Release 466 • External acceptance readiness

External API, Provider & Integration Readiness

The single setup authority for the active provider environment configuration: exact Cloudflare reference names, where values originate, callbacks, scopes, provider-review notes, readiness checks and correction mechanics. Actual secret/token values never belong in D1, source, Markdown or browser output.

Autonomous preparationReference names, callbacks, scopes, signatures, idempotency and local validation can advance without credentials.
Payment executionClosed unless both Development-only payment switches and explicit request confirmation are deliberately enabled for a bounded test.
Social/provider executionOAuth acceptance and publication remain closed until separately authorized.

Secret rule: API keys, OAuth client secrets, access/refresh tokens, webhook signing secrets, passwords and private keys stay in approved Cloudflare secret storage. This page handles reference names and safe readiness evidence only.

Execution rule: loading setup/readiness does not call Stripe, PayPal, Etsy, Pinterest, Meta, X, TikTok or YouTube and does not enable publication.

PayPal runtime name: use PAYPAL_SECRET for the sandbox client secret; this remains aligned with the actual payment runtime.

Cloudflare location: for Etsy connection testing on the retained main-site operator surface, configure the required Etsy variables/secrets under Production. Other explicitly Development-only integrations may still use Preview. Do not configure credentials in the retired devilndove-site-dev project.

Detailed provider setup authority

Presence means the named field exists in the active Cloudflare Pages environment; it does not mean OAuth, sandbox checkout, refund, account review or publishing acceptance has passed.

Etsy main-site connection

OAuth + automatic Shop ID discovery. Etsy remains in normal shop mode and listing writes stay locked during connection acceptance.

Provider acceptance checklist

Durable current I.T. backlog for credentials, callbacks, sandbox/test transactions, account/domain review, media/consent and evidence. A provider is not accepted simply because configuration exists.

Add or update integration metadata

This flexible registry remains available for non-secret integration metadata. Prefer the detailed setup authority above for canonical provider field names.

Registered integrations