This is a fake transaction demo. No accounts, cards, money, land or production services are involved. Send only the documented synthetic JSON payloads.
Use a fresh random 32-character lowercase hexadecimal run ID. The sequence is init → validate → confirm → charge → receipt. The audit endpoint shows ordered application requests, body SHA-256 hashes and attempt/success counts.
A separately configured Cloudflare WAF rule may challenge an exact selected run path. This Worker never creates a challenge or clearance cookie. A request stopped by the edge must not appear in the application audit.
Keep the same browser session. Runs expire after one hour and accept at most 100 recorded requests, including audit reads. Request bodies are limited to 4 KiB; raw bodies and session cookies are never written to the audit.
See the lab README for payloads, deployment, the DNS decision and the manual human-solve protocol. Automated browsers may fail a real challenge.
Open the normal human-browser baseline. This link does not configure Cloudflare WAF or guarantee a challenge will be issued.