isProvisioned
True only when a real Apple merchant identifier is in place.
Two conditions, not one. The sentinel check catches "nobody ran provision.sh"; the merchant. prefix catches the worse case — somebody swapped in a wrong value, e.g. the app bundle id. PassKit's answer to a malformed merchant id is a sheet that presents and then fails to authorize, which is the failure mode this whole contract exists to prevent.