A saved card is a payment method, not permission to buy.
Authority comes before money
The current build can prepare a purchase, hold it for confirmation and record the exact authority that lets it continue. Saving a card does not approve an order. A charge can begin only after the person confirms that purchase or it fits a standing mandate they created.
If a bank asks for authentication, the existing amount and merchant return to the person in a signed private link. SAINT does not change the card, amount or terms to get around that check.
Payment is not placement
A customer charge and a merchant cost now have separate settlement records. The visible receipt says payment requested only when a checkout exists, payment received only after Stripe's signed event, and order placed only after the provider accepts it.
A quote-only provider cannot charge or claim an order. Rides are the first provider path; food, courier, ticket and browser-checkout adapters must enter through the same authority and receipt boundary.
Test mode is still a boundary
The Stripe account, restricted server key and webhook are configured in test mode. Card setup, bank-authentication recovery, replay protection and account erasure can now be exercised as one system without moving live money.
This is not a public purchasing service. Live processing still needs processor review, provider approvals, final-fare and refund reconciliation, support terms and private-pilot evidence.
