The form never fakes a COPPA stamp
Consent only runs after a valid sha256 digest. It does not mint guardianConsentAt otherwise.
Kumir never invents a successful coppa stamp. POST /api/guardian/consent and POST /api/v1/guardian/consent only set User.guardianConsentAt after a valid sha256 digest.
A failed or expired code does not mint guardianConsentAt. Admin still reviews the intro before any storefront goes live.