OBP public catalogue
A dated unauthenticated GET checkpoint returned HTTP 200 with 226 catalogue entries on 25 July 2026.
- Account access
- No
- Consent used
- No
- Payment executed
- No
Follow one synthetic business payment from organization authority and minimized account evidence through approve, exact-action step-up, decline, provider ambiguity, reconciliation, and model governance.
The campaign uses a synthetic PHP 750 SME payment for the GFTN path and a separate EUR 1,500-over-1,000-cap negative control.
Open a scenario to see the evidence and the limit of the claim.
Bundled GLEIF testnet evidence is verified offline and connected to bounded officer and agent authority.
Not production QVI issuance or legal bank onboarding.
Three OBP-shaped read invocations become three bounded risk features. Raw feature values remain undisclosed and the payload vault path is exercised.
Synthetic records, not customer-consented account access.
Risk, organization authority, PaymentAuthorization v1, provider request, delegation and signed-receipt gates all verify.
Authorization evidence is not provider acceptance.
The payment blocks first. A pinned local holder key signs the exact payment, validates OID4VP transaction data, and unlocks a fresh authorization.
Local holder fixture, not external-wallet regulated SCA.
No payment authorization is issued and no checkout or gateway dispatch is attempted.
This proves control behavior, not model accuracy.
The delegated agent is denied when the payment crosses its bounded authority.
Local policy enforcement, not a bank-side payment limit.
The first delegation verifies; after revocation, the same purchase is denied.
Not a production revocation registry or legal termination.
Amount, currency, payee, VoP, consent/SCA, provider request, risk, idempotency and organization-authority substitutions all fail closed.
A commitment binds evidence; it does not make the evidence true.
Risk, wallet and payment-authorization replay, payment substitution, receipt tamper and attacker re-signing are rejected.
Not transport-level exactly-once settlement.
One provider mutation is recorded. The identical replay resolves from state with zero second mutations and signed evidence verifies.
The provider is a deterministic local fixture.
A timed-out dispatch becomes outcome_unknown. Repetition does not
issue another mutation.
No real provider timeout or callback was observed.
One read-only lookup resolves the ambiguous state; mutation calls during reconciliation remain zero.
Local recovery mechanics, not bank settlement evidence.
Poison and feedback-replay attempts fail. Signed shadow gates pass, a reviewed promotion runs, and the kill-switch rollback is exercised.
Synthetic measurement, not bank calibration or performance.
The implementation exists, but your account, consent, credential, or explicit provider action is the authority boundary.
A dated unauthenticated GET checkpoint returned HTTP 200 with 226 catalogue entries on 25 July 2026.
Read one sandbox account, balance and transaction set into the same minimized three-feature boundary.
--read.Create one PHP sandbox checkout only after the approved exact-payment gate.
The runner blocks socket use, reads no provider credential, launches no browser, and returns a public-safe matrix.
cd "/home/kaali/crazy idea"
PYTHONPATH=src:. python3 \
scripts/run_banking_sandbox_campaign.py