Server-prices a prepaid-capacity request and records a short-lived,
leader-authorized purchase ticket the Stripe checkout edge fn acts on
(mirrors procurement: Java authorizes + records intent, the edge fn owns
Stripe, the pool lands via an RPC — Java never touches the Stripe SDK).
- V40: payg_bundle_quote ticket table + payg_credit_bundle(...) RPC that
opens one pool, applies the 12-month term, idempotent on stripe_ref.
- PrepaidPurchaseService prices units x rate x 10/12 (12-for-10), null-safe
when the rate has not synced; PaygBundleController POST /payg/bundle/quote
is leader-only (401 unauth / 403 member), team from the principal.
- Stripe stays the source of truth for purchased quantity + amount; the
edge fns + Supabase twin are specced for the SaaS repo.