{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=himanshu-jha/webhook-replay-boundary@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Analyzes captured webhook delivery scenarios as a security and correctness boundary. Use it before every handler or provider-integration release and after duplicate-effect or signature incidents. Four sibling probes verify that signatures bind the exact raw body, enforce signature and timestamp freshness, require explicit idempotency keys to be non-empty, stable across redeliveries, and unique across event IDs while covering provider retry horizons, and prove verification/claim/side-effect/ack ordering; a synthesis join exposes replay paths that isolated signature checks miss and orders fixes by severity. It reads JSON only, sends no webhook, executes no handler, writes no idempotency record, and makes no network calls. Run with input=evidence/webhook-scenarios.json or omit input for the bundled demo. Limits: HMAC-SHA256 is the portable modeled scheme, secrets in input should be synthetic or safely exported test material, database isolation and crash behavior are assessed only from declared scenario facts, an","distribution":{"digest":"sha256:af5c4b9dc100e4b30ae57f39090ab9b7f2037af0535af9536df3c541831181a4","mediaType":"application/vnd.modiqo.rote-flow","size":11868,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"license":"MIT","links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0.json"},"name":"webhook-replay-boundary","owner":{"kind":"org","slug":"himanshu-jha"},"parameters":[{"description":"Workspace-relative webhook scenario JSON. Omit for the bundled demo; pass input=evidence/payment-webhook-replays.json for fresh captured test scenarios.","example":"evidence/payment-webhook-replays.json","input":{"allowCustom":true,"choices":[],"label":"Input"},"name":"input","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/webhook-replay-boundary@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.78.0"},"publishedAt":"2026-09-04T12:26:49.089837+00:00","reference":"himanshu-jha/webhook-replay-boundary@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":2,"installs":0},"steps":{"count":5,"names":["audit_idempotency_replay_scope","enforce_signature_time_window","prove_side_effect_ordering","synthesize_replay_boundary","verify_exact_raw_body_binding"]},"title":"webhook-replay-boundary","type":"play","version":"0.1.0","visibility":"public"}