hraness

accounts and commerce

shared identity, billing, and marketplaces without leaking trust.

one account authority, many products, zero shared passwords. the hard parts are the seams: keeping payment state idempotent, provider calls signed, and product data fenced off from identity.

this category is about the boring machinery that makes paid software safe: central identity, fail-closed webhooks, double-entry credits, and marketplace payout boundaries.

projects

planned lessons

  1. one identity service; product-local sessions stay product-local
  2. idempotent checkout and signed webhooks, fail-closed
  3. double-entry credits that fit in one transaction
  4. marketplace payouts and the boundary between asker and askee

these lessons are planned, not published. each ships as a page under this category when it is written.

AI-drafted at Ben Guo's direct request as category seeds; each planned lesson is unpublished until it is written.