Updated Fri 18 Sep 2026, 14:06 London, daily refresh. Partial sources: today's 13:06Z scheduled collection came back blind for a third straight day on Slack (the channel list and all 8 merchant and payout channels), the prod DB (all six tracked merchants, plus a JSON decode error on the raw read) and TG Core Engineering, the same missing-PATH signature named explicitly on the last two boards with a fix recipe, now ten occurrences since 2 Sep and still not applied. git and Linear both answered clean and carried real movement: Nur merged 12 PRs today (11 his, plus Tim's long-stale PR #283 branch) including production promotions of the embedded-box M2 work and yesterday's postmerge fixes, and Nur filed six new findings straight to Backlog, among them REV-266 (Pura Peptides dark 36 hours, a fatal error freezing orders, callbacks now returning HTTP 400) and REV-262 (a checkout phone field that still blocks payment on the Synergy account). Every task below sourced only from Slack, the DB or TG carries over unchanged from the 15 Sep 18:32Z read, now three collection cycles stale. No ticks or comments were left on the 17 Sep board.
Top now: Pura Peptides has been dark 36 hours with a fatal error freezing orders and callbacks now returning HTTP 400 · Seven Sigma's bank details and Cloudflare-blocked webhook are still unresolved and today is REV-250's payout deadline · confirm Synergy's checkout is actually fixed, REV-254 dropped off but newly filed REV-262 says a checkout phone field still blocks payment
Today's git carries two production promotions that read like the payoff of yesterday's ten-PR batch: promote/m2-full (#502) and promote/wave1-safe-fixes (#501), plus a scoped promotion of PR #477's config endpoint ("Promote #477, config endpoint only: expose embedding_enabled in integration config"). Read literally, "m2-full" is the exact milestone REV-234 asked Narboto to run with you Thursday. If it is what it says it is, M2 passed and the embedded box is now live in production the same day Apex is scheduled to switch.
REV-234 itself ("QA: embedded Visa box on WooCommerce, plan now, run M1 Wed + M2 Thu with Tim") still reads upd 2026-09-16 in today's Linear pull, unchanged for two straight days including the day the promotion it's meant to gate actually shipped. That is the same "ticket says nothing happened, code says otherwise" pattern already flagged on REV-127 and REV-146. Slack and the DB are both still down, so there is no session-level evidence either way that a real buyer has gone through the new box yet.
Get a direct answer from Narboto before letting today's switch proceed further: did M2 actually run, does "m2-full" mean what it sounds like, and is there a real pass/fail record anywhere that isn't just a branch name. If nobody can answer that in the next hour, treat the switch as unverified regardless of what's already in production.
REV-250 "Seven Sigma: get bank details before the 18 Sep payout" ([Todo] p1 @tim) is unchanged in today's Linear pull, and today is that deadline. REV-244 "Cloudflare blocks our webhook, callbacks never arrive" ([Todo] p2 @nur) shows upd 2026-09-18, so something moved on it today, but Slack and TG are both still down so what changed is unverified.
REV-256 (sent payouts stuck in processing without a bank reference) was also touched again today, still open. If Seven Sigma's first payout goes out today, it is walking into both an unresolved webhook block on their order state and a platform-wide payout-integrity question at the same time.
Next actionConfirm the bank details are actually in before end of day, and ask Nur directly whether REV-244 moved today because it's fixed or just because it was looked at. Don't let this be the first payout riding on an unresolved webhook block.
The domain fix landed in the blind window: the merchant row read https://biopepusa.com as of the 15 Sep read (it was www at the 2 Sep read). Since 13 Sep mrc_roNy1mlK9Ij5 showed four sessions and zero payment intents: cs_RVasVZH_AAxR1qMea1PK $109.00 and cs_EZO-PKMQnMyecR0VfwTx $3,277.87 (no buyer email), then cs_ZK_B_CCbydE0g6S43ljT and cs_xzPaO8-h-7F5c3TwHr1C, both $69.99 from info@biopepusa.com. Nobody got as far as submitting a card. REV-241 (PR #461, prohibited products allowed at checkout by default) shipped 15 Sep as a plausible fix if BAC Water was the wall; nobody has re-run Biopep's cart to check, and REV-231 no longer appears in any Linear pull since 16 Sep either way.
Three days running now with nothing fresh: Slack and the DB are down again today, so none of it has been re-checked against what actually happened since 13 Sep.
Next actionAsk Casey to try the $69.99 cart again today, now that REV-241 has had three days to reach production, and email him regardless: what he saw on the checkout screen if it still fails. Get Nur's BAC Water answer directly since REV-241 changing the default is not the same as confirming what Biopep actually hit.
As of the 15 Sep read, #rhp-rhpeptides ended on Jarrod's 1 Sep 05:57Z message: "that text is from the master document, not the one you signed... I will discuss with Aadil today and get back to you." Your 31 Aug 16:36Z answer to his Washington question rested on three things: Revion is the seller of record, "Revion is registered in Florida today", and sections 8.5 and 8.7. RHP: 0 sessions since 13 Sep, fee_rate 14. None of that has been re-checked in three days, Slack is down again today.
REV-196 ("Turn OFF Florida sales-tax collection until registered") is still [In Progress] p1 @nur in today's Linear pull, unchanged since the suppression code merged 15 Sep (PR #465). The refund and TaxJar-purge parts of REV-196 are still unshipped, and no commit has touched it today either.
Check whether a fresh Florida quote now comes back at $0 before replying to Jarrod. Still get the Florida registration fact and the executed RHP agreement from Aadil, since REV-196 turning tax off does not by itself answer whether Revion is registered.
REV-251 "Apex: cross-check the 25 approved September payments against Matt cancelled orders" ([Todo] p2 @tim) is unchanged in today's Linear pull. Matt is almost certainly Matthew Jensen, the Apex contact you and Aadil were meant to call. No detail on which orders Matt disputes is in any readable source today.
REV-256 (see Aadil's top item) was updated again today, still open. Cross-checking cancelled orders is moot if the payout itself has not actually landed cleanly; check REV-256's outcome first.
Next actionGet the list of cancelled order numbers from Matt on your call, and check none of the 25 approved payments were built from an order Woo shows cancelled. First confirm with Aadil/Nur that the transfer itself cleared, not just that it was approved.
app_uHyTgAc1QXxFQKBW (coreresearchpeptides.com) was under review from 1 Sep. His current status is not in any readable source today, the DB is down again. REV-214 (verify callback, activate, then send portal credentials) shows upd 2026-09-18 in today's pull, still [Todo] p1.
REV-258 "Sache's stores: Vyal Labs and Halo Labs USA are still inactive with zero sessions" ([Todo] p2 @tim) is unchanged since 16 Sep. New today: three merged PRs (#498, #499, #500) shipped REV-267, "allow approved merchants to set up portal before activation" straight to production. Neither Linear nor Slack states the connection directly, but that is exactly the kind of gap that would leave an approved-but-not-yet-activated merchant sitting idle with zero sessions. Worth checking Vyal and Halo Labs USA against it before assuming they are still stuck.
Run onboarding-check.sh against Vyal Labs, Halo Labs USA and Sean Finck's account once the DB is reachable, specifically to see whether today's REV-267 fix already moved any of them. If he is live, confirm banking_approved before his first balance matures.
As of the 15 Sep read: 11 Sep run, Halo $1.32, Zen $801.06; 14 Sep run, Halo $358.16 (Mercury ••••2806), Narboto inc $0.09, Zen $2,491.16; Andrew, 15 Sep 13:12Z: "others got paid". The 27 Aug $1,139.16 (9 orders) had not appeared in any run since, and no reference for it was visible. None of this has been re-checked in three days now, Slack is down again.
REV-256's "sent payouts stuck in processing, no bank reference" finding, still open and touched again today, is exactly the failure shape this task has been chasing for Halo specifically.
Next actionAsk Andrew for the bank references of the 27 Aug and 1 Sep Halo drafts and of the 15 Sep send, check each one is recorded in Revion, then close REV-163 with Aadil.
As of the 15 Sep read, #best-peptide-lab: your 31 Aug 09:06Z follow-up offered 20 minutes to run the first embedded order together, no reply, then Slackbot, 11 Sep 09:44Z, the team removed themselves. Merchant row: active, banking approved 2 Sep, contact dev@guardedpaypro.com, fee 12, 0 sessions and 0 orders since 13 Sep.
REV-247 (rotate the "GuardedPay" password leaked in Core Engineering) is still open, unchanged today. For the record, PR #484's branch name "nur/payment-links-guardedpay" (payment-links feature, guarded catalogue prices) is an unrelated naming coincidence, not this merchant's dev@guardedpaypro.com contact.
Next actionEmail dev@guardedpaypro.com, since Slack no longer reaches them: ask straight whether they are still integrating, and offer a slot to put the embedded box on bestpeptidelab.com with you watching, once today's Apex switch is out of the way.
#kiyora-peptide-llc, 13 Sep 15:30Z, Andrew: "We confirm receipt of Kiyora Peptide, LLC's notice of termination dated September 13, 2026... As Kiyora did not process any transactions through the Revion platform, there are no processed transactions, settlements, chargebacks, refunds, transaction-related losses, or termination reserve to reconcile." 15 Sep DB read: mrc_zinhzQp6eyBC status=active, 0 sessions. Why a working merchant left without trying a single sale is in no source, and the DB is down again today to check whether the row changed.
Close the account (keys off), send the effective date Andrew promised, and ask one question: what stopped Kiyora switching Revion on. The same reason may be sitting with Best Peptide and RHP.
4SMZBX4M… + run the REV-60 cleanup scriptWhether the ticket is resolved is still unverified, today's read has no billing-inquiry rows either. As of the 15 Sep read: the 14 Sep run listed Narboto inc at $0.09 to a test bank, Andrew refused to send it, Aadil asked Nur to remove all test accounts from payouts, and Nur agreed.
Next actionrevioncaps.com/admin/billing-inquiries, Resolve, note "QA daily test, no action". Locally: source ~/RevionCaps/creds.sh && python3 ~/RevionCaps/linear_cleanup_rev60.py (idempotent; it also comments on REV-170).
#halo-peptides, 24 Aug 14:36Z: "done and live. Every new order now gets a private order note 'Revion payment link: <url>' plus an order meta field _revion_checkout_url that Sufyan can read programmatically... Already active on your store (plugin 1.2.27)." REV-127 is still [In Progress] p2 @tim in today's Linear pull, untouched since 2 Sep.
New today: PR #503/#504 shipped "Payment links: stop advertising SMS in the portal," more movement in the same payment-links area while this specific ticket sits untouched.
Next actionClose REV-127 with the 24 Aug message as proof, or write on it what is left. A shipped ticket left In Progress makes the open list lie.
REV-252 "Backend reviewer: hire, or interim AI review on every PR" ([Todo] p3 @tim) is unchanged in today's Linear pull. Today's git alone carries 12 merged PRs (#283, #494 through #504) plus 17 direct commits, effectively one engineer on all of it, into production the same day as the Apex switch and Pura's dark-36h incident.
Pick a direction, hire or an AI-review gate on every PR, and file which one under REV-252.
Done since yesterday: nothing closes for certain today, Slack and the DB stayed down for a third straight day so none of yesterday's open items could be re-verified. One concrete win: PR #283, your long-stale agents-change-protocol branch, finally merged today. No marks were left on the 17 Sep board.
As of the 15 Sep read: "Synergy Research, LLC" (synergy-labs.uswholesalepeptides.com, mrc_LLEYN7Q4l9fC) applied 10 Sep, approved, live since 15 Sep; "Vyal Labs LLC" (vyallabs.com, mrc_PA2TX_ACHQq5) approved 12 Sep; "Halo Labs USA LLC" (halolabsusa.com, mrc_f4LFsn8VaAaJ, contact Alice Rewoldt) approved 14 Sep. Halo Labs USA is a different business from Halo Peptides, keep the two apart in payouts and in REV-231.
REV-254 ("Synergy Labs live: buyers see 'Card processing is temporarily unavailable'") no longer appears in today's Linear pull, and neither does REV-257 (the QA repro ticket). Whether that means it's fixed is unconfirmed: a new ticket, REV-262 "Checkout phone field says 'optional' but blocks payment (Synergy Labs, live)," is filed today straight to Backlog, still unfixed as far as any source shows, and names the same merchant. Treat this as the likely continuation of the same incident, not proof it's over. Separately, REV-258 (Vyal and Halo Labs USA still idle) is unchanged since 16 Sep, but today's REV-267 fix ("allow approved merchants to set up portal before activation") shipped to production and may be exactly what was blocking them.
Next actionPush Nur for a straight yes/no on Synergy today: is REV-262 fixed, and can a buyer actually pay right now. Separately, ask whether today's REV-267 fix moved Vyal or Halo Labs USA off zero sessions; if not, chase banking and set them live by hand.
As of the 15 Sep read, #ach-payouts-production: Andrew 16:19Z, "when do you show payouts starting for apex peptide supply they said they had transactions sept 4-7?"; 16:22Z, "peptide 911 wants to know there status as well". Nur, TG 17:48Z: "Two merchants transacted with matured, payable balances but no payout went out because their banking verification step had not been run. Both are now verified." Apex Peptide Supply $2,267.28 (19 orders settled 3-10 Sep); Peptide911 $262.79. None of this has been re-checked in three days, Slack is down again.
REV-256 "Close out sent payouts: bank reference and sent date, not stuck in processing" ([Todo] p1 @nur) shows upd 2026-09-18, touched again today, still open. Whether it now includes Apex and Peptide911's catch-up run specifically is not stated anywhere readable.
Ask Nur directly: does REV-256 include the Apex/Peptide911 catch-up run, and what changed on it today. Then confirm with Andrew that both ACH transfers have an actual bank reference recorded, not just a "sent" status, before calling Matthew Jensen and James Votraw.
Open since 28 Aug; Nur asked again on the morning of 29 Aug. Whether his payment went out is still unverified, TG is down today so the thread cannot be checked.
Today alone, from git: 12 more PRs merged (#283, #494 through #504) plus 17 direct commits. Headline items: REV-267 shipped end to end to production, the embedded-box M2 and wave-1 work promoted live, a canonical-domain link batch and magic-link fixes, and six new findings filed to Backlog including Pura's dark-36h incident. Now the second-busiest day in the read, right behind yesterday, all one engineer.
Next actionSend it, confirm in the thread.
The wall was measured on 2 Sep: $380 and $361 non-Visa declines in five days. As of the 15 Sep read, 10 production attempts across merchants, 5 authorized, and card declines returned "Your card was declined. Please use another Visa card or contact your card issuer."
REV-239, filed yesterday as "Apple Pay in the box," no longer appears today. REV-112 "Apple Pay on NMI, step 0: confirm with Ignacio the MID supports own-certificate Apple Pay" ([Backlog] p2 @aadil) is new to the board today; not confirmed the two are formally the same ticket, but the description reads like the same question narrowed to its first concrete step. No separate brand-enablement ticket for Mastercard/Amex/Discover appears in today's pull either.
Answer REV-112 with Ignacio directly: does the MID support own-certificate Apple Pay. Separately, ask what enables Mastercard, Amex and Discover, and by when, now that the embedded box is carrying real production traffic today.
As of the 15 Sep read: Jarrod's copy ends at 8.4 (31 Aug 23:48Z). Tim promised on 1 Sep to discuss it with you that day; the channel had been silent since. Tim's 31 Aug message told him "Revion is registered in Florida today" and tagged you to review Washington registration timing. None of that has been re-checked in three days, Slack is down again.
REV-196 (the Florida suppression code, merged 15 Sep) is unchanged in today's Linear pull, still [In Progress]. That is the tax-collection half of Tim's question answered from the code side; the registration fact and the executed agreement are still only yours to give him.
Send Tim the executed RHP agreement and one line on Florida, registered or not, plus your call on an addendum or accepting Jarrod's position.
As of the 15 Sep read: Kiyora terminated (Andrew acknowledged 13 Sep 15:30Z, "did not process any transactions"); Best Peptide's team removed themselves from #best-peptide-lab 11 Sep 09:44Z, 0 sessions since 13 Sep; Biopep had four checkouts since 13 Sep and none reached a card; RHP had 0 sessions since 13 Sep. None of it has been re-checked in three days, Slack is down again, so treat all four as still open until proven otherwise.
New today: REV-266 "Pura Peptides dark 36h: fatal error freezes orders, our callbacks now get HTTP 400" ([Backlog] p1 @nur). This is a different, sharper kind of problem than the others, an active fatal error rather than silence, and it is filed straight to Backlog rather than Todo, meaning nobody has picked it up yet.
Call Pura today, this is the most urgent of the merchant-relationship items on this board. By phone this week otherwise: Best Peptide, Biopep's Casey (with Tim), Jarrod (after the Florida answer), one call to Kiyora to ask why they left.
As of the 15 Sep read, VAPI_PRIVATE_KEY etc. were set on revioncaps-prod; calls were held off only by VAPI_OUTBOUND_ENABLED=false, and vapi-outbound.ts had no calling-window, DNC or consent gates. No VAPI ticket appears in today's Linear pull either. The buyer base behind it keeps growing with more merchants live.
Either unset the prod keys or commission the TCPA gates, and file whichever it is.
As of the 15 Sep read: Hudaifa rejoined #halo-peptides on 31 Aug, no messages from Halo since; Andrew confirmed the 14 Sep run went out ("others got paid"); the 27 Aug $1,139.16 had no visible bank reference. REV-163 is still [Todo] p2 @aadil in today's Linear pull, untouched since 2 Sep.
Once Andrew confirms the references (and once REV-256's stuck-in-processing question is answered generally), a short note or call to Hudaifa on what was paid and when; then close REV-163.
REV-164 sits below today's top-50 Linear window too (last seen updated 27 Aug), so its state is unverified rather than closed. TG is down today so whether the message was deleted cannot be checked.
REV-247 (rotate the separate "GuardedPay" leaked credential) is also still open, unchanged today. A new, unrelated REV-268 "Avoid duplicate candidate lookup and password verification on failed merchant login" ([Backlog] p3 @unassigned) is a login-hardening item, not a third leak, worth not conflating with these two.
Rotate it, delete the message, close the ticket.
Decided in TG on 31 Aug: DocuSeal replaces DocuSign seats, filed as REV-187 ([Backlog] p3 @unassigned), unchanged in today's Linear pull. REV-87 (move e-sign to DocuSign) is also still open, unchanged. REV-144 (banking verified as a gate to LIVE) shipped 15 Sep, closing the question by default before REV-187 or REV-87 ever got an answer.
Say whether DocuSign-by-default is fine to keep, or whether REV-187 still needs doing properly. Then chase Planet, Fit Aminos and Sports Tech yourself.
Variants live in the "Revion Home Variants" artifact (REV-101, [In Progress] @tim, unchanged today). No letter in any readable source.
Reply with a letter in Core Engineering, or say the redesign is parked so REV-174 and REV-101 can close.
Done since yesterday: nothing new confirms closed, Slack and the DB stayed down for a third straight day. REV-256 was touched again today but the direction is unverified. No marks were left on the 17 Sep board.
REV-266 "Pura Peptides dark 36h: fatal error freezes orders, our callbacks now get HTTP 400" ([Backlog] p1 @nur), filed today. Pura already has an open thread on this board (REV-189's 8.5% fee rate question, REV-246's NMI batch cutoff time), but this is a different order of problem: a fatal error and orders frozen for a day and a half, with callbacks failing at the HTTP layer. No detail on root cause is in any readable source today; Slack and the DB are both down, so there is no session-level evidence to work from beyond the ticket title.
This is a similar failure shape to REV-244 (Cloudflare blocking Seven Sigma's and Bioscience's webhooks), callbacks not arriving, but described here as the callbacks now actively returning HTTP 400 rather than being silently dropped, which points more toward a broken endpoint or contract change than a network block. Worth ruling in or out against REV-244's cause before assuming they're unrelated.
Next actionGet this out of Backlog and into Todo today. Find out what actually changed 36 hours ago, whether it's on our side or Pura's, and whether the frozen orders are recoverable once the callback path is fixed. This reads as the single most urgent item on the board right now.
REV-254 "Synergy Labs live: buyers see 'Card processing is temporarily unavailable'" and REV-257 (Narboto's repro ticket) both no longer appear in today's Linear pull. Whether that means the incident actually closed is not stated anywhere readable. New today: REV-262 "Checkout phone field says 'optional' but blocks payment (Synergy Labs, live)" ([Backlog] p1 @nur), filed today, names the same merchant and the same live symptom. Treat this as the likely continuation of yesterday's incident under a more specific description, not confirmation it's resolved, especially since it's filed to Backlog rather than Todo.
This also lands the same day as the embedded box's M2 work reaching production (see below); whether Synergy runs through that box or the older redirect flow is still not stated anywhere, worth ruling in or out given a shared root cause would change how much today's Apex switch can be trusted.
Next actionMove REV-262 to Todo and fix it today, or say plainly why it's still Backlog for a live merchant that can't take payment. Confirm with an actual test order whether Synergy buyers can pay right now, don't infer it from the ticket disappearing.
As of the 15 Sep read: your TG 17:48Z, matured balances, "no payout went out because their banking verification step had not been run"; REV-144 shipped 15 Sep to gate future Set-live on banking verification. That closed the cause for NEW merchants; it does not by itself prove every already-live merchant's balance is actually paid out.
REV-256 shows upd 2026-09-18, touched again today, still [Todo] p1. It directly touches Apex and Peptide911's catch-up run, Halo's 14 Sep $358.16, Zen's overlapping-window runs, and now Seven Sigma's first payout, due today.
Post one list in #ach-payouts-production: every payout marked sent in the last 30 days, with or without a bank reference. Anything without one is not actually confirmed paid regardless of status. Prioritise Apex, Peptide911 and Seven Sigma given today's deadlines.
REV-233 remains absent from today's Linear open-issues pull. Today's git adds two production promotions: promote/m2-full (#502) and promote/wave1-safe-fixes (#501), plus "Promote #477 (config endpoint only): expose embedding_enabled in integration config." Neither promotion merge carries new distinct file-level commits today, meaning the underlying work was already on sandbox from yesterday's ten-PR batch and is now just reaching production.
Also today: a canonical-domain link batch ("Use canonical domain and portal paths for all public links," "Set the customer portal CSP for the shared proxy template," "fix: link embedded checkout policies to revioncaps.net") and magic-link fixes ("preserve customer portal destination," "retain complete portal return URL before email sign-in," "preserve checkout amount contracts during embedded refresh"), all promoted sandbox-to-production today (#494-#497). None of this is independently QA-confirmed by anything in today's readable sources, and REV-234 still shows upd 2026-09-16.
Give Narboto and Tim a straight answer today: did M2 actually run, and does today's production promotion reflect a real pass, not just a branch name. Confirm whether REV-262 (Synergy's phone-field bug) shares any code path with this batch before the switch is trusted.
REV-231 ("Check: Halo still shows what they sell with product names hidden; confirm Biopep's BAC Water refusals") remains absent from today's Linear pull; it may be closed, or it may simply have aged out. Neither is confirmed. Biopep (mrc_roNy1mlK9Ij5) had four expired sessions and zero payment intents as of the 15 Sep read, none of it re-checked since, the DB is down again.
REV-232 "Test: product-name alias on every screen, restricted items still refused with it on" ([Todo] p1 @narbotokerimov) is unchanged in today's Linear pull, still open, still not reconciled with REV-241's "allow prohibited products by default" change from 15 Sep. New today, on the same data-quality theme: REV-263 "Guest orders not fixed: plugin still never writes the billing name (REV-230 closed early)" (see the fulfilment/data-integrity item below), a second case of a ticket closed before the underlying behaviour actually changed.
Say plainly whether REV-231 closed and what it concluded. Until REV-232 is reconciled, do not treat "restricted items are refused" as true for any merchant.
REV-244 "Seven Sigma and Bioscience: Cloudflare blocks our webhook, callbacks never arrive" ([Todo] p2 @nur) shows upd 2026-09-18, touched again today, still open. Neither merchant's order state can be trusted while their callbacks never land, the same mechanism REV-226 already found cancelling paid Apex orders.
Pura's new REV-266 (dark 36h, callbacks now HTTP 400) is a related but distinct failure shape, worth comparing notes on since both are callback-path breakages surfacing the same week.
Next actionFind what Cloudflare is blocking and get an allowlist or bypass in today, before Seven Sigma's payout goes out on unverified order state. Say what today's REV-244 update actually changed.
REV-247 "Delete the credentials and bank details posted in Core Engineering, rotate the GuardedPay password" ([Todo] p1 @nur) is unchanged in today's Linear pull. No detail on how long it was exposed or who posted it is in any readable source; TG is down today so the message itself cannot be checked.
Delete the message, rotate the password, and check whether anything was accessed with it while it was live.
REV-196 "Turn OFF Florida sales-tax collection until registered" ([In Progress] p1 @nur) is unchanged in today's Linear pull. PR #465 (merged 15 Sep) covers the "$0 FL quotes" half; the refund and TaxJar-purge halves are still not named in any commit today either.
Confirm a fresh Florida quote comes back $0. Then either refund what was already collected and purge the TaxJar test transactions, or get the registration fact from Aadil first if the suppression turns out to be wrong.
REV-214 ("verify callback, activate, then send portal credentials") shows upd 2026-09-18, still [Todo] p1. REV-267, shipped today via three merged PRs (#498 sandbox-refresh-contract, #499 merchant-login, #500 production) and two direct fix commits, changes exactly this: letting approved merchants set up their portal before activation completes. Neither Linear nor Slack states the two tickets are linked, but the description overlap is strong.
Confirm REV-267 actually answers REV-214, and close REV-214 if so. Add the standing Slack alert for any live merchant without banking_approved, since REV-144 gates new merchants but does not retroactively flag old ones.
REV-226 ("Webhook timeouts cancel PAID Woo orders") had two merges through 15 Sep: #455 (ack-then-process) and #457 (bound delivery lifetime within outbox lease). It does not appear in today's Linear pull either way. Today's git is mostly domain-and-portal-link consistency work (#494-#497) plus REV-267's activation-sequence fix, adjacent territory but not a direct continuation of REV-226. The reconcile sweep for orders already cancelled by the original bug is still not named in any commit.
Next actionConfirm #455 and #457 are promoted to production, then run the one-off reconcile of Apex orders Revion shows AUTHORIZED and Woo shows cancelled. Give Aadil the result before his call to Apex.
REV-265 "No order has ever had a tracking number: 240 orders ($24,000) past ship date with no fulfilment evidence" ([Backlog] p2 @nur, upd 17 Sep) is the headline: if a buyer disputes non-delivery on any of these, there is nothing on record to show otherwise. REV-263 "Guest orders not fixed: plugin still never writes the billing name (REV-230 closed early)" ([Backlog] p1 @nur) says a previously-closed ticket didn't actually fix the underlying behaviour, the same "closed but not really done" pattern flagged elsewhere on this board. REV-268 "Avoid duplicate candidate lookup and password verification on failed merchant login" ([Backlog] p3 @unassigned) is a smaller efficiency/hardening item.
All four sit in Backlog, not Todo, meaning none has been actively picked up yet despite REV-265's dollar exposure.
Next actionTriage REV-265 into Todo first given the dollar figure and dispute risk; pull a sample of the 240 orders and check whether tracking data exists anywhere outside Revion (carrier, Woo) before assuming it's genuinely missing. REV-263 and REV-268 can follow.
As of the 15 Sep read: 10 attempts, 5 authorized, 3 card_declined, 1 insufficient funds, 1 in review; Biopep 4 sessions and 0 intents since 13 Sep. Still open in today's Linear pull: REV-165 funnel/decline report (p2), REV-145 plugins page (p2), REV-173 telemetry null (p4), REV-104 operator payment links (p2).
New today: REV-261 "REV-142 shipped a dead detector: gateway failure streak join matches 0 rows on prod" ([Backlog] p1 @nur) confirms what was previously just an open ticket, the silent-merchant alert this board has been asking for doesn't actually work. That means Pura's 36-hour dark stretch (REV-266) and Synergy's failure both had to be found by a human noticing, not by any automated detector, and would again next time.
Fix REV-142's join today, this is the mechanism that would have caught Pura and Synergy hours earlier instead of after the fact. REV-165's daily funnel report is the next layer once the detector itself actually runs.
REV-189 remains missing from the open list, and no commit today names fee rates. At the last code read: zod locks feeRate to 12|14 in three places, sandbox-provisioning-client.ts:66 refuses other values, and settlement.ts guards fee_rate IN (12, 14) twice. REV-246 (Pura's NMI batch cutoff time, blocked item from REV-236) is unchanged in today's Linear pull, still open.
While in Pura's account for REV-266, check the merchant row: if it went live at 12 or 14 against an 8.5 contract, tell Aadil; if 8.5 is stored, prove it passes both settlement guards.
emails.ts:368 carried the "processing is disabled" line at the 2 Sep read. REV-169 "Fix the merchant credentials email copy" remains [Duplicate], unchanged today. No commit today touches emails.ts directly, and no readable source names which ticket absorbed it, but REV-214 (onboarding activation sequence, touched again today) remains the most likely candidate given it covers the same send path.
Find the canonical ticket REV-169 now points to and confirm the email copy itself actually changed, a status flip alone is not proof the lie is fixed.
As of the 15 Sep read: opt-in NMI reversal reconciliation "and atomic accounting" (#443), linked reversals held before reporting to the ACH generation fence (#445), external refund parent and original payment verified (#448), an exception review queue with opt-in Slack alerts (#452). At the last code read settlement.ts deducted refunded_cents but never recalculated fee_cents down, and MFSA 16.4 argues it should.
One line: does #443's accounting reduce the fee share on a partial refund? If not, add it before reconciliation is switched on for real merchants.
As of the 15 Sep read, Biopep now reads https://biopepusa.com. Application websites: Research Chemical LLC https://www.researchchemical.com; Veri 7 labs https://veri7labs.com followed by a zero-width U+2060 character. Whether either row carries the application value is unverified, the DB is down again today.
Today's "Use canonical domain and portal paths for all public links" batch (#494/#495) fixes how links are constructed, not what's stored on individual merchant rows, so it likely doesn't touch this specific issue.
Next actionRead both merchant rows once the DB is back and fix by single-field update if needed; then normalise domains at registration so the next merchant cannot arrive broken.
slack_provisioning_status/_error exist on the merchant row but nothing shows them. Departures are just as invisible: Halo's consultancy left #halo-peptides on 23 Aug, Best Peptide's team left #best-peptide-lab on 11 Sep.
Show invite state and external-member count per merchant in admin, and post to Slack when a merchant's last external member leaves.
Asked in Core Engineering 31 Aug 13:48Z: "Would be sick if we had the customers number ready for anyone/me/andrew/pat to call them right away too." The buyer's phone is collected at checkout; the billing-inquiry queue and its alert email do not surface it. No such ticket is in today's Linear pull either.
Next actionShow the buyer's phone on the billing-inquiry admin view and in the alert email; file it in Linear with the LLM pre-check block.
support_admin_alert emails to support@send.revioncaps.com showed [failed] repeatedly from about 28 Aug. REV-146 was last confirmed [Todo] p2 on the 16 Sep read, then disappeared from the 17 Sep pull after a batch of REV-146 follow-up commits and a plugin repackage, and remains absent today too, with no new commits referencing it.
Confirm REV-146's actual Linear status, then check a real support_admin_alert delivers before calling the sending-domain question closed.
REV-174 does not appear in today's Linear pull (was [Todo] p4 @nur as of 16 Sep). REV-101 (the variants, Tim) is unchanged, still [In Progress]. No letter in any readable source.
Nothing before Aadil's letter; if p4 means parked, say so on REV-174 so REV-101 can close too.
Done since yesterday: another huge day in git: 12 PRs merged (#283, Tim's, plus #494 through #504) and 17 direct commits, all Nur's authorship except #283. Headline: REV-267 (approved merchants can set up their portal before activation) shipped end to end to production; the embedded-box M2 work and wave-1 postmerge fixes were promoted to production the same day as the Apex switch; a canonical-domain and portal-link consistency batch and magic-link portal-return-URL fixes also reached production; a small payment-links copy fix (stop advertising SMS) shipped too. Separately, Nur filed six new findings straight to Backlog: REV-266 (Pura dark 36h), REV-262 (Synergy phone-field blocks payment), REV-265 (240 orders / $24,000 never tracked), REV-261 (REV-142's alert confirmed dead), REV-263 (guest billing name still unfixed) and REV-268 (login hardening). None of today's shipped work is independently QA-confirmed by anything in today's readable sources.
REV-234 "QA: embedded Visa box on WooCommerce (REV-233), plan now, run M1 Wed + M2 Thu with Tim" ([Todo] p1) is unchanged in today's Linear pull, still upd 2026-09-16. Today's git shows promote/m2-full (#502) and promote/wave1-safe-fixes (#501) reaching production, exactly the milestone name this ticket describes.
REV-249's 10 manual QA cases were written against "plugin 1.2.34," but recent git includes a repackaged 1.3.1 plugin and a note that "backend release metadata follows plugin 1.3.3." If the live plugin has moved past 1.2.34, REV-249's cases may now be testing a build that no longer exists.
Next actionSay plainly today: did M2 run, does today's promotion reflect it, and what plugin version is actually live. This is the one answer the whole board is waiting on before trusting today's Apex switch.
REV-257 "QA: reproduce the Synergy checkout failure and capture the exact error we return" ([Todo] p1 @narbotokerimov) no longer appears in today's Linear pull, consistent with the repro having been delivered, unconfirmed. REV-262 "Checkout phone field says 'optional' but blocks payment (Synergy Labs, live)" appeared as new today, filed to Backlog rather than Todo.
Confirm your repro is what became REV-262, and run one more real checkout on Synergy's store today to check whether a buyer can actually complete a purchase right now, don't assume it from the ticket's disappearance.
As of the 15 Sep read: Tim estimated about 9 of 20 real buyers reached the page and never submitted a card, and replay review of those sessions was the next step; no result was visible in any source. Targets: Biopep cs_EZO-PKMQnMyecR0VfwTx $3,277.87, cs_RVasVZH_AAxR1qMea1PK $109.00, cs_ZK_B_CCbydE0g6S43ljT and cs_xzPaO8-h-7F5c3TwHr1C (both $69.99). None of it has been re-checked in three days, the DB is down again.
Watch the four Biopep replays once today's REV-234 answer is out. One line each on Biopep to Nur for REV-231 and to Tim.
REV-232 "Test: product-name alias on every screen, restricted items still refused with it on" ([Todo] p1) is unchanged in today's Linear pull. Halo runs with names hidden and was converting as of the 15 Sep read. REV-231, Nur's paired ticket on the same question, remains absent from today's Linear pull too.
Before testing anything: ask Nur whether REV-241 was meant to replace this ticket's assumption, and what happened to REV-231. If refusal is still the rule for some merchants, get the per-merchant PROHIBITED_PRODUCTS_MODE values first.
REV-235 [Todo] p1 @narbotokerimov is unchanged in today's Linear pull. REV-104 (operators create payment links) remains open. Yesterday's PR #484 reworked merchant payment links (guarded catalogue prices, durable email, cooldown mailbox); today's #503/#504 removed an SMS-advertising line from the same portal surface. None of it has been tested end to end by anyone yet as far as any readable source shows.
Run it on your own test merchant, not Halo: Send Link, pay with a Visa, check the dashboard shows it, mark it fulfilled, refund. Check the SMS-copy removal actually rendered correctly in the portal.
As of the 15 Sep read: 14 Sep payout run, Narboto inc $0.09 to a test bank account, Andrew refused to send it, Aadil asked for test accounts to be removed from payouts, Nur promised the next run leaves them out. Halo orders RC-2026-1000228, -232, -233, -235, -236 and -242 (all $0.50) were unrefunded at the 2 Sep read; whether a refund landed since is unverified, the DB is down again.
Next actionRefund the six from admin, confirm with Nur that test merchants are flagged out of payout runs, and move $-tests to your own store.
Unchanged in today's Linear pull: REV-93 scanned PDFs ([Todo] p2), REV-92 duplicate applications ([In Review]), REV-90 mobile wizard defects ([In Review]), REV-91 guest upload-session defects ([Todo]). REV-240 (automate deploy regression checks inside the Checkout E2E gate) is also unchanged, still open.
Finish the REV-90 and REV-92 reviews this week; for REV-93, reproduce with a phone-scanned PDF and post the CDR rejection code for REV-186.
REV-216 ([Todo] p2) is unchanged since its title updated 17 Sep. Test traffic keeps landing in production money: the $0.09 Narboto inc payout, the six $0.50 Halo orders, and a QA case set written against a plugin version that has since moved.
One Woo store on your own account, so REV-234, REV-232 and REV-235 run there instead of on a merchant, and so plugin-version QA cases stay pinned to what you control.
Open: REV-215 (11 Sep, p1), REV-209 (7 Sep), REV-207 (6 Sep), REV-206 (5 Sep), REV-202 (3 Sep), REV-181 (30 Aug), REV-180 (29 Aug), REV-260 ("QA daily - 2026-09-17", [Backlog] p0, still open). REV-98 (validate merchant dashboard release 5565719) has been [In Review] since 2 Sep. No "QA daily - 2026-09-18" ticket appears in today's pull; a reasonable read is that REV-257's live repro work took priority today, but that's not stated anywhere, confirm it wasn't simply skipped.
Close or mark-skipped every daily older than REV-260, one line each, and either file today's daily retroactively or note explicitly why it didn't happen.
Done since yesterday: nothing confirms closed today. REV-257 (Synergy repro) dropped off Linear, plausibly finished and handed off as REV-262, unconfirmed. No 2026-09-18 QA daily ticket was filed, plausibly because today went to the live Synergy repro instead. No marks were left on the 17 Sep board.
Today's 13:06Z launchd collection came back blind again: Slack (channel list and all 8 channels), the prod DB (all six tracked merchants, plus the same JSON decode error on the raw read) and TG Core Engineering all read SECTION UNAVAILABLE, and nobody re-collected by hand, so this board carries the 15 Sep 18:32Z read forward for a third straight day wherever those three sources are the only evidence. This is the same PATH gap flagged on 2, 7, 8, 9, 10, 12, 14, 16 and 17 Sep, nine prior occurrences, with the fix named explicitly on both of the last two boards: export PATH at the top of collect.sh and generate.sh. It was not applied before today's run either.
git and Linear, which do not depend on that PATH, answered clean again today and carried the most consequential signal of the week regardless: REV-266 (Pura dark 36h), REV-262 (Synergy's likely root cause), and twelve merged PRs. That this board can still function on git and Linear alone is not a reason to keep leaving the fix unapplied, it means the other three sources are pure loss every single day they stay broken.
Next actionNaming this in the board a fourth time will not fix it, that loop is demonstrably not working after nine failures. Apply the one-line PATH export directly today, or flag to Tim directly that it needs a human to run it, rather than writing it into another board.
Sandbox-to-production merges through 17 Sep: #373 through #484 (tracked across prior boards). Today's git adds 12 more merged PRs: #283 (Tim's agents-change-protocol), #494/#495 (canonical-public-links), #496/#497 (magic-link-destination), #498/#499/#500 (REV-267), #501 (promote/wave1-safe-fixes), #502 (promote/m2-full), #503/#504 (paylinks-hide-sms). Whether any of them, especially the two labelled for today's switch, are actually running on revioncaps-prod is unverified; flyctl was unreachable today, the same PATH gap as the Slack/DB/TG collector.
Next actionOnce the PATH fix lands, run flyctl releases per app plus the release tag for all twelve of today's merges, prioritising promote/m2-full and promote/wave1-safe-fixes given Apex is switching today. Never place a payment on sandbox.revioncaps.com: prod keys.
As of the 15 Sep read, live merchants included Apex Peptide Supply mrc_Jj7KJ7lPbJSh, Bioscience Peptides mrc_gUkKa0d4TClA, Veri 7 labs mrc_7RFYJXz5hHPT, Epic Wholesalers mrc_i1ZcMuL8KlKJ, Research Chemical mrc_Vhs6nzY0_j-c, Peptide911 mrc_PCV1-S_xcogf, Viltrumite Lab mrc_4oOU2meLCons; none of the seven is in the collector's channel list. Only six merchants are in the DB watch list at all: halo, rhp, kiyora, zen, bpl, biopep.
New today: Pura Peptides (REV-266, dark 36h with a fatal error) is not in that six-merchant list either, despite having its own Linear thread since at least REV-189. A merchant already having a fatal-error incident while the collector isn't even configured to watch its DB state is the clearest case yet for fixing this.
Next actionAdd Pura, Seven Sigma and Synergy to MERCHANTS and their channels to CHANNELS in collect.sh today, this one has an active incident behind it. Then derive both lists from the DB so the next go-live is tracked automatically, once the PATH fix restores DB access at all.
REV-245's original "watch Synergy's first order" framing is long overtaken. The two live threads today are: the embedded box's actual production traffic now that promote/m2-full has shipped, and Pura Peptides' recovery once REV-266 is fixed. Biopep's next attempt is also still open, none of four sessions has reached a card as of the 15 Sep read. watch-merchant.sh could not be tested today, node and flyctl were both off PATH again.
Stay out of Nur's and Narboto's way on REV-266/REV-262 today. Once the PATH fix lands, watch the embedded box's next live order, confirm charge, receipt and Woo order state, and post the result on REV-234.
File one labelled Charge inquiry via the sandbox public support endpoint and confirm the alert email carries both admin links. (Claude's live POST was classifier-blocked, so it needs a human-run curl or Tim's go.) It pairs with Nur's failing support_admin_alert item, likely closed by REV-146, same send path either way.
Slack, the DB and TG all read SECTION UNAVAILABLE today, so there is no fresh merchant-channel signal to sweep; every item on this board sourced from those three still carries over from the 15 Sep 18:32Z read. What did move came from git and Linear: 12 PRs shipped including two switch-day production promotions, and six new findings filed including REV-266 (Pura dark 36h) and REV-262 (Synergy's likely root cause). Drafts go to the owner on this board; nothing is sent from here.
Done since yesterday: nothing, today's blind collection was not re-run by hand for a third straight day. This board's Slack, DB and TG dependent tasks all still carry forward unchanged from the 15 Sep read instead.