{
  "artifact": "stripe-connector-contract",
  "recorded": "2026-07-20T16:55:00-05:00",
  "service": "Stripe (payments; sandbox environment)",
  "public_owner_role": "Ax0s integration operator",
  "contract": {
    "api_surface": "read-only API client pinned to Stripe API version 2026-06-24.dahlia; events are consumed as change-feed provenance only and every referenced object is re-fetched under the pinned version before mapping",
    "credential_boundary": "the restricted API key is supplied only to the per-environment systemd unit via LoadCredential; sandbox and live environments run as separate templated units with separate credentials and state",
    "data_scope": "customers, invoices, subscriptions, payment intents, and charges for one account per environment",
    "write_path": "secret-redacted object snapshots to corpus project stripe, plus pointer records and finance-domain fabric entities on slug ax0s"
  },
  "redaction": "a dedicated Stripe redaction policy runs before any write: secrets and idempotency keys, capability URLs (hosted invoice, receipt, and file links), payment-method details including card data, fingerprints, and last4, addresses, phones, emails, and names are redacted; free-text fields are PII-scrubbed and metadata passes only a fixed allowlist",
  "acceptance_criteria": [
    "timer-scheduled runs complete clean on the 5-minute cadence",
    "objects land as redacted corpus snapshots plus pointers with supersede-by-source-key deduplication",
    "the event watermark checkpoints atomically between runs",
    "an object-ingest and later-recall receipt is published once the first real object exists in the connected environment"
  ],
  "status": {
    "runtime": "LIVE (deployed 2026-07-18; systemd user timer ax0s-ingest-stripe@sandbox.timer, 5-minute cadence, hub host)",
    "first_scheduled_run": "2026-07-18T08:58:07-05:00 completed clean",
    "scheduled_runs_total": "670 timer runs through 2026-07-20T16:41-05:00",
    "objects_ingested": 0,
    "availability_window": "on 2026-07-20 a hub host DNS-resolution outage failed 60 consecutive scheduled runs between 03:42 and 08:37 CDT; operation resumed automatically with no operator action",
    "note": "the sandbox environment currently holds zero objects; connector operation is demonstrated, object ingest is not yet"
  },
  "pipeline": {
    "source": "ax0s-ingest v0.1.0 (versioned source + 261-test suite)"
  },
  "limitation": "This artifact proves connector deployment, the pinned read-only API contract, pre-write redaction policy, and scheduled operation on the recorded date, including a disclosed same-day host-network outage window. No object ingest or later recall is demonstrated yet; the ledger row upgrades only with a dated ingest receipt."
}
