Skip to content

Phase 0 execution register ​

Started: 2026-09-01 (Asia/Manila)
Scope: decisions, provider evidence, sandbox readiness, and go/no-go only.
Current result: NO-GO for any Whop money operation. Phase 0 is partially complete and blocked on owner policy approval, an isolated sandbox, account-specific Whop capability evidence, and tax/compliance ownership.

Status dashboard ​

GateStatusEvidence / required completion
Funding sourceComplete — owner-confirmedBloxClips pays clippers from BloxClips' Whop business balance. No creator-funded or per-campaign Whop origin.
Candidate railConditional recommendation completeCurrent API ledger transfer from the BloxClips business balance to a verified creator balance; direct user_… capability remains unproven.
Seven product policiesPending owner approvalRecommended ballot below; source-balance choice is no longer among them.
API version/SDKResearch complete; runtime pin missingLatest researched pin 2026-08-31; installed official SDK 1.0.14 supports account, ledger, transfer, idempotency, and webhook types. Recheck on implementation date.
Local credential isolationFailed readinessA gitignored backend .env contains generic Whop variables, but no payout-specific environment/base/origin guard proves sandbox.
Account identity/balance/capabilityNot runExact safe read sequence identified below; cannot use current key without sandbox proof.
Creator recipientNot availableNo consenting sandbox user_… payment recipient or payment-specific identity proof. Existing chat WhopIdentity is insufficient.
Transfer/idempotency/retrievalNot runBlocked by sandbox/account/recipient gates.
Webhook validationNot run for TransfersExisting Whop chat webhook verifies signatures but has no transfer subscription/inbox evidence.
Tax/compliance policyPending owner/counselNeed ruling for balance-credit reporting, forms, countries, gross/net, and whether payout is blocked or reported.

Local readiness evidence ​

No secret values were printed or copied.

  • Bloxclips-backend/.env is excluded by Bloxclips-backend/.gitignore:3 and contains generic variable names for Whop key, company ID/route, and webhook secret.
  • Neither the checked environment shape nor .env.template defines a payout-specific sandbox environment, base URL, or immutable payout origin.
  • Bloxclips-backend/src/utils/whopClient.ts constructs a generic SDK client from the key only; it does not pin Api-Version-Date, base URL, origin, timeout, or retry policy.
  • Bloxclips-backend/src/api/routes/live.ts:14 defaults its unrelated Whop base URL to production when no base is configured. This does not prove which environment the key belongs to and makes implicit-host reuse unsafe.
  • Installed official SDK 1.0.14 exposes accounts.me(), accounts.retrieve({id: "me"}), ledgerAccounts.retrieve, and Transfers create/list/listRecipients/retrieve.
  • Current Retrieve Account documentation exposes capabilities.transfer and balance breakdown fields available, in_transit, pending, and reserve.
  • The ledger retrieval SDK/type/reference requires company:balance:read and payout:account:read and can resolve a biz_… to its ledger details.

Conclusion: the next read-only calls are technically identified, but the configured credential must not be used until its sandbox host and ownership are established outside the call itself.

Provisional owner decision ballot ​

These are recommendations, not approvals. The owner can approve all defaults together or specify exceptions by number.

#Recommended Phase 0 defaultStatus
1Seven-day rolling finality hold; 24-hour ingestion grace after campaign cutoffPending
2USD 100 aggregate automatic transfer threshold for initial rollout, reviewed after measured fees/operationsPending
3No additional creator fee; creator RPM is the promised payout and CPM minus RPM is BloxClips marginPending
4At most one active clipper group per creator per campaign; individual override winsPending
5Post-payment negative correction becomes finance-reviewed recovery due and may offset future BloxClips earnings after notice; no invented Whop clawbackPending
6Full local campaign-budget commitment before LIVE; maintain a forecasted buffer in the single BloxClips Whop business balancePending
7First automatic sweep includes content-creator earnings only; affiliate commissions remain separate until independently modeledPending

Tax/compliance is not a selectable default: finance/counsel must state the applicable rule before production credit.

Exact sandbox entry criteria ​

An operator must provide all of these through secret management/dashboard evidence, not chat or source control:

  1. WHOP_PAYOUT_ENVIRONMENT=sandbox.
  2. API base exactly https://sandbox-api.whop.com/api/v1.
  3. Sandbox Account API key whose dashboard owner is the sandbox BloxClips business.
  4. Expected sandbox biz_… ID recorded independently of the API response.
  5. Least-privilege read/transfer/webhook scopes confirmed by Whop.
  6. A consenting sandbox creator and independently obtained user_… ID.
  7. Sandbox webhook endpoint and ws_… secret isolated from chat and production.
  8. Written confirmation that sandbox supports ledger Transfers despite the sandbox guide's broad payout limitation.

If any item is absent, the validator exits before authentication.

First read-only validation sequence ​

Once the entry criteria are met, the smallest test is:

  1. Construct SDK client with sandbox base, explicit API pin, short timeout, and maxRetries: 0.
  2. Call accounts.me() and require returned ID to equal the independently configured sandbox BloxClips biz_….
  3. Require capabilities.transfer === "active" and inspect USD available, pending, in_transit, and reserve separately.
  4. Call ledgerAccounts.retrieve({id: returnedBusinessId}); record backing ldgr_…, payments approval, currency balance, and transfer fee.
  5. Call transfers.listRecipients({origin_id: returnedBusinessId}) or the Whop-confirmed recipient-verification alternative; require the consenting sandbox creator identity.
  6. Stop and produce redacted evidence for human review. Do not create a transfer in the same run.

Only a second explicitly approved validator run may attempt the minimal ledger transfer/idempotency/webhook sequence in 05-sandbox-validation.md.

Copy-ready Whop capability request ​

BloxClips is implementing automatic creator credits funded from BloxClips' own Whop business balance. BloxClips remains the source of truth for campaign rules, verified views, CPM budget consumption, creator RPM, earnings, finality, payout state, and reconciliation. We want to credit a creator's Whop balance; the creator will later use Whop's withdrawal flow.

Please confirm for our sandbox and production business accounts:

  1. Can our biz_… business balance/backing ldgr_… send USD Current API ledger transfers directly to creator user_… balances?
  2. If direct user credit is unavailable, must each creator be an enrolled connected biz_… account?
  3. What exact scopes are required for Current API account identity/balance, ledger retrieval, transfer create/retrieve/list/list-recipients, and transfer.created|completed|failed webhooks? Is payout:transfer_funds still the applicable create scope?
  4. What account approval/KYC, countries, currencies, minimum/maximum amounts, velocity limits, fees, available-funds, pending-funds, reserve, and stablecoin-rails restrictions apply to our origin and recipients?
  5. Does sandbox support ledger Transfers, user recipients, balances, same-key idempotency, transfer webhooks, retrieval/listing, and safe failure fixtures? The public sandbox guide says payout functionality is unavailable; does that include Transfers?
  6. For Transfers, how long is body idempotence_key retained, and should it equal the Idempotency-Key header?
  7. When a transfer is failed but may later succeed under the same ctt_… ID, what provider action/retry semantics cause that transition?
  8. Is any transfer cancellation/reversal/recovery operation available that is not in the public Current API reference?

Store Whop's response with sender/date/account context and mark each answer as account-specific or general documentation.

Go/no-go rule ​

Phase 0 becomes GO for Phase 1 local accounting only when decisions 1–7 are approved and tax/compliance ownership is assigned. It becomes GO for Whop adapter/sandbox dispatch work only when all sandbox entry criteria and account-specific provider questions are resolved.

Until then:

  • no configured Whop credential may be probed;
  • no provider transfer code joins a production path;
  • no existing payout/send route is repurposed;
  • provider-neutral schema design may be reviewed but not claimed as a validated Whop integration.