JC·HARNESS

Integration Actions

Send public-safe pentest evidence to Sandbox or BrowserOps only when the action has a clear operator purpose and downstream confirmation.

Preview

available

Anyone can preview the exact payload. No downstream call is made and no success is claimed.

Protected Send

operator checkpoint

The server has PLATPHORM_API_KEY for downstream calls, but the browser action still needs an operator session key or Authorization header.

Evidence Contract

artifact backed

Handoffs include run id, target scope, allowed host, selected evidence routes, trace ids, and a public-safe redaction policy.

Evidence Handoff Workflow
Choose a run and a concrete downstream job. Preview shows the exact public-safe payload; protected send uses the server PlatPhorm key when configured, or a browser-session runtime key as an override.
no fake success

Evidence source

Operator authorization

Server downstream keyserver configured
Browser operator keyoperator checkpoint

Server `PLATPHORM_API_KEY` is checked before this page renders. When present, protected sends use that backend credential without exposing it to the browser. Add a runtime PlatPhorm key only when the server key is missing or you need a one-action override.

What will be sent

  • run id and target scope
  • allowed-host validation result
  • public-safe run and log artifact links
  • trace/request ids

Evidence routes

  • https://example.test
  • https://pentest.platphormnews.com/runs/pentest-2026-06-14-a39c81cd
  • https://pentest.platphormnews.com/api/v1/runs/pentest-2026-06-14-a39c81cd/logs

Expected confirmation

  • handoff acceptance id
  • schema/scope validation status
  • safe replay or dry-run evidence pointer

Server-side `PLATPHORM_API_KEY` is configured. Protected sends are available from this deployment; the key is never rendered and delivery is still confirmed only by the downstream service.

Operator credential controlscollapsed by default

Runtime Credentials

Server credentials are used first. Browser-session keys are optional one-action overrides and are never rendered back.

0 session keys
PlatPhorm API keyserver configured

Used for real-run setup, protected integration previews, downstream PlatPhorm handoff.

Vercel AI Gateway keyserver configured

Used for model routing checks, future gateway-backed model calls.

Vercel tokenserver configured

Used for future sandbox job creation when server OIDC is unavailable.

Direct provider keys are hidden because AI Gateway is configured server-side for model execution.

Provider Status

22 PlatPhorm services available through registry/API
Vercelconfigured
Neon Postgresconfigured
Vercel AI Gatewayconfigured
PlatPhorm Sandboxconfigured
Vercel Functions Webhooksconfigured
Local storage plus PlatPhorm Filesconfigured
PlatPhorm service registry
PlatPhorm Docsconfigured
PlatPhorm Sheetsconfigured
PlatPhorm Filesconfigured
PlatPhorm Traceconfigured
PlatPhorm WebhookLabconfigured
PlatPhorm Sandboxconfigured
PlatPhorm BrowserOpsconfigured
PlatPhorm AgentOpsconfigured
PlatPhorm TrustOpsconfigured
PlatPhorm Evalsconfigured
PlatPhorm AgentUIconfigured
PlatPhorm Webhooksconfigured
PlatPhorm Specconfigured
PlatPhorm MCPconfigured
Phormconfigured
PlatPhorm ASCIIconfigured
PlatPhorm Desaconfigured
PlatPhorm XMLconfigured
PlatPhorm JSONconfigured
PlatPhorm Markdownconfigured
PlatPhorm SearchOpsconfigured
PlatPhorm SitemapOpsconfigured