Outcome
Provide a clear UI where contributors and evaluators can select a configured provider, initiate a sandbox payment, follow redirect/webhook state, verify status, and test refunds without editing source code.
Guardrails
- Browser code must never receive provider secret keys.
- The console must clearly distinguish mock, sandbox, and live modes.
- Destructive/live actions require explicit server-side policy and confirmation.
- Logs and payloads must be sanitized.
Acceptance criteria
Outcome
Provide a clear UI where contributors and evaluators can select a configured provider, initiate a sandbox payment, follow redirect/webhook state, verify status, and test refunds without editing source code.
Guardrails
Acceptance criteria