Measured 11 Oct 2026. These six items still need a person. This page does not store tokens or keys. Classification stays RELEASE BLOCKED until PayPal accepts the Return URL.
Server already verified
Glue :4011/health 200. Jack :4012/health 200. Godmode :4173/api/health 200 and shell off.
Payout of 1 to locked-check@example.com returned 503 and no payout_batch_id. Unsigned webhook returned 403.
PR 34 is unmerged and is not the running tree. Deployment commit UNKNOWN.
Payouts stay locked. The sovereign live map stays empty until task 2 is signed from the physical deployment register. Coordinates are not inferred.
FAIL
1. PayPal Live Return URL
Connect is HTTP 302 and the redirect_uri is the value below. PayPal still answers with invalid_redirect_uri. Page title: Sorry about that. Their API cannot set the app Return URL. This is not done.
The signed envelope is still missing. Template on this host: /root/config/live-map-region-claims.template.json (claims array empty). The sign script is /root/scripts/manage-live-map-region-evidence.mjs and npm run live-map:region-evidence works from /root. /opt/bridge-ai-os-main does not contain that script. No coordinates are invented here.
Copy /root/config/live-map-region-claims.template.json to /etc/bridge-ai-os/live-map/region-claims.json outside git.
Fill the claims from the physical deployment register. Leave the array empty if you do not have that register.
Run the sign command from /root after real claims are filled. Do not sign an empty claims array.
Point SOVEREIGN_LIVE_MAP_SOURCE_URL at the served envelope. This page does not set that variable.
Blocked
3. Cloudflare worker for business.supaco.ai
Public https://business.supaco.ai/ and /admin are still HTTP 503 JSON because the worker requires a zero-trust JWT on every path. This host: / is 200 and /admin is 401. Keep the /admin JWT. Token verify HTTP 200. Workers Scripts list HTTP 403. supaco.ai zone lookup HTTP 200 with zero zones. Origin TLS on this name is self-signed, so a DNS-only point at this nginx waits until a publicly trusted certificate is installed. /root/edge/src/index.js now leaves public business paths open and still requires the JWT on /admin. That file is not deployed.
Open the supaco.ai zone in the account that uses those nameservers.
Create a token with Workers Scripts:Edit and give it to the operator out of band. Keep the token off this page.
Deploy /root/edge. /admin keeps the JWT requirement.
Public https://dashboard.bridge-ai-os.com/ is still HTTP 403. Title: DNS points to prohibited IP | dashboard.bridge-ai-os.com | Cloudflare. Live nameservers are decker.ns.cloudflare.com and kim.ns.cloudflare.com. The token on this host can edit DNS only on a moved bridge-ai-os.com zone (zone status moved, nameservers janet and santino, permissions dns edit and read plus zone read). A DNS-only CNAME to go.ai-os.co.za there returned HTTP 200 and the live answer stayed on the proxied address, so that record was reverted. On this host the name is HTTP 302 to /landing.html, then 200.
Open DNS for the live bridge-ai-os.com zone (decker and kim).
Replace the proxied dashboard record with a grey-cloud CNAME to go.ai-os.co.za.
Reload https://dashboard.bridge-ai-os.com/ and confirm the title is the site, not the Cloudflare 403 page.
Status: Blocked. The task-runner auth process already has GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, and GOOGLE_REDIRECT_URI set. Google returns redirect_uri_mismatch until this exact authorized redirect URI is added on the existing OAuth web client (no query string): https://go.ai-os.co.za/founders-dashboard
https://bridge-ai-os.tech/ is HTTP 302 to /landing.html on .tech. bridge-ai-os.org has no address (nameservers rosalie.ns.cloudflare.com and garret.ns.cloudflare.com). https://bridge-ai-os.xyz/ timed out with Cloudflare 522. spine.bridge-ai-os.com has no record in the zone this token can read, and the name does not resolve. Zone lookup for .tech, .org, and .xyz returned HTTP 200 with zero zones. Workers list returned HTTP 403, so /root/website/wrangler.toml stayed undeployed. .com stays primary.
Open the Cloudflare account for santino.ns.cloudflare.com and janet.ns.cloudflare.com.
Add the 301 from bridge-ai-os.tech and bridge-ai-os.xyz to https://bridge-ai-os.com/.
Open the rosalie/garret account, add an address for bridge-ai-os.org, and add the same 301.