Sample walkthrough — not a live probe of your tokens

Click once. See VALID vs WITHHELD.

A kill receipt is VALID only if the old grant bounces. WITHHELD when the vendor is green and the leftover is still live. The receipt engine is real. This page does not call Google, Microsoft, or your tenant.

Sample walkthroughLab fixtures · not your tenant

Synthetic leftovers lc_gt_01 (Google OAuth bounce) and lc_ms_02 (Entra session — vendor-green lie). Illustration only — not captured customer grants. Same receipt schema. When this host has a signing key, the sample is server-signed (Ed25519 or HMAC). Signature = integrity, not liveness. Replay bounce vs still-live is the liveness proof. Live GitHub, GitLab, Entra, Google, and AWS connectors stay locked.

Bounce to VALID

Illustration / synthetic leftover — waiting for the one-click cut.

False green to WITHHELD

Illustration / synthetic leftover — waiting for the one-click cut.

Sample walkthrough — not a production kill receipt. Lab fixtures teach the rule; a connected operator cut is the same loop against a real grant (GitHub beachhead). Do not paste live tokens, cookies, or keys.

Not connect, revoke, verify.

Inventory leftover trust. Cut out-of-band. Replay the old grant. A kill receipt is VALID only on bounce. WITHHELD if still live.

  1. Inventory leftover trust

    Sessions, OAuth grants, refresh tokens, API keys, and machine leftovers that stay alive after rotation or a vendor incident.

  2. Out-of-band cut

    Revoke from a plane that is not the possibly stolen session. Do not trust the compromised vendor to be the only cutter.

  3. Adversarial replay / bounce

    Present the old grant again from an isolated probe. Bounce means the credential failed. Still live means it worked.

  4. Kill receipt VALID only on bounce

    VALID if replay bounced. WITHHELD if still live -- even when the vendor said revoked:true. Not connect, revoke, verify.

This is lab. Live connectors stay locked.

Visitors get signed sample receipts on lc_gt_01 and lc_ms_02 — LingerCut-controlled synthetic leftovers, not captured customer grants. Production GitHub org, GitLab, Entra, Google Workspace, and AWS cuts still require the operator lock. We do not bypass that for a demo. There is no visitor sandbox that accepts your live PAT, cookie, or API key.

Talk leftover trust after a vendor incident

Same lead store as the homepage. Name, work email, company, country/region, consent. This is not a kill receipt.