01

The problem

An agent can check one request, then submit another. A green badge from the earlier check says nothing about the new recipient, text or metadata.

02

Our approach

Sentry signs the result and binds it to digests of the request and action. The client verifies that binding, the signature and the expiry before using the verdict. Changed input needs a new check.

03

What we checked

Local client and backend checks cover altered requests and invalid signatures. The live browser flow also rejected an expired result and asked for an explicit new check.

04

The limit

This helps only when the consuming application verifies the result and gates the action. A signature does not prove merchant honesty or completed payment settlement.

Source & context

Local client, proxy and backend verification

Open the local verification record

Engineering record from 28 September 2026. Simulated balances and wallets; no production settlement or independent security audit.