This is a configuration screen for test purposes. The customer won't see this.
⏳
Connecting to Argufy…
Card identification to send:
Pattern A — Bank JWT
The bank signs a short-lived JWT (ES256, JWKS-verified) containing a one-time nonce. Argufy validates the signature using the bank's published public key.
Pattern C — SAML Assertion
The bank's IdP posts a SAML 2.0 assertion to Argufy's ACS endpoint. The assertion ID is checked against a Firestore nonce store to prevent replay.