API tokens and credentials must live in Secrets Manager per
secrets-and-config.md, but the four original payment Lambdas still
read 10 SecureString SSM params. Move them to three grouped secrets
(slack-bot-token plaintext, boa-check-mgmt and boa-reporting as JSON),
matching the pattern the expense Lambdas already use. IAM is scoped to
secretsmanager:GetSecretValue per secret; the VPC Lambdas reach the
public endpoint over the existing NAT path. Test/reissue scripts and
the client-ssm dependency are updated/removed accordingly.
Refs: #3
Use correct sandbox base URL (api-sb.bofa.com), proper OAuth
client-credentials flow with applicationID, and routing number
for transaction inquiries. Both APIs now return 200 in sandbox.
- Add standalone test script to validate sandbox API connectivity
for check management and account info endpoints
- Update seed-bank-status to persist amount, issueDate, and method fields
- Add data/ to gitignore