Appearance
Phase 0 execution register
Started: 2026-09-01 (Asia/Manila)
Scope: decisions, provider evidence, sandbox readiness, and go/no-go only.
Current result: NO-GO for any Whop money operation. Phase 0 is partially complete and blocked on owner policy approval, an isolated sandbox, account-specific Whop capability evidence, and tax/compliance ownership.
Status dashboard
| Gate | Status | Evidence / required completion |
|---|---|---|
| Funding source | Complete — owner-confirmed | BloxClips pays clippers from BloxClips' Whop business balance. No creator-funded or per-campaign Whop origin. |
| Candidate rail | Conditional recommendation complete | Current API ledger transfer from the BloxClips business balance to a verified creator balance; direct user_… capability remains unproven. |
| Seven product policies | Pending owner approval | Recommended ballot below; source-balance choice is no longer among them. |
| API version/SDK | Research complete; runtime pin missing | Latest researched pin 2026-08-31; installed official SDK 1.0.14 supports account, ledger, transfer, idempotency, and webhook types. Recheck on implementation date. |
| Local credential isolation | Failed readiness | A gitignored backend .env contains generic Whop variables, but no payout-specific environment/base/origin guard proves sandbox. |
| Account identity/balance/capability | Not run | Exact safe read sequence identified below; cannot use current key without sandbox proof. |
| Creator recipient | Not available | No consenting sandbox user_… payment recipient or payment-specific identity proof. Existing chat WhopIdentity is insufficient. |
| Transfer/idempotency/retrieval | Not run | Blocked by sandbox/account/recipient gates. |
| Webhook validation | Not run for Transfers | Existing Whop chat webhook verifies signatures but has no transfer subscription/inbox evidence. |
| Tax/compliance policy | Pending owner/counsel | Need ruling for balance-credit reporting, forms, countries, gross/net, and whether payout is blocked or reported. |
Local readiness evidence
No secret values were printed or copied.
Bloxclips-backend/.envis excluded byBloxclips-backend/.gitignore:3and contains generic variable names for Whop key, company ID/route, and webhook secret.- Neither the checked environment shape nor
.env.templatedefines a payout-specific sandbox environment, base URL, or immutable payout origin. Bloxclips-backend/src/utils/whopClient.tsconstructs a generic SDK client from the key only; it does not pinApi-Version-Date, base URL, origin, timeout, or retry policy.Bloxclips-backend/src/api/routes/live.ts:14defaults its unrelated Whop base URL to production when no base is configured. This does not prove which environment the key belongs to and makes implicit-host reuse unsafe.- Installed official SDK 1.0.14 exposes
accounts.me(),accounts.retrieve({id: "me"}),ledgerAccounts.retrieve, and Transfers create/list/listRecipients/retrieve. - Current Retrieve Account documentation exposes
capabilities.transferand balance breakdown fieldsavailable,in_transit,pending, andreserve. - The ledger retrieval SDK/type/reference requires
company:balance:readandpayout:account:readand can resolve abiz_…to its ledger details.
Conclusion: the next read-only calls are technically identified, but the configured credential must not be used until its sandbox host and ownership are established outside the call itself.
Provisional owner decision ballot
These are recommendations, not approvals. The owner can approve all defaults together or specify exceptions by number.
| # | Recommended Phase 0 default | Status |
|---|---|---|
| 1 | Seven-day rolling finality hold; 24-hour ingestion grace after campaign cutoff | Pending |
| 2 | USD 100 aggregate automatic transfer threshold for initial rollout, reviewed after measured fees/operations | Pending |
| 3 | No additional creator fee; creator RPM is the promised payout and CPM minus RPM is BloxClips margin | Pending |
| 4 | At most one active clipper group per creator per campaign; individual override wins | Pending |
| 5 | Post-payment negative correction becomes finance-reviewed recovery due and may offset future BloxClips earnings after notice; no invented Whop clawback | Pending |
| 6 | Full local campaign-budget commitment before LIVE; maintain a forecasted buffer in the single BloxClips Whop business balance | Pending |
| 7 | First automatic sweep includes content-creator earnings only; affiliate commissions remain separate until independently modeled | Pending |
Tax/compliance is not a selectable default: finance/counsel must state the applicable rule before production credit.
Exact sandbox entry criteria
An operator must provide all of these through secret management/dashboard evidence, not chat or source control:
WHOP_PAYOUT_ENVIRONMENT=sandbox.- API base exactly
https://sandbox-api.whop.com/api/v1. - Sandbox Account API key whose dashboard owner is the sandbox BloxClips business.
- Expected sandbox
biz_…ID recorded independently of the API response. - Least-privilege read/transfer/webhook scopes confirmed by Whop.
- A consenting sandbox creator and independently obtained
user_…ID. - Sandbox webhook endpoint and
ws_…secret isolated from chat and production. - Written confirmation that sandbox supports
ledgerTransfers despite the sandbox guide's broad payout limitation.
If any item is absent, the validator exits before authentication.
First read-only validation sequence
Once the entry criteria are met, the smallest test is:
- Construct SDK client with sandbox base, explicit API pin, short timeout, and
maxRetries: 0. - Call
accounts.me()and require returned ID to equal the independently configured sandbox BloxClipsbiz_…. - Require
capabilities.transfer === "active"and inspect USDavailable,pending,in_transit, andreserveseparately. - Call
ledgerAccounts.retrieve({id: returnedBusinessId}); record backingldgr_…, payments approval, currency balance, and transfer fee. - Call
transfers.listRecipients({origin_id: returnedBusinessId})or the Whop-confirmed recipient-verification alternative; require the consenting sandbox creator identity. - Stop and produce redacted evidence for human review. Do not create a transfer in the same run.
Only a second explicitly approved validator run may attempt the minimal ledger transfer/idempotency/webhook sequence in 05-sandbox-validation.md.
Copy-ready Whop capability request
BloxClips is implementing automatic creator credits funded from BloxClips' own Whop business balance. BloxClips remains the source of truth for campaign rules, verified views, CPM budget consumption, creator RPM, earnings, finality, payout state, and reconciliation. We want to credit a creator's Whop balance; the creator will later use Whop's withdrawal flow.
Please confirm for our sandbox and production business accounts:
- Can our
biz_…business balance/backingldgr_…send USD Current APIledgertransfers directly to creatoruser_…balances?- If direct user credit is unavailable, must each creator be an enrolled connected
biz_…account?- What exact scopes are required for Current API account identity/balance, ledger retrieval, transfer create/retrieve/list/list-recipients, and
transfer.created|completed|failedwebhooks? Ispayout:transfer_fundsstill the applicable create scope?- What account approval/KYC, countries, currencies, minimum/maximum amounts, velocity limits, fees, available-funds, pending-funds, reserve, and stablecoin-rails restrictions apply to our origin and recipients?
- Does sandbox support
ledgerTransfers, user recipients, balances, same-key idempotency, transfer webhooks, retrieval/listing, and safe failure fixtures? The public sandbox guide says payout functionality is unavailable; does that include Transfers?- For Transfers, how long is body
idempotence_keyretained, and should it equal theIdempotency-Keyheader?- When a transfer is
failedbut may later succeed under the samectt_…ID, what provider action/retry semantics cause that transition?- Is any transfer cancellation/reversal/recovery operation available that is not in the public Current API reference?
Store Whop's response with sender/date/account context and mark each answer as account-specific or general documentation.
Go/no-go rule
Phase 0 becomes GO for Phase 1 local accounting only when decisions 1–7 are approved and tax/compliance ownership is assigned. It becomes GO for Whop adapter/sandbox dispatch work only when all sandbox entry criteria and account-specific provider questions are resolved.
Until then:
- no configured Whop credential may be probed;
- no provider transfer code joins a production path;
- no existing payout/send route is repurposed;
- provider-neutral schema design may be reviewed but not claimed as a validated Whop integration.