SPC Attack Lab
Learn which server checks turn signed browser evidence into a trustworthy authorization.
Replay
Submit an already accepted assertion again. A single-use issuer challenge must reject it.
CHALLENGE_REPLAYAmount mismatch
Compare the browser-confirmed total with the stored transaction amount.
AMOUNT_MISMATCHPayee mismatch
Change the issuer's expected merchant identity after confirmation.
PAYEE_MISMATCHWrong origin
An assertion from an unexpected top origin cannot authorize this transaction.
ORIGIN_MISMATCHOrdinary WebAuthn
webauthn.get is not accepted where payment.get is required.
INVALID_CEREMONYRun an experiment
First approve a payment in the Request Builder. Use its issuer inspector to view the verified evidence, then replay the captured response using the button shown after approval.
Amount, payee, origin, and ceremony checks are performed by POST /api/payment/verify. The normal builder can demonstrate mismatches by changing fields between payment creation and native confirmation while inspecting the resulting verdict.