CAMARA Quality-on-Demand session
—Issue a short-lived operator credential, load one fixed synthetic incident, freeze one CAMARA Quality-on-Demand request, authorize that exact request, and independently verify the signed execution receipt. Five steps, one bounded synthetic incident.
This page demonstrates a cryptographic control chain, not a carrier deployment or an independently compatible wallet.
Not claimed: external-wallet interoperability, live carrier execution, legal authority, certification, accreditation, or production readiness.
The wallet, identifiers, and keys are ephemeral. Reloading discards the browser capability; the reset control asks the server to discard its matching sandbox state.
embedded ephemeral wallet
The sandbox creates a synthetic carrier decision. The embedded wallet proves possession of an ephemeral P-256 key and receives a short-lived, holder-bound Network Operator SD-JWT VC.
minimum operator authority
Inspect only the privacy-reduced wallet card. The raw credential, holder key, internal operator references, and status index never appear in the page.
fixed synthetic incident
The page asks the sandbox for one fixed synthetic CAPIF/MEC incident and its pre-bounded Quality-on-Demand proposal. It does not run Edge Lab's HTTP action plane or an autonomous agent. No model key or carrier credential is used.
—holder + transaction binding
The embedded wallet presents only the authorization claims required by policy. The SD-JWT holder proof is bound to a fresh nonce, the holder key, and the exact action shown above. This reliable laptop path does not claim an external-wallet OID4VP HTTP exchange.
public-key verification
The sandbox verifies the wallet-derived permission against the frozen request, records bounded mock acceptance, and signs a receipt. This page does not call Edge Lab's actual HTTP action plane. Receipt verification uses anchored public key material; it does not prove carrier fulfilment.
Each control runs on an isolated fork of this synthetic session, so your completed main path stays inspectable.
Mark the forked credential revoked and try the same holder-bound presentation.
Change the profile after wallet approval and test the exact-action boundary.
Submit the bounded destructive fixture and confirm it is rejected before mock acceptance.
The embedded wallet makes this event demo repeatable and offline-friendly. A phone-wallet path will be enabled only after the Network Operator credential profile completes independent issuance and presentation compatibility testing.