Demo Merchant
Adversarial training mode
Controlled experiments

SPC Attack Lab

Learn which server checks turn signed browser evidence into a trustworthy authorization.

Back to request builder
Safe demonstration only. These controls never move money and do not weaken browser security.
01

Replay

Submit an already accepted assertion again. A single-use issuer challenge must reject it.

CHALLENGE_REPLAY
02

Amount mismatch

Compare the browser-confirmed total with the stored transaction amount.

AMOUNT_MISMATCH
03

Payee mismatch

Change the issuer's expected merchant identity after confirmation.

PAYEE_MISMATCH
04

Wrong origin

An assertion from an unexpected top origin cannot authorize this transaction.

ORIGIN_MISMATCH
05

Ordinary WebAuthn

webauthn.get is not accepted where payment.get is required.

INVALID_CEREMONY

Run an experiment

First approve a payment in the Request Builder. Use its issuer inspector to view the verified evidence, then replay the captured response using the button shown after approval.

Signed assertion→Single-use challenge→Declined replay

Amount, payee, origin, and ceremony checks are performed by POST /api/payment/verify. The normal builder can demonstrate mismatches by changing fields between payment creation and native confirmation while inspecting the resulting verdict.