Recipe details are unavailable in this marketplace snapshot.
Paid Document Fulfillment
Transactional workflow pack for turning one single-item intake into one paid, reviewed, and delivered PDF. Core Seller may hold a separate outcome-offer row established through granted `core.seller.*` operations, but this pack, publisher, and version are distribution provenance only and never Seller identity or authority; the workflow creates no customer token, entitlement, or usage row. The saved exact-form origin defaults Seller registration off. Only an explicitly enabled run may create one exact core Seller draft and one-way attach an unlinked creator-owned row to the exact saved recipe before order/provider writes; it cannot activate, redirect, edit the offer definition, or put payment state in Seller. The core.seller.order row is the single durable fulfilment lifecycle record, surfaced owner-side in Settings -> Seller -> Orders; no member maintains task projections or shared-state rows. The exact-form origin crash-safely creates or recovers one Stripe Checkout Session and sends one checkout-link email behind a durable ambiguity fence. Checkout-link and delivery subject/body copy are bounded owner-authored recipe variables rendered only through closed placeholders; AI never writes customer communications. New sends pin the exact rendered subject with the core-derived opaque provider identity before dispatch, while legacy installed recipes and already-fenced rows retain their fixed-subject fallback. The attended mail reconciler may clear only one exact Sent identity, recipient, pinned-or-legacy subject, and timestamp match; legacy identity-free fences and all non-matches remain no-resend owner work. An owner-attended payment sweep lists orders awaiting payment, fresh-reads each order's own attached Session, and advances only exact complete-and-paid source truth through core.seller.order.confirm-payment, whose server fences re-verify the correlation and exact amount per order; the sweep is manual, so installation performs no provider read, and it never initiates money movement or touches Seller access. One separate manual reconciler closes an order as refunded only from an exact owner-selected Refund locator plus fresh Refund and PaymentIntent proof of a succeeded FULL refund of exactly that order's recorded payment, through core.seller.order.confirm-refund - the only way an order reaches refunded. A second attended inspector accepts one exact Dispute locator, fresh-reads the Dispute and the order's recorded PaymentIntent, and renders only bounded scalar source truth against the order's own amount; it never searches, aggregates, creates dispute state, calls a write/action operation, notifies, changes workflow state, references or renders evidence fields, or exposes a dispute action. V4 payment alone authorizes neither generation nor delivery before exact owner review and D-199 promotion. Static generation remains the default. Optional AI generation uses a source-checked attended-owner capability to re-read the row, canonical D-199 response, and template before server-deriving the selected mode. It may also source-check and pin one owner-selected local PDF or DOCX under 10 MiB. Docling receives only the closed core-pinned ref/hash carrier and converts its verified bytes into run-scoped Markdown; one hard-bounded nonempty template summary and, when a reference is selected, one hard-bounded nonempty reference summary join the existing bounded response projection under effective content declarations, while raw reference bytes, converted Markdown, and model key-point structures never enter durable workflow state or the strict renderer. Only one bounded escaped ai.draft scalar enters deterministic rendering. Authenticated exact-file cards route server-derived response/hash pins into source-checked owner approve-and-send, regenerate, reject, cancel, and mail-recovery actions. Approve-and-send re-reads the immutable D-199 recipient, uncached Stripe source truth, and exact durable PDF, then pins the artifact, rendered subject, sender, and opaque provider reconciliation identity before one attachment-bearing mail attempt. Every live mail adapter carries that identity. Delivery reconciliation retains its stronger exact attachment-byte match. Concrete duplicate-header, multiple-message, or source-mismatch evidence moves sending to durable ambiguous owner work without authorizing resend; repeated ambiguity does not churn state, and later exact proof may complete the same fence. Not-found or unavailable evidence preserves the current sending or ambiguous state, while stale or conflicting evidence fails closed. The attended delivery reconciler settles the checkout-link and delivery mail claims against the Sent collection through the same general fence; a claim that was never written is reported per leg, never resent. Regeneration retains the reviewed PDF before releasing its current pin and rendering fresh bytes. Cancellation does not refund payment. Automatic mail reconciliation, refund initiation, dispute lifecycle/action automation, and manual resend or source override remain disabled; partial or multiple dispute inspection is observational only.
What this pack installs
This pack installs the complete recipe workflow together. 1 supporting recipe runs as background automation.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Show all 11 recipes
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Recipe details are unavailable in this marketplace snapshot.
Builds on
- seller-stripe v2+
- email-outbox-pack v3+
- pandoc-pack v2+
- docling v2+
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.