This runbook describes operational recovery expectations for the public protocol/interface repository. It avoids private deployment details while documenting how Kairo surfaces should behave when dependencies fail.
- Confirm the authenticated wallet owns the run or authorization.
- Check whether the state store has the run context and authorization record.
- If state is missing, return a non-success response and avoid fabricating authorization state.
- If settlement proof is delayed, keep the record in a pending/proof-needed status and retry adapter verification.
- Record the final receipt projection only after durable state is present.
- Validate the viewer role for the private thread.
- Require configured private A2A encryption before accepting new encrypted envelopes.
- Store ciphertext hash and plaintext hash separately from private content handling.
- If delivery fails, keep the thread state intact and retry envelope persistence before notifying participants.
- Never expose private-room plaintext in public receipt responses.
- Sign webhook payloads with the configured webhook secret.
- Treat HTTP delivery failures as retryable adapter events.
- Redact wallet/session-sensitive values from logs.
- Keep the state store as the source of truth; webhook delivery is an output channel.
- Resolve receipt state from durable storage.
- Return redacted receipt projections for public verification.
- Require participant/evaluator authorization for private receipt views.
- If state is missing, return not found rather than a success-shaped fallback.
- Rotate
KAIRO_PRIVATE_A2A_ENCRYPTION_KEYwith an envelope-version migration plan. - Keep old material available only long enough to decrypt and re-envelope active private threads.
- Record envelope version and hash metadata so receipts remain verifiable after rotation.