Provider API
Checking…
Three tested invocation invariants
Privileged fields reject, nonexistent items do nothing, and replay commits once. Trusted state comes from a source-fixed server replay.
Scope: three frozen synthetic checkout cases on the exact tested build. Thurstone is a testing/audit system—not runtime enforcement, certification, guaranteed security, or arbitrary-site verification.
Open this route in the official ChatGPT in-app browser. In Chrome 149+, open chrome://flags/#enable-webmcp-testing, choose Enabled, and relaunch Chrome.
If Thurstone reports consumer-mismatch, close other same-origin Thurstone tabs, then reload this tab.
The browser supplies only native receipts and traces from the source-fixed calls. The verifier accepts no caller-selected tool, payload, schema, expected value, target URL, or trusted state and replays the frozen sequence in a fresh server-only store.
The one-run guard uses an exclusive browser LockManager claim keyed to this exact build in same-origin localStorage for this browser profile. Clearing site storage or using another browser or profile can bypass it; no in-app reset is provided, and the guard is not a security boundary.
Checking…
Checking…
Discovering…
Compatibility: pending · one read-only cart_get completed; the measured reset runs atomically at one-shot admission.
checkout_request · rejection-no-op
Awaiting the one-shot run
cart_update · rejection-no-op
Awaiting the one-shot run
checkout_request · one-transition-then-replay-no-op
Awaiting the one-shot run