Run signature checks and validate delivery proof hash using the actual response artifact.
Upload the response artifact (or paste response text), compute SHA-256, and compare with receipt delivery commitment.