scoped, revocable authority for this service?",
            "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
            "context": "Stripe supports restricted API keys (RAKs) with limited permissions, but managing and revealing them relies on manual action via the Dashboard."
          },
          "secondary_context": [
            {
              "signal_code": "access_control_operability",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured registration endpoint returned an incompatible browser error page, leaving access control operability unresolved."
            },
            {
              "signal_code": "captcha_compatible_access",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "Both captured targets returned an incompatible browser message, so CAPTCHA requirements cannot be determined."
            },
            {
              "signal_code": "phone_verification_compatible",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The captured signup page rendered an incompatible browser error, leaving phone verification requirements unresolved."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "context": "A stable signup route is established by the registration page metadata at https://dashboard.stripe.com/register."
            }
          ],
          "signals": [
            {
              "signal_code": "access_control_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent operate the access controls and safe handoffs deterministically?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:13.805Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured registration endpoint returned an incompatible browser error page, leaving access control operability unresolved."
            },
            {
              "signal_code": "access_entrypoint_stability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Is there a stable route to begin obtaining service access?",
              "finding": "A stable canonical route begins the required access bootstrap.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:13.805Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "dashboard-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [
                {
                  "kind": "direct_observation",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:5c371c228d025e025120b983e387eb94ca2f015a3c8e94eb56c1502d6dce622e",
                      "capture_rung": "headless"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:3878570f4a62a0d65f57cf1754e0269e56ec797f4e36e26b44c172eb6e800401",
                    "sha256:4112f3815cd81a458b8d1334bf7f81ab4470d17391f7d24d680b108e6de6a022",
                    "sha256:4afc7fd88d474f640b7f7b4a3ab15ad645409964125d3a49ba9e96e993ab4c19",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c6c57f512540c94ddc6fb83b625d3da62fe77c83738861dd2dad74b15d868502",
                    "sha256:cd02f5a91146e001e07e0096a897b53f49bdfba025c49ed503c0ccc03de4188c"
                  ],
                  "locators": [
                    {
                      "artifact_digest": "sha256:cd02f5a91146e001e07e0096a897b53f49bdfba025c49ed503c0ccc03de4188c",
                      "start_byte": 0,
                      "end_byte": 264,
                      "value_digest": "sha256:6ae77c2872ac63a3733bb94ed92ef39aedaea3153fb974bc7d969167abe91785"
                    }
                  ]
                }
              ],
              "note": "A stable signup route is established by the registration page metadata at https://dashboard.stripe.com/register."
            },
            {
              "signal_code": "captcha_compatible_access",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent obtain access without an unsupported CAPTCHA boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:13.805Z",
              "tested_surfaces": [
                {
                  "node_kind": "endpoint",
                  "node_id": "registration"
                },
                {
                  "node_kind": "resource",
                  "node_id": "dashboard-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "Both captured targets returned an incompatible browser message, so CAPTCHA requirements cannot be determined."
            },
            {
              "signal_code": "delegated_identity_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent obtain scoped, revocable authority for this service?",
              "finding": "Machine credentials exist but require manual copying, broad authority, or weak lifecycle support.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:31.218Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "credential-lifecycle"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a1381b462a327a649124ea6ecc31d16bbd673d8da405e2e232c98924a2bf0667",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:31918c60bb212b65477c7ab0d1f8ce22b7ba43cd6e3d1195a24060406e5ef899",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                    "sha256:d8db9ec0f66c1ad6db738259f2559472b0f1d68b7e680fbc5984ec5ebc5c1aaa"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "credential-lifecycle"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                      "start_byte": 432,
                      "end_byte": 648,
                      "value_digest": "sha256:a3c0f6afd9986929151a9b8a1ed66625c11fa6cf0c2682c7ed98ea0d16d7395e"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b2d0f02ed13af212a7b11dca0455e67ddb5b3448ed3890525e390ddb6deb3511",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:83c4232f037d0885ba6b492ca2065bde812687ebd659dcc98049d1ef9a11911f",
                    "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                    "sha256:b72b60a0903537ff4d6077abed43b50dd626808a183f21622d47dbd7cec74903"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                      "start_byte": 9657,
                      "end_byte": 10454,
                      "value_digest": "sha256:b595de453e38bcea7af8ae3c7e460fbaa3e457931182360d629180b48d97487f"
                    }
                  ]
                }
              ],
              "note": "Stripe supports restricted API keys (RAKs) with limited permissions, but managing and revealing them relies on manual action via the Dashboard.",
              "remediation": {
                "signal_code": "delegated_identity_access",
                "code": "improve.sign_up.delegated_identity_access",
                "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
              }
            },
            {
              "signal_code": "phone_verification_compatible",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can required phone verification be completed through a supported boundary?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:13.805Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "dashboard-signup"
                }
              ],
              "assessment_method": {
                "name": "bounded-headless-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f1212e8cd082308cfde3c097bc933c4a4b72046b1f242205c3e27a3b020b3311"
              },
              "determination_bases": [],
              "note": "The captured signup page rendered an incompatible browser error, leaving phone verification requirements unresolved."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "delegated_identity_access",
              "code": "improve.sign_up.delegated_identity_access",
              "instruction": "Provide scoped delegated authorization with consent, revocation, and deterministic resumption."
            }
          ]
        },
        {
          "stage": "pay",
          "stage_label": "Pay",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "commitment_disclosure",
            "condition": "Is the exact commercial commitment disclosed before authorization?",
            "finding": "The public commitment omits a material component until later in the flow.",
            "context": "Stripe discloses standard pay-as-you-go card processing rates (e.g., 1.7% + A$0.30 for domestic cards in AUD) and billing rates (0.7% of volume or A$930.00/month), but custom pricing packages, volume discounts, and conversion fees starting at 2% require contextual or deferred determination."
          },
          "secondary_context": [
            {
              "signal_code": "checkout_operability",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The retained evidence mentions Checkout as a prebuilt payment UI but does not provide sufficient detail to establish deterministic construction, approval handoff, and resumption."
            },
            {
              "signal_code": "payment_authorization",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "context": "The evidence references accepting credit and debit cards, digital wallets, Buy Now Pay Later, PayTo, and BECS Direct Debit, but does not document a delegated agent rail or human-confirmed authorization flow with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "Self-service is tier- or condition-limited, or a bounded vendor review exposes status.",
              "context": "Self-service sign-up is available for the Standard pay-as-you-go pricing plan via a 'Get started' link, but the Custom pricing package requires contacting sales."
            }
          ],
          "signals": [
            {
              "signal_code": "checkout_operability",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can an agent construct checkout, hand off approval safely, and resume?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.632Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The retained evidence mentions Checkout as a prebuilt payment UI but does not provide sufficient detail to establish deterministic construction, approval handoff, and resumption."
            },
            {
              "signal_code": "commitment_disclosure",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Is the exact commercial commitment disclosed before authorization?",
              "finding": "The public commitment omits a material component until later in the flow.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.632Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:75a34d0edef7d7a193b52be3060cb458693e93ed251efb4cd990bf825bf7a2c3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                    "sha256:1c7cdccf6789cdb3fab1cf56146979c6c847b2e09ea2ecf4a0f6578713f439d7",
                    "sha256:612ab598e462569eef3e88cc908da51e1ec3bf705ee5388618b5ff7a695f14ff",
                    "sha256:a8f6eda4d3061aebe1b92237e9e813b9533756eb4727aca637ca8712a33dd5a0"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                      "start_byte": 28304,
                      "end_byte": 29100,
                      "value_digest": "sha256:cbfa96fd45e61138e166f4a71003d8af5972d5d880f830fef5fd282dd80d0174"
                    }
                  ]
                }
              ],
              "note": "Stripe discloses standard pay-as-you-go card processing rates (e.g., 1.7% + A$0.30 for domestic cards in AUD) and billing rates (0.7% of volume or A$930.00/month), but custom pricing packages, volume discounts, and conversion fees starting at 2% require contextual or deferred determination.",
              "remediation": {
                "signal_code": "commitment_disclosure",
                "code": "improve.pay.commitment_disclosure",
                "instruction": "Disclose the complete commitment before payment authorization."
              }
            },
            {
              "signal_code": "payment_authorization",
              "evaluation_role": "barrier",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Can payment be authorized within scoped agent or explicit human authority?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.632Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [],
              "note": "The evidence references accepting credit and debit cards, digital wallets, Buy Now Pay Later, PayTo, and BECS Direct Debit, but does not document a delegated agent rail or human-confirmed authorization flow with receipts."
            },
            {
              "signal_code": "self_service_purchase",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Is a direct self-service path to paid access documented?",
              "finding": "Self-service is tier- or condition-limited, or a bounded vendor review exposes status.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:00.632Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "pricing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:75a34d0edef7d7a193b52be3060cb458693e93ed251efb4cd990bf825bf7a2c3",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                    "sha256:1c7cdccf6789cdb3fab1cf56146979c6c847b2e09ea2ecf4a0f6578713f439d7",
                    "sha256:3f3f74c610837b844e4622394258902aa98fdd3751acec6b466a369e408a941b",
                    "sha256:612ab598e462569eef3e88cc908da51e1ec3bf705ee5388618b5ff7a695f14ff"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "pricing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:04020bf9916713bcc54e29a3add3fb214496235432fc08485ca89178de9156d2",
                      "start_byte": 21153,
                      "end_byte": 21951,
                      "value_digest": "sha256:abdf90018a9b803fe1c564c903dcdbc94bf831694bb3878501f2797a998e0c92"
                    }
                  ]
                }
              ],
              "note": "Self-service sign-up is available for the Standard pay-as-you-go pricing plan via a 'Get started' link, but the Custom pricing package requires contacting sales.",
              "remediation": {
                "signal_code": "self_service_purchase",
                "code": "improve.pay.self_service_purchase",
                "instruction": "Document a direct purchase path or bounded vendor review with machine-readable status."
              }
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "commitment_disclosure",
              "code": "improve.pay.commitment_disclosure",
              "instruction": "Disclose the complete commitment before payment authorization."
            },
            {
              "signal_code": "self_service_purchase",
              "code": "improve.pay.self_service_purchase",
              "instruction": "Document a direct purchase path or bounded vendor review with machine-readable status."
            }
          ]
        },
        {
          "stage": "provision",
          "stage_label": "Provision",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "access_material_delivery",
            "condition": "Can usable access material be delivered securely to an authorized agent?",
            "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
            "context": "Stripe API keys are managed in the Dashboard. In live mode, secret keys are displayed once before saving and cannot be revealed later, requiring human copy-paste transfer."
          },
          "secondary_context": [
            {
              "signal_code": "provisioning_operability",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "context": "PaymentIntents can be machine-triggered programmatically via POST requests to /v1/payment_intents."
            },
            {
              "signal_code": "provisioning_completion",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "context": "PaymentIntents return synchronous status responses (such as requires_payment_method) or move asynchronously through processing, succeeded, and requires_payment_method states with corresponding payment_intent.succeeded and payment_intent.payment_failed webhooks to reconcile outcomes."
            }
          ],
          "signals": [
            {
              "signal_code": "access_material_delivery",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can usable access material be delivered securely to an authorized agent?",
              "finding": "Delivery needs additional human transfer or has weak scope or lifecycle semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:31.218Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "credential-lifecycle"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a1381b462a327a649124ea6ecc31d16bbd673d8da405e2e232c98924a2bf0667",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                    "sha256:d8db9ec0f66c1ad6db738259f2559472b0f1d68b7e680fbc5984ec5ebc5c1aaa",
                    "sha256:fe5231c985f7870e8d417de741f3bc4dc986c4dbdb3b8c6b34a37c87acdf60b4"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "credential-lifecycle"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                      "start_byte": 8840,
                      "end_byte": 8995,
                      "value_digest": "sha256:5d16208068426d6954e2a36402945ec80adffff5e1a60a06becc78be32e6e728"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b2d0f02ed13af212a7b11dca0455e67ddb5b3448ed3890525e390ddb6deb3511",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:65cb3d9bf30b0a39668200fa880bd8626b6589b6d6efa1a025c26ab730600b0e",
                    "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                    "sha256:b72b60a0903537ff4d6077abed43b50dd626808a183f21622d47dbd7cec74903"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                      "start_byte": 8858,
                      "end_byte": 9656,
                      "value_digest": "sha256:276cc4e7c2d3d26976293535a107f2c0ea2023e06ca028e900a9d6e3756b6b07"
                    }
                  ]
                }
              ],
              "note": "Stripe API keys are managed in the Dashboard. In live mode, secret keys are displayed once before saving and cannot be revealed later, requiring human copy-paste transfer.",
              "remediation": {
                "signal_code": "access_material_delivery",
                "code": "improve.provision.access_material_delivery",
                "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
              }
            },
            {
              "signal_code": "provisioning_completion",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent determine successful provisioning completion and reconcile asynchronous failure?",
              "finding": "A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:27.449Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "payment-intents-create"
                },
                {
                  "node_kind": "resource",
                  "node_id": "testing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4ff3bb5c2a363dfc84d211648aee49f2e4f6b3a527ed7d444b5c0bc92c022e3c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:06b46ba765f13fbcd76e6f7bb3e159db62f6fbd2732d712b8d84d5089a1a67fc",
                    "sha256:3232ffaf4605a371aecf7fa5fb0c6f34dbbf7a970e1d22b17e43644c1d0a0956",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:e07f98ec85be586d0b27dc0eec35e52dd7c2b1e18e85eec7c704ccfa2346b89e"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "testing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:3232ffaf4605a371aecf7fa5fb0c6f34dbbf7a970e1d22b17e43644c1d0a0956",
                      "start_byte": 40435,
                      "end_byte": 41239,
                      "value_digest": "sha256:003aa050bbf9677b6e4627048aabddf1a53932a36135cf7fc6039829195f05be"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b9c527e4e4bb3195f1e7acc830d3490a2d45ebd6463418d4084585ed45095a54",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5f4436d4b4d11598f6d93f155715b01c1a55188544f66f953999312272f15824",
                    "sha256:9ea2b69b6e8879820ded164dbba1856c73c5c42da7c043319d27d34f0d1033af",
                    "sha256:bd1e5a3f812367b9e3d8029918557ce08074d914702a7b122a9e6bbe86952a4d"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "payment-intents-create"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:5f4436d4b4d11598f6d93f155715b01c1a55188544f66f953999312272f15824",
                      "start_byte": 9199,
                      "end_byte": 9982,
                      "value_digest": "sha256:ae6a38b84b162658fddd8715792f457975dcd52233ab60a2172849fa4976b43f"
                    }
                  ]
                }
              ],
              "note": "PaymentIntents return synchronous status responses (such as requires_payment_method) or move asynchronously through processing, succeeded, and requires_payment_method states with corresponding payment_intent.succeeded and payment_intent.payment_failed webhooks to reconcile outcomes."
            },
            {
              "signal_code": "provisioning_operability",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can provisioning be initiated within supported agent authority?",
              "finding": "Provisioning is machine-triggerable or follows deterministically from an allowed handoff.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:27.449Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "credential-lifecycle"
                },
                {
                  "node_kind": "resource",
                  "node_id": "payment-intents-create"
                },
                {
                  "node_kind": "resource",
                  "node_id": "testing"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b9c527e4e4bb3195f1e7acc830d3490a2d45ebd6463418d4084585ed45095a54",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5f4436d4b4d11598f6d93f155715b01c1a55188544f66f953999312272f15824",
                    "sha256:85e47791f6761d3ef48e4c8bacef378ecb3f4cc76e2127febe5be834cfa443de",
                    "sha256:9ea2b69b6e8879820ded164dbba1856c73c5c42da7c043319d27d34f0d1033af"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "payment-intents-create"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:5f4436d4b4d11598f6d93f155715b01c1a55188544f66f953999312272f15824",
                      "start_byte": 11553,
                      "end_byte": 12350,
                      "value_digest": "sha256:24633918a8b9a10636b71063c2ab1e58a1e8b8e8d42dfa182ca6f7a7a0747394"
                    }
                  ]
                }
              ],
              "note": "PaymentIntents can be machine-triggered programmatically via POST requests to /v1/payment_intents."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "access_material_delivery",
              "code": "improve.provision.access_material_delivery",
              "instruction": "Deliver scoped access material through a secure documented machine-usable flow."
            }
          ]
        },
        {
          "stage": "operate",
          "stage_label": "Operate",
          "outcome": "constrained",
          "public_state": "limited",
          "state_label": "Limited",
          "primary_finding": {
            "signal_code": "credential_lifecycle",
            "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
            "finding": "Only part of the credential lifecycle is agent-operable.",
            "context": "Stripe documents that API keys can be rotated, expired, and revoked upon compromise. However, rotation and revocation steps are documented via manual actions in the Stripe Dashboard."
          },
          "secondary_context": [
            {
              "signal_code": "agent_protocol_interface",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding."
            },
            {
              "signal_code": "target_interface_access",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "context": "Stripe provides machine-operable interfaces across HTTP REST endpoints, official SDK client libraries (such as Ruby, Python, Node.js), and the Stripe CLI for interacting with and testing API targets."
            },
            {
              "signal_code": "operation_authentication",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "context": "Stripe documents API key authentication over HTTPS using test mode keys or restricted API keys (RAKs) configured with specific permissions to scope authority."
            },
            {
              "signal_code": "operation_contract",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "context": "Essential operations and input/output semantics are documented across the API reference, HTTP status code response specifications, idempotency options, and test environment sandboxes."
            },
            {
              "signal_code": "failure_contract",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.",
              "context": "Stripe documents API error response HTTP status codes, error types, rate limits (429 errors recommending exponential backoff), and idempotency mechanics via the Idempotency-Key header for safely retrying POST requests."
            }
          ],
          "signals": [
            {
              "signal_code": "agent_protocol_interface",
              "evaluation_role": "informational",
              "required": false,
              "value": "unknown",
              "value_label": "Unknown",
              "outcome": "unknown",
              "public_state": "unknown",
              "condition": "Is an agent-native protocol interface verified against the essential targets?",
              "finding": "Current admissible evidence does not resolve this finding.",
              "evidence_status": "missing",
              "freshness": "unknown",
              "tested_surfaces": [],
              "determination_bases": []
            },
            {
              "signal_code": "credential_lifecycle",
              "evaluation_role": "graded",
              "required": true,
              "value": "partial",
              "value_label": "Limited",
              "outcome": "constrained",
              "public_state": "limited",
              "condition": "Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?",
              "finding": "Only part of the credential lifecycle is agent-operable.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:56:31.218Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "credential-lifecycle"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:a1381b462a327a649124ea6ecc31d16bbd673d8da405e2e232c98924a2bf0667",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                    "sha256:91bf063e554b3a045cb72baa7a5edf739c09131815c4e45d637a1efb50a10ed1",
                    "sha256:d8db9ec0f66c1ad6db738259f2559472b0f1d68b7e680fbc5984ec5ebc5c1aaa"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "credential-lifecycle"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                      "start_byte": 12748,
                      "end_byte": 13150,
                      "value_digest": "sha256:5d68478c5230edac2f6f5be445fedc302932670e34da68181008410b2f41ded7"
                    },
                    {
                      "artifact_digest": "sha256:7775fd6efac8a1d41c9ae64ae3d5b11dd83ada75afa4833926d370f02c951eed",
                      "start_byte": 13954,
                      "end_byte": 14532,
                      "value_digest": "sha256:1be7ff467093156d5ce341aeb93cefca0a26cd364bfb66cb151038685388ac4f"
                    }
                  ]
                }
              ],
              "note": "Stripe documents that API keys can be rotated, expired, and revoked upon compromise. However, rotation and revocation steps are documented via manual actions in the Stripe Dashboard.",
              "remediation": {
                "signal_code": "credential_lifecycle",
                "code": "improve.operate.credential_lifecycle",
                "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
              }
            },
            {
              "signal_code": "failure_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent handle applicable failure modes safely?",
              "finding": "Applicable limits, errors, retry, idempotency, cancellation, and reconciliation semantics are documented.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:03.924Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "api-errors"
                },
                {
                  "node_kind": "resource",
                  "node_id": "credential-lifecycle"
                },
                {
                  "node_kind": "resource",
                  "node_id": "idempotency"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b43436f3e40e5abc567805298ef638455c28a60f97700bcea0e822a55f0bb279",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2823e7dd745de7daa5e4f4e438db448137453b755b05401ed97079a5a2d12790",
                    "sha256:444d59e35094b32f491446dc0b7ab652618fb14481bfebb101d7ed6e41589b18",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c59661a9272a4984098c6302bcc02d1a9329a2a8721192f77150edc2f7656977"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "idempotency"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:2823e7dd745de7daa5e4f4e438db448137453b755b05401ed97079a5a2d12790",
                      "start_byte": 8750,
                      "end_byte": 9549,
                      "value_digest": "sha256:27df7eb6f1aabcbf4f9d044bdaf0941f8a40aa7a6b726cbeb1ce43b7b35a8489"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0a88823b59d53188e50f8a3d0ccaaf99fbbfb97785ac267938f4882dfaff364c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                    "sha256:311590923f71d8a1d33a96ded50b0268d1981e5439c4fe585b95f4392b1e4a03",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:bfa80746ccc727fe88d21ad0874b6f942a0cf32f3113dfd933efe8931cf2c7c5"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                      "start_byte": 11578,
                      "end_byte": 12385,
                      "value_digest": "sha256:62c0f229ad2749daed334e843e8ecf3caa0c1e7c3c0b0cd47afdacecda78a31c"
                    },
                    {
                      "artifact_digest": "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                      "start_byte": 8674,
                      "end_byte": 9470,
                      "value_digest": "sha256:d5c384c8609f98ea40b842dceea185aacadc2faeb927c0788c49209e27ead06c"
                    }
                  ]
                }
              ],
              "note": "Stripe documents API error response HTTP status codes, error types, rate limits (429 errors recommending exponential backoff), and idempotency mechanics via the Idempotency-Key header for safely retrying POST requests."
            },
            {
              "signal_code": "operation_authentication",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent authenticate service operations with scoped authority?",
              "finding": "Request-time authentication is documented and usable under scoped agent authority.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:55:59.999Z",
              "tested_surfaces": [
                {
                  "node_kind": "resource",
                  "node_id": "authentication"
                },
                {
                  "node_kind": "resource",
                  "node_id": "credential-lifecycle"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b2d0f02ed13af212a7b11dca0455e67ddb5b3448ed3890525e390ddb6deb3511",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:6ed61e4dcc01a08d8023141d87fdf296e8ea380d9185871f21dc4cb2db22ca99",
                    "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                    "sha256:b72b60a0903537ff4d6077abed43b50dd626808a183f21622d47dbd7cec74903"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "authentication"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                      "start_byte": 9657,
                      "end_byte": 10454,
                      "value_digest": "sha256:b595de453e38bcea7af8ae3c7e460fbaa3e457931182360d629180b48d97487f"
                    },
                    {
                      "artifact_digest": "sha256:93ed21fe96326ed25fc8fa83993e6b7d8dccbb674661f333d5663a49a47bcae0",
                      "start_byte": 8858,
                      "end_byte": 9656,
                      "value_digest": "sha256:276cc4e7c2d3d26976293535a107f2c0ea2023e06ca028e900a9d6e3756b6b07"
                    }
                  ]
                }
              ],
              "note": "Stripe documents API key authentication over HTTPS using test mode keys or restricted API keys (RAKs) configured with specific permissions to scope authority."
            },
            {
              "signal_code": "operation_contract",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Are essential operation inputs, outputs, and effects stable and decidable?",
              "finding": "Essential operations have stable readable request, response, and effect semantics.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:03.924Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "payments-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0a88823b59d53188e50f8a3d0ccaaf99fbbfb97785ac267938f4882dfaff364c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                    "sha256:311590923f71d8a1d33a96ded50b0268d1981e5439c4fe585b95f4392b1e4a03",
                    "sha256:4f199b5f3e356c845f5ab92f3200385639ef2f2f09b9c5d1f30de44c1093ec0e",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                      "start_byte": 10773,
                      "end_byte": 11577,
                      "value_digest": "sha256:e30fe1870a04a312772edb32fa32acf4e091240399ad1aac4fcdc60031f439aa"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:041276c1c2483840b963040292e73cbb1bde39b9c8777a04eee80c951f9c9937",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2734d9346a54d77d721f29be36729a74fe33558520b16d2c0ab1f55f72ea0518",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7856d1a55d23c264c1a998db53006d9790e9c65757545a491c7e369fdd5ab289",
                    "sha256:d510a9500dad2ee0069636cfcffd6b25ff6b241d864401bc7fc20fd83fca5389"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7856d1a55d23c264c1a998db53006d9790e9c65757545a491c7e369fdd5ab289",
                      "start_byte": 9396,
                      "end_byte": 10191,
                      "value_digest": "sha256:fe2d8779019d60272212e0eb71515a972c3d183ca528f71f4d48cb52c49c2fe9"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4ff3bb5c2a363dfc84d211648aee49f2e4f6b3a527ed7d444b5c0bc92c022e3c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:06b46ba765f13fbcd76e6f7bb3e159db62f6fbd2732d712b8d84d5089a1a67fc",
                    "sha256:3232ffaf4605a371aecf7fa5fb0c6f34dbbf7a970e1d22b17e43644c1d0a0956",
                    "sha256:48e1afa0334a6ffd10a3e430c6d4a5bdc9bc6c5adae6a7b973e89648d88ac088",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "testing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:3232ffaf4605a371aecf7fa5fb0c6f34dbbf7a970e1d22b17e43644c1d0a0956",
                      "start_byte": 17451,
                      "end_byte": 18200,
                      "value_digest": "sha256:87c27863c1f2f796c37c6d52492bae1c2bc6e03d83ef3034bf2db9f278de8c62"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b43436f3e40e5abc567805298ef638455c28a60f97700bcea0e822a55f0bb279",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2823e7dd745de7daa5e4f4e438db448137453b755b05401ed97079a5a2d12790",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:5d232b0ab515bfc67a4ba7cbf1a5728b7a171da443537d3033bc659b1afb0a6f",
                    "sha256:c59661a9272a4984098c6302bcc02d1a9329a2a8721192f77150edc2f7656977"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "idempotency"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:2823e7dd745de7daa5e4f4e438db448137453b755b05401ed97079a5a2d12790",
                      "start_byte": 11155,
                      "end_byte": 11956,
                      "value_digest": "sha256:4a0c06054a51513b392ec42b37d3c028c88bbc0b90b822700bc37b8bfe7d73c1"
                    }
                  ]
                }
              ],
              "note": "Essential operations and input/output semantics are documented across the API reference, HTTP status code response specifications, idempotency options, and test environment sandboxes."
            },
            {
              "signal_code": "target_interface_access",
              "evaluation_role": "graded",
              "required": true,
              "value": "yes",
              "value_label": "Ready",
              "outcome": "pass",
              "public_state": "ready",
              "condition": "Can an agent perform every essential assessment target through a usable interface?",
              "finding": "Every essential target has a stable documented agent-usable interface alternative.",
              "evidence_status": "supported",
              "freshness": "fresh",
              "observed_at": "2026-08-20T15:57:03.924Z",
              "tested_surfaces": [
                {
                  "node_kind": "interface",
                  "node_id": "payments-api"
                }
              ],
              "assessment_method": {
                "name": "public-http-semantic-assessment",
                "version": "2026-08-20",
                "method_digest": "sha256:f7c4219d9b75928a6bcff8d125dc30bbc718673e579a66f00d832172e8c9d43d"
              },
              "determination_bases": [
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:0a88823b59d53188e50f8a3d0ccaaf99fbbfb97785ac267938f4882dfaff364c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                    "sha256:311590923f71d8a1d33a96ded50b0268d1981e5439c4fe585b95f4392b1e4a03",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7feec6f0d9098c757a66e4d45bc5ae7bd3627c57556d59254bd91487303a052c"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-errors"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:1cbddc9b0070adb1dd8867c3139e9cfd91d4d9e422c7e756cae0fd4745346a65",
                      "start_byte": 10245,
                      "end_byte": 10772,
                      "value_digest": "sha256:413358af656a6ca9b23265abaac85d9bf555f309472df4386994944a933504db"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:b43436f3e40e5abc567805298ef638455c28a60f97700bcea0e822a55f0bb279",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:2823e7dd745de7daa5e4f4e438db448137453b755b05401ed97079a5a2d12790",
                    "sha256:29fbc79fd434edc8a3b5ee24c55b08e144911cbae78dcff1ba1e22bf38e5d1fd",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:c59661a9272a4984098c6302bcc02d1a9329a2a8721192f77150edc2f7656977"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "idempotency"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:2823e7dd745de7daa5e4f4e438db448137453b755b05401ed97079a5a2d12790",
                      "start_byte": 9550,
                      "end_byte": 10347,
                      "value_digest": "sha256:7c40cb431818d8f760b504330e2b0d781232bdd588829f41c28d6b7c5ec11fd5"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:041276c1c2483840b963040292e73cbb1bde39b9c8777a04eee80c951f9c9937",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:7856d1a55d23c264c1a998db53006d9790e9c65757545a491c7e369fdd5ab289",
                    "sha256:cf8fe2dd034f33ab4bff315a14bc5a3027676d2497daaa2dc87b500c9bef298c",
                    "sha256:d510a9500dad2ee0069636cfcffd6b25ff6b241d864401bc7fc20fd83fca5389"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "api-reference"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:7856d1a55d23c264c1a998db53006d9790e9c65757545a491c7e369fdd5ab289",
                      "start_byte": 10953,
                      "end_byte": 11751,
                      "value_digest": "sha256:d75dead307d7487ea4a779836ddfbcaf633924af22de19e62a1ba3bcc01caa9e"
                    }
                  ]
                },
                {
                  "kind": "explicit_first_party_declaration",
                  "captures": [
                    {
                      "retained_capture_digest": "sha256:4ff3bb5c2a363dfc84d211648aee49f2e4f6b3a527ed7d444b5c0bc92c022e3c",
                      "capture_rung": "http"
                    }
                  ],
                  "artifact_digests": [
                    "sha256:06b46ba765f13fbcd76e6f7bb3e159db62f6fbd2732d712b8d84d5089a1a67fc",
                    "sha256:3232ffaf4605a371aecf7fa5fb0c6f34dbbf7a970e1d22b17e43644c1d0a0956",
                    "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
                    "sha256:a5865cc02e68984d85e9c77bd26b0ee6403a493044a6d5d040cd91103944461a"
                  ],
                  "source_surface": {
                    "node_kind": "resource",
                    "node_id": "testing"
                  },
                  "locators": [
                    {
                      "artifact_digest": "sha256:3232ffaf4605a371aecf7fa5fb0c6f34dbbf7a970e1d22b17e43644c1d0a0956",
                      "start_byte": 8000,
                      "end_byte": 8799,
                      "value_digest": "sha256:2d8d2fc9a57d2055b0fb68eff855850c664a4cc62ac44536de9b8c5f002b4e79"
                    }
                  ]
                }
              ],
              "note": "Stripe provides machine-operable interfaces across HTTP REST endpoints, official SDK client libraries (such as Ruby, Python, Node.js), and the Stripe CLI for interacting with and testing API targets."
            }
          ],
          "blockers": [],
          "remediations": [
            {
              "signal_code": "credential_lifecycle",
              "code": "improve.operate.credential_lifecycle",
              "instruction": "Provide scoped expiry, rotation, revocation, compromise, and recovery operations."
            }
          ]
        }
      ],
      "coverage": {
        "status": "complete",
        "required_signals": 16,
        "covered_signals": 16,
        "ratio": 1,
        "barrier_signals": 5,
        "verified_barrier_signals": 0,
        "barrier_ratio": 0
      },
      "last_tested_at": "2026-08-20T15:57:13.805Z",
      "freshness": "fresh",
      "provenance": {
        "tier": "observed",
        "freshness": "fresh",
        "dispute": "none",
        "coverage_policy_digest": "sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139",
        "freshness_policy_digest": "sha256:00f7f2a35f37b184e57ce2cc116f6a5e3feb4813991aacd7e29e322f2d3607a8",
        "basis_event_ids": [
          "sha256:00305737021acfd74b287fefcd9f209f1c3db628dc25713f96e0c1ceb349c7a0",
          "sha256:00787c374b83327ca86401ed064f4b29c16b68b8dcb6664c49823a7fdb1cef6f",
          "sha256:02f3a13354da862da234be419b49d584156616daf3ccda0a7e666c24582b6578",
          "sha256:05ebe0b2a5b2d9ab1f78a24360980b511112cba11b35e10d990ff867e3936fa7",
          "sha256:09f467062242b77add889b15cb857cd12e1cbcfa7bf3c62333839f0d587488b1",
          "sha256:11c8dc63510061d57e9738e90a7df71cf11d467c8cfbfe41fd7b8918e8163e88",
          "sha256:1cf63afcffd2a15160fbdf5adeaf0afe5f3d58be1d853b50d31d94b921279664",
          "sha256:2155503d051d18ca4c774e42a50ffa84c556c8f74161ff8ea59d3c851f545184",
          "sha256:2887859ea525dafa6089bec7b3438218f59a638c0a0d1faaf48eb0751a6edf82",
          "sha256:31b2f22766ab4e73db3ae3c73afe7c00e98a31d044efd634efe917d151223bf0",
          "sha256:5f447f16449f924c47b1f165dcfcc9db0e695b46cc3963469bdcdd0c05db411f",
          "sha256:6c6e28bf65148f8640a2df5a2f626d32d0731116365527ee9dab1758a845a3d3",
          "sha256:6e0269d7f714994c6bc0753873faf0b76581a8b554b5fd254c66b1bee327eba9",
          "sha256:824d7a9f1e44229496efdc0830a2b2c35fa91813e3860d4b5c89bf1984b7a868",
          "sha256:8268c1857fd615ca343f6aa5b5bc62024d32ca5829d8a74c6d6801b7a6f99f84",
          "sha256:84ce8f7011dfc2ec5587701a06e3b6a25fc7bbeffc22b4038e91051f8c6a85c8",
          "sha256:8a8f0427b84efff50d1f28bf9ec636a420b4e3f5162e4b1b2a2d63fa5f031748",
          "sha256:a4f39e320538d60c9fafc3a902da6d3a0a7e7eae2e4ea2109c3759df82b8a8c6",
          "sha256:b08415f433dbd9072ac75b83d120ea85fbca29028c43638f7c039acbe3205381",
          "sha256:ba21699ce31aaa56d64c9355d9fa6817e528aeea35f9549d46601e3858fcdf03",
          "sha256:bb3ea3f4abcf12fc5ee3ff011bb320f7b5372acddd605b981c8433b8f6119cbf",
          "sha256:c456d61c69515ff7cd9a0e18befc7f237752c29e84316af148af45aec73361ff",
          "sha256:cd94fb2afc8806041e9ac8bcf4cfcde163802f819374c7289b2b83492cc2b105",
          "sha256:ce98a8f3e600ce36d17f9e9916704f4d79edf2f41e270bb6252f82be8b4c34a3",
          "sha256:d177f30e6a67cbd5a71f29e1d1ee9d514016644c9afe54f86f69d068b8683046",
          "sha256:d1d9f23f2e17d5bd1628edee4fe23607ef9111e76b59121b556e45259ecbf85c",
          "sha256:d81de7b74053ef73b0be19e5a419feaf873383ea7a170084c32854cb7a406bd7",
          "sha256:d899cbc36e0cacec79648bfbaaa71d63c0f21746a1d91b275182a318930ab3bb",
          "sha256:d90b43378f04b711fa080928c8c5227b58c261a400a2594939e1f493d3ef7da7",
          "sha256:e9a5d0b2b202a4801d9adc5ab6c31417f9ed70177ad97e9bf0f1a74c6702ba8a",
          "sha256:ea7bc7fb43248b681c24edfbecb0db27bffa21d6a5dd959bad053cc496113ff8",
          "sha256:f5759c472cbb78601dd03b974c3256c5b5fece9f7342420a113584ae26921eb8"
        ],
        "fields": [
          {
            "path": "/signals/0",
            "supporting_event_ids": [
              "sha256:bb3ea3f4abcf12fc5ee3ff011bb320f7b5372acddd605b981c8433b8f6119cbf"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.183Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/1",
            "supporting_event_ids": [
              "sha256:2155503d051d18ca4c774e42a50ffa84c556c8f74161ff8ea59d3c851f545184"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.632Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/2",
            "supporting_event_ids": [
              "sha256:00787c374b83327ca86401ed064f4b29c16b68b8dcb6664c49823a7fdb1cef6f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:24.008Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/3",
            "supporting_event_ids": [
              "sha256:84ce8f7011dfc2ec5587701a06e3b6a25fc7bbeffc22b4038e91051f8c6a85c8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.183Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/4",
            "supporting_event_ids": [
              "sha256:f5759c472cbb78601dd03b974c3256c5b5fece9f7342420a113584ae26921eb8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:13.805Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/5",
            "supporting_event_ids": [
              "sha256:ce98a8f3e600ce36d17f9e9916704f4d79edf2f41e270bb6252f82be8b4c34a3"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:13.805Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/6",
            "supporting_event_ids": [
              "sha256:ba21699ce31aaa56d64c9355d9fa6817e528aeea35f9549d46601e3858fcdf03",
              "sha256:c456d61c69515ff7cd9a0e18befc7f237752c29e84316af148af45aec73361ff"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:13.805Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/7",
            "supporting_event_ids": [
              "sha256:11c8dc63510061d57e9738e90a7df71cf11d467c8cfbfe41fd7b8918e8163e88",
              "sha256:5f447f16449f924c47b1f165dcfcc9db0e695b46cc3963469bdcdd0c05db411f"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:31.218Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/8",
            "supporting_event_ids": [
              "sha256:b08415f433dbd9072ac75b83d120ea85fbca29028c43638f7c039acbe3205381"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:13.805Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/9",
            "supporting_event_ids": [
              "sha256:09f467062242b77add889b15cb857cd12e1cbcfa7bf3c62333839f0d587488b1"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.632Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/10",
            "supporting_event_ids": [
              "sha256:6e0269d7f714994c6bc0753873faf0b76581a8b554b5fd254c66b1bee327eba9"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.632Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/11",
            "supporting_event_ids": [
              "sha256:ea7bc7fb43248b681c24edfbecb0db27bffa21d6a5dd959bad053cc496113ff8"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.632Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/12",
            "supporting_event_ids": [
              "sha256:cd94fb2afc8806041e9ac8bcf4cfcde163802f819374c7289b2b83492cc2b105"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:00.632Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/13",
            "supporting_event_ids": [
              "sha256:d177f30e6a67cbd5a71f29e1d1ee9d514016644c9afe54f86f69d068b8683046",
              "sha256:d90b43378f04b711fa080928c8c5227b58c261a400a2594939e1f493d3ef7da7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:31.218Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/14",
            "supporting_event_ids": [
              "sha256:824d7a9f1e44229496efdc0830a2b2c35fa91813e3860d4b5c89bf1984b7a868",
              "sha256:d81de7b74053ef73b0be19e5a419feaf873383ea7a170084c32854cb7a406bd7"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:27.449Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/15",
            "supporting_event_ids": [
              "sha256:2887859ea525dafa6089bec7b3438218f59a638c0a0d1faaf48eb0751a6edf82"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:27.449Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/16",
            "supporting_event_ids": [
              "sha256:a4f39e320538d60c9fafc3a902da6d3a0a7e7eae2e4ea2109c3759df82b8a8c6"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:56:31.218Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/17",
            "supporting_event_ids": [
              "sha256:1cf63afcffd2a15160fbdf5adeaf0afe5f3d58be1d853b50d31d94b921279664",
              "sha256:d1d9f23f2e17d5bd1628edee4fe23607ef9111e76b59121b556e45259ecbf85c"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:03.924Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/18",
            "supporting_event_ids": [
              "sha256:8268c1857fd615ca343f6aa5b5bc62024d32ca5829d8a74c6d6801b7a6f99f84"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:55:59.999Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/19",
            "supporting_event_ids": [
              "sha256:05ebe0b2a5b2d9ab1f78a24360980b511112cba11b35e10d990ff867e3936fa7",
              "sha256:31b2f22766ab4e73db3ae3c73afe7c00e98a31d044efd634efe917d151223bf0",
              "sha256:d899cbc36e0cacec79648bfbaaa71d63c0f21746a1d91b275182a318930ab3bb",
              "sha256:e9a5d0b2b202a4801d9adc5ab6c31417f9ed70177ad97e9bf0f1a74c6702ba8a"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:03.924Z",
            "freshness": "fresh"
          },
          {
            "path": "/signals/20",
            "supporting_event_ids": [
              "sha256:00305737021acfd74b287fefcd9f209f1c3db628dc25713f96e0c1ceb349c7a0",
              "sha256:02f3a13354da862da234be419b49d584156616daf3ccda0a7e666c24582b6578",
              "sha256:6c6e28bf65148f8640a2df5a2f626d32d0731116365527ee9dab1758a845a3d3",
              "sha256:8a8f0427b84efff50d1f28bf9ec636a420b4e3f5162e4b1b2a2d63fa5f031748"
            ],
            "contradicting_event_ids": [],
            "accepted_proof_kinds": [
              "observed"
            ],
            "evidence_proof_kinds": [
              "observed"
            ],
            "latest_observation_at": "2026-08-20T15:57:03.924Z",
            "freshness": "fresh"
          }
        ]
      },
      "canonical_url": "https://sourcey.com/catalog/stripe/agent-readiness/stripe-payments-api/api-payment-lifecycle",
      "projection_digest": "sha256:3bd6c6cb6971100a485d73aaab3be57a4c75fc790b661cf1c745bead1251a73c"
    }
  }
}
