Trust the notification only after every gate passes.
Play an SNS HTTP notification through parsing, exact TopicArn policy, certificate retrieval and chain validation, SignatureVersion 1/2 verification, and the post-verification handler boundary.
Choose a signed SNS story
Post-verification branch × 8
Security sequence
Step 0 / 7
Verification progress1 · Parse the envelope
Scroll horizontally to inspect the full security sequence →
SNS HTTP endpointuntrusted raw JSONSnsHttpMessageParsershape and URL checksTopicArn policyexact allowlistSnsMessageManagercertificate and signatureApplication boundaryverified handler or confirmation
raw SNS HTTP JSON + optional x-amz-sns-message-type
What happens
Guardrail
What follows
Visible signal
Trust boundary
No certificate or handler access before trust
│ fail closed │
Policy-owned
This offline explorer models the ordering and failure boundaries. The AWS SDK owns the concrete certificate cache and cryptographic implementation; the application owns its exact allowlist, runtime dependency, authorization, idempotency, and confirmation policy.
Use the step buttons or Left/Right/Home/End. Play advances this offline explanation only.