portable sandbox · embedded wallet · mock network

Put the exact network permission in a wallet.

Issue a short-lived operator credential, load one fixed synthetic incident, freeze one CAMARA Quality-on-Demand request, authorize that exact request, and independently verify the signed execution receipt. Five steps, one bounded synthetic incident.

read before running

Real controls. Synthetic authority and network.

This page demonstrates a cryptographic control chain, not a carrier deployment or an independently compatible wallet.

Actually checked

  • Issuer signature and active credential status
  • Holder proof and one-time wallet presentation
  • Exact action and transaction binding
  • Bounded denial paths and signed-receipt verification

Deliberately simulated

  • Carrier administrator and operator identity
  • Device, incident, and network measurements
  • CAMARA provider fulfilment and commercial cost
  • Production key custody and governance

Not claimed: external-wallet interoperability, live carrier execution, legal authority, certification, accreditation, or production readiness.

the governed round-trip

One credential. One frozen action. One receipt.

The wallet, identifiers, and keys are ephemeral. Reloading discards the browser capability; the reset control asks the server to discard its matching sandbox state.

No session
  1. 01Issue
  2. 02Inspect
  3. 03Investigate
  4. 04Present
  5. 05Verify
Ready. Start by issuing a synthetic operator credential.
01

embedded ephemeral wallet

Issue a synthetic operator credential

Ready

The sandbox creates a synthetic carrier decision. The embedded wallet proves possession of an ephemeral P-256 key and receives a short-lived, holder-bound Network Operator SD-JWT VC.

Real: signing, holder binding, status allocation, and closed credential shape. Synthetic: the carrier administrator and operator enrollment decision.
02

minimum operator authority

Inspect the active credential

Locked

Inspect only the privacy-reduced wallet card. The raw credential, holder key, internal operator references, and status index never appear in the page.

03

fixed synthetic incident

Load and freeze the proposed action

Locked

The page asks the sandbox for one fixed synthetic CAPIF/MEC incident and its pre-bounded Quality-on-Demand proposal. It does not run Edge Lab's HTTP action plane or an autonomous agent. No model key or carrier credential is used.

04

holder + transaction binding

Approve and present from the wallet

Locked

The embedded wallet presents only the authorization claims required by policy. The SD-JWT holder proof is bound to a fresh nonce, the holder key, and the exact action shown above. This reliable laptop path does not claim an external-wallet OID4VP HTTP exchange.

tenantorganization pseudonymrole allowed operationenvironmentassurance profile active status
05

public-key verification

Verify the signed execution receipt

Locked

The sandbox verifies the wallet-derived permission against the frozen request, records bounded mock acceptance, and signs a receipt. This page does not call Edge Lab's actual HTTP action plane. Receipt verification uses anchored public key material; it does not prove carrier fulfilment.

fail closed, visibly

Try the paths that must not dispatch.

Each control runs on an isolated fork of this synthetic session, so your completed main path stays inspectable.

N1 · STATUS

Revoke, then present

Mark the forked credential revoked and try the same holder-bound presentation.

N2 · BINDING

Tamper with QoS

Change the profile after wallet approval and test the exact-action boundary.

N3 · POLICY

Try destructive delete

Submit the bounded destructive fixture and confirm it is rejected before mock acceptance.

next interoperability gate

Phone and QR wallet mode

The embedded wallet makes this event demo repeatable and offline-friendly. A phone-wallet path will be enabled only after the Network Operator credential profile completes independent issuance and presentation compatibility testing.

COMING AFTER COMPATIBILITY PROOF