Northfield Bank · issuer (fictional)

Enrollment is a one-time guided step. Step 1 adds a fictional test card. Step 2 creates a WebAuthn credential bound to this bank origin with the payment extension (used by SPC). Step 3 happens at the wallet origin.

1 · Add a card

Fictional test card, last four only:not added

2 · Enroll SPC credential

rpId: …. Creates a real WebAuthn credential (platform authenticator, extensions.payment.isPayment = true) when this browser can, and always a software "simulated SPC" credential so the demo works anywhere.

none

3 · Wallet

Open the wallet and register its device key: wallet origin (or use the phone frame on the shop's Enroll page). Registered device keys: 0

Fraud-loss ledger (illustrative rules)

Liability rules table (illustrative, not a real rulebook)