The code boxes are 56px tall at 20px / 56px / 600, uppercase and centred, 4px apart — react-otp-input's containerStyle, which is why the gap is 4 and not the widget's usual 8. That type is its own scale: there is no 20px in the type tokens, and the line-height doubles as the box height. Hover is --blue-3 and focus is --input-focus-color, same as any Input, so the boxes still read as fields; ::selection is transparent so retyping a digit does not flash blue. The stylesheet exists three times, byte for byte — Verification/index.module.pcss, Verification/Email/index.module.pcss and Verification/Phone/index.module.pcss — but the root copy is never imported: Verification/index.tsx only picks Phone or Email by retailingPrimaryAuthType === 'sms'. Two live copies and one dead one. The send button pulses while the code has not been sent and the countdown is at zero, which is the only decorative animation in the widget.
Documents is a Body holding Applications, then one UploadDocument per configured document, then References — so the credit applications and the references are not their own screens, they are sections of this one. Two source comments explain the conditionals: a dead upload link is terminal and shows only its error title, "instead of upload slots the backend would reject"; and on a live upload link the Applications and References sections are dropped to "keep the panel to its one job", because those entry points do not carry the code and would route elsewhere. An upload slot is a SelectorButton — incomplete (dashed) until a file lands, active on a valid drag, error on an invalid one — so upload state reuses the selector's states rather than inventing any. Adornments track it too: file → file-check on the left, and a plus on the right that disappears once a single-file slot is filled.
FileLabel is 5px radius, a --gray-4 border, 2px 4px 2px 8px padding (tighter on the right, where the trash button sits), 30px min-height, white on hover. CreditApp/Applications declares that recipe again, identically, and its source comment says why: "Visual recipe copied from UploadDocument/FileLabel so the co-signer action chips match the document file labels rendered in the same view." A deliberate duplicate, not drift — and note neither is the Chip component, which is 8px radius with 8px 12px padding. Each label is a Popover trigger that opens a file preview; an unverified account gets "To view this file, please verify your account." and no trash button, and a non-image file falls back to a 3x file icon with "No preview available". Deleting swaps the name for "Deleting {name}".
References renders a ReferenceButton per submitted reference and then requireReferenceCount − submitted.length identical empty SelectorButton slots, each labelled "Reference / Personal Reference" — so the customer always sees how many are still needed, and the number comes from dealershipConfig rather than the UI. A submitted reference's end adornment is a red-1 trash, replaced by a Spinner while deleting, and omitted entirely for an unverified account. Profile is the plainest screen in the widget: an h5 "Basic Information", the shared CustomerInfoForm, and a large Save. Which fields are required is derived, not configured per screen: requirePhone is true when retailingPrimaryAuthType === 'sms' or the global form requires it, and requireEmail is true when it is anything else — so the field the customer signs in with is always mandatory.