JC·HARNESS

Integration Actions

Send public-safe pentest evidence to Sandbox or BrowserOps only when the action has a clear operator purpose and downstream confirmation.

Preview

available

Anyone can preview the exact payload. No downstream call is made and no success is claimed.

Protected Send

operator checkpoint

The server has PLATPHORM_API_KEY for downstream calls, but the browser action still needs an operator session key or Authorization header.

Evidence Contract

artifact backed

Handoffs include run id, target scope, allowed host, selected evidence routes, trace ids, and a public-safe redaction policy.

Evidence Handoff Workflow
Choose a run and a concrete downstream job. Preview shows the exact public-safe payload; protected send requires an operator session key and downstream confirmation.
no fake success

Evidence source

Operator authorization

Server downstream keyserver configured
Browser operator keyoperator checkpoint

Server `PLATPHORM_API_KEY` lets the backend call PlatPhorm services after an operator-authorized request. It does not make this public page a free mutation endpoint. Add a runtime PlatPhorm key below to enable protected sends from this browser session.

What will be sent

  • run id and target scope
  • allowed-host validation result
  • public-safe run and log artifact links
  • trace/request ids

Evidence routes

  • https://example.test
  • https://pentest.platphormnews.com/runs/pentest-2026-06-14-a39c81cd
  • https://pentest.platphormnews.com/api/v1/runs/pentest-2026-06-14-a39c81cd/logs

Expected confirmation

  • handoff acceptance id
  • schema/scope validation status
  • safe replay or dry-run evidence pointer

Protected sends are disabled until this browser session has an operator PlatPhorm key. Preview remains available and shows exactly what would be sent.

Operator credential controlscollapsed by default

Runtime Credentials

Server credentials are used first. Browser-session keys are optional one-action overrides and are never rendered back.

0 session keys
PlatPhorm API keyserver configured

Used for real-run setup, protected integration previews, downstream PlatPhorm handoff.

Vercel AI Gateway keyserver configured

Used for model routing checks, future gateway-backed model calls.

Vercel tokenserver configured

Used for future sandbox job creation when server OIDC is unavailable.

Direct provider keys are hidden because AI Gateway is configured server-side for model execution.

Provider Status

22 PlatPhorm services available through registry/API
Vercelconfigured
Neon Postgresconfigured
Vercel AI Gatewayconfigured
PlatPhorm Sandboxconfigured
Vercel Functions Webhooksconfigured
Local storage plus PlatPhorm Filesconfigured
PlatPhorm service registry
PlatPhorm Docsconfigured
PlatPhorm Sheetsconfigured
PlatPhorm Filesconfigured
PlatPhorm Traceconfigured
PlatPhorm WebhookLabconfigured
PlatPhorm Sandboxconfigured
PlatPhorm BrowserOpsconfigured
PlatPhorm AgentOpsconfigured
PlatPhorm TrustOpsconfigured
PlatPhorm Evalsconfigured
PlatPhorm AgentUIconfigured
PlatPhorm Webhooksconfigured
PlatPhorm Specconfigured
PlatPhorm MCPconfigured
Phormconfigured
PlatPhorm ASCIIconfigured
PlatPhorm Desaconfigured
PlatPhorm XMLconfigured
PlatPhorm JSONconfigured
PlatPhorm Markdownconfigured
PlatPhorm SearchOpsconfigured
PlatPhorm SitemapOpsconfigured