Provider Reality & Operations Dashboard

Truthful operational status of external billing, object storage, and push notification integrations.

Operational Reality Audited
Zero Secrets in Browser (Command 21 Invariant)

Provider credentials (Stripe secret keys, APNs p8 private keys, FCM service account JSON, and S3 credentials) are strictly held in secure server environments. The Platform Admin console reports operational status, latency, and error codes without ever reading, displaying, or transmitting secret values.

BILLING

Stripe Billing & Invoicing

IMPLEMENTED NOT_CONFIGURED

Hosted Checkout sessions, Customer Portal, and webhook signature verification.

Verified Capabilities:
Credit/Debit CardsWebhook RetriesServer Authoritative PricesIdempotent Receipts
Protocol: HTTPS REST / Webhooks Encrypted Server-Side
BILLING

Apple App Store (StoreKit 2)

IMPLEMENTED NOT_CONFIGURED

Native iOS in-app purchases with server-side JWS transaction verification.

Verified Capabilities:
StoreKit 2 JWSAuto-Renewable SubscriptionsGrace Period Support
Protocol: Apple App Store Server API Encrypted Server-Side
BILLING

Google Play Billing (v7)

IMPLEMENTED NOT_CONFIGURED

Android in-app purchases with Google Play Developer API server verification.

Verified Capabilities:
Play Billing v7RTDN WebhooksAccount Linking Nonce
Protocol: Google Play Developer API v3 Encrypted Server-Side
STORAGE

Local & Encrypted Object Storage

IMPLEMENTED NOT_CONFIGURED

Command 19 compliant multi-tenant storage engine with SHA-256 integrity verification.

Verified Capabilities:
Zero Pre-signed LeakageTenant IsolationStrict 1GB/20GB QuotasHash Verification
Protocol: POSIX / S3 API Compatible Encrypted Server-Side
PUSH

Firebase Cloud Messaging (FCM)

IMPLEMENTED NOT_CONFIGURED

Android push notification delivery via modern OAuth 2.0 HTTP v1 API.

Verified Capabilities:
HTTP v1 ProtocolAuto Token Invalidation on 404/410Zero Server Keys in Client
Protocol: OAuth 2.0 / HTTP v1 Encrypted Server-Side
PUSH

Apple Push Notification service (APNs)

IMPLEMENTED NOT_CONFIGURED

iOS push notification delivery via direct HTTP/2 with ES256 JWT authentication.

Verified Capabilities:
HTTP/2 ProtocolES256 ECDSA SigningImmediate Token Revocation on 410
Protocol: HTTP/2 Token Auth Encrypted Server-Side

Operational Reconciliation Triggers

Execute asynchronous reconciliation jobs without disrupting ongoing household operations.

Billing Reconciliation

Delegates to Command 18 engine to audit subscription states.

Storage Quota Reconciliation

Delegates to Command 19 engine to reconcile storage usage vs quotas.