Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
976 commits
Select commit Hold shift + click to select a range
8b39517
patch ts tag script (#2675)
phdargen Jun 19, 2026
be91f31
chore(stellar): upgrade stellar sdk to v16 (#2662)
skyc1e Jun 22, 2026
b1c4734
add authoring-specs skill (#2692)
phdargen Jun 24, 2026
4cba262
feat: improve & document wallet compatibility (#2658)
CarsonRoscoe Jun 25, 2026
266b19d
Make the facilitator's receiverAuthorizer optional in batch-settlemen…
phdargen Jun 26, 2026
f4b33a2
Update docs/schemes/batch-settlement.mdx (#2705)
mintlify[bot] Jun 26, 2026
20cf64a
feat(concordium): Exact mechanism implementation (replacement) (#2390)
pavelhbl Jun 26, 2026
abdb550
Add Concordium (ccd) network to SDK features and exact scheme docs (#…
mintlify[bot] Jun 26, 2026
8b8c05a
Optional facilitator receiver authorizer: py/go (#2706)
phdargen Jun 26, 2026
0d00282
Batch settlement: facilitator setup docs + Go example link (#2713)
mintlify[bot] Jun 26, 2026
0a4a412
ccd fast-follow (#2712)
phdargen Jun 26, 2026
885e674
add e2e lockfile check (#2708)
phdargen Jun 26, 2026
bd6298d
chore: version typescript packages (#2714)
phdargen Jun 26, 2026
c4a9440
chore: version python package (#2715)
phdargen Jun 26, 2026
2b4f50e
chore(go): release (#2716)
phdargen Jun 26, 2026
1e7db46
docs(contracts): record batch-settlement deployments on Optimism, Ava…
feyyazcigim Jun 29, 2026
2a5d98c
fix next e2e (#2735)
phdargen Jun 29, 2026
3118f01
Add HPP facilitator to the facilitators directory (#2743)
nolnol3 Jun 30, 2026
0486033
fix(evm): emit spec-compliant authorization_value_mismatch error for …
DrVelvetFog Jul 1, 2026
5f99b5f
fix labelers (#2754)
phdargen Jul 2, 2026
b892aef
NEAR reference implementation (#2663)
mikedotexe Jul 3, 2026
888d20d
Pull request for mintlify/docs-update-1783067909137 (#2771)
mintlify[bot] Jul 3, 2026
91b6f79
Fix e2e runs (#2756)
phdargen Jul 3, 2026
d00e388
Hardened Hedera facilitator verify (#2707)
phdargen Jul 3, 2026
d0af9ee
spec(xrpl): add exact scheme (#2547)
aristotle-satoshi Jul 3, 2026
d7fd9b4
Add XRPL to exact scheme docs (#2777)
mintlify[bot] Jul 3, 2026
17adec9
fix keeta tests + near sdk release preparation (#2773)
phdargen Jul 3, 2026
a3ad102
mcp interop fixes (#2774)
phdargen Jul 3, 2026
10ccbdb
docs: replace dead facilitator.x402.org with x402.org/facilitator (#2…
Echolonius Jul 5, 2026
2b74587
fix(examples/go): make the echo server + http client pair work from a…
farid-moradi Jul 6, 2026
7be420a
Deprecate website (#2794)
phdargen Jul 7, 2026
29311c1
Builder code py (#2795)
phdargen Jul 7, 2026
49706f0
Add Python support for builder-code extension (#2809)
mintlify[bot] Jul 7, 2026
f4530e2
fix(python/flask): use sync server in payment_middleware_from_config …
kakedashi3 Jul 8, 2026
d9bd02d
feat(evm): add Igra mainnet (eip155:38833) default stablecoin (#2800)
emdin Jul 8, 2026
8b1abae
docs(specs): add exact scheme spec for Casper Network (#2741)
davidatwhiletrue Jul 8, 2026
f5070b9
fix flask 3xx response bug (#2826)
phdargen Jul 10, 2026
765990c
fix(python/fastapi): return 500 (and log) on unexpected settlement er…
moped2110 Jul 10, 2026
07bd44d
docs: clarify production facilitator guidance for mainnet EVM routes …
defiQUG Jul 10, 2026
79bad65
chore: version python package  (#2827)
phdargen Jul 10, 2026
7301f6c
chore: version typescript packages  (#2828)
phdargen Jul 10, 2026
2aa22d3
chore(go): release (#2829)
phdargen Jul 10, 2026
0a60407
fix e2e exit hang (#2830)
phdargen Jul 10, 2026
ea2cd81
docs(facilitators): add Solvador to facilitators list (#2757)
feyyazcigim Jul 13, 2026
ac7a51b
fix(python/flask): return 500 (not empty 402) on unexpected settlemen…
kakedashi3 Jul 14, 2026
60af28e
Aptos signature check (#2850)
phdargen Jul 14, 2026
08a3b46
feat(xrpl): add exact scheme TypeScript reference implementation (#2801)
aristotle-satoshi Jul 14, 2026
13579dc
feat(site): register XRPL testnet on the facilitator (#2857)
aristotle-satoshi Jul 15, 2026
45b9f6c
Document XRPL exact scheme TypeScript SDK support (#2854)
mintlify[bot] Jul 15, 2026
22a7677
docs: add XRPL to buyer quickstart, network lists, and facilitators (…
aristotle-satoshi Jul 15, 2026
f692e8b
Add XRPL Testnet to x402.org facilitator network support (#2858)
mintlify[bot] Jul 15, 2026
90d2aa8
docs(near): document network support (#2813)
mikedotexe Jul 15, 2026
21b0745
Bind SIWX domain validation to a configured origin (#2859)
phdargen Jul 15, 2026
c72cfee
Harden channel storage (#2863)
phdargen Jul 16, 2026
0e1c7e8
Update onAfterVerify hook docs with abort support (#2882)
mintlify[bot] Jul 16, 2026
411f65c
Fix go deposit balance double-count (#2881)
phdargen Jul 16, 2026
f752271
fix go VerifyDeposit projected balance (#2883)
phdargen Jul 16, 2026
aad8e4e
fix(evm): auto-wrap any eth_account BaseAccount, not just LocalAccoun…
0xkurious Jul 17, 2026
c1f2d90
TS: siwx structured errors (#2888)
phdargen Jul 17, 2026
0c8f533
Update SIWX docs for discriminated union result types (#2892)
mintlify[bot] Jul 17, 2026
91bd553
go/py: SIWX structured-errors (#2889)
phdargen Jul 17, 2026
c4d2de6
fix stellar tx fee (#2852)
phdargen Jul 17, 2026
62723fd
chore: version typescript packages  (#2893)
phdargen Jul 17, 2026
f2596a1
chore: version python package  (#2894)
phdargen Jul 17, 2026
67b1ba0
chore(go): release (#2895)
phdargen Jul 17, 2026
5a587d3
fix(go): preserve request bodies across payment retries (#2914)
wnjoon Jul 21, 2026
c67998e
docs(examples): refresh TypeScript examples index (#2916)
Toby1009 Jul 22, 2026
d3d4f2b
fix: propagate batch settlement storage errors (#2917)
wnjoon Jul 22, 2026
6f544b4
fix(go): return invalid payload for malformed payment signature (#2907)
wnjoon Jul 22, 2026
b7bfa69
Limit s buildercode (#2912)
phdargen Jul 22, 2026
ec4ef24
Document MAX_SERVICE_CODES cap for builder-code extension (#2923)
mintlify[bot] Jul 22, 2026
27fadeb
fix(fetch): preserve Request body during recovery (#2900)
realmehmetali Jul 22, 2026
328bf1e
fix(python): preserve streaming bodies on payment retry (#2899)
realmehmetali Jul 22, 2026
a0b5ba1
docs: add x402-list.com to ecosystem directories (#2925)
mcccsm Jul 22, 2026
21a2e48
add slack link (#2926)
phdargen Jul 22, 2026
bc22b7d
docs(svm): add `upto` SVM scheme specification (#2697)
lgalabru Jul 22, 2026
e5c5051
fix(evm): batch-settlement honors caller-supplied asset on networks o…
fretchen Jul 23, 2026
69652a6
docs+spec: clarify signer authorization in offer-receipt extension (#…
alftom Jul 23, 2026
1e9f650
feat(svm): server-provided recent blockhash in the exact 402 challeng…
lgalabru Jul 23, 2026
7915362
feat(go/svm): support server-provided recent blockhash (#2731)
wnjoon Jul 23, 2026
32464a2
Fix: SVM SIWx small-order Ed25519 verification (#2933)
phdargen Jul 23, 2026
61349de
Fix: Algorand CAIP-2 network IDs (#2931)
phdargen Jul 23, 2026
d027b57
feat: add Solana support to cloudfront-lambda-edge example (#2944)
notorious-d-e-v Jul 24, 2026
8e29d2e
specs(exact): propose Starknet exact scheme for x402 v2 (spec-only) (…
adipundir Jul 24, 2026
8982979
examples(python): demonstrate service metadata in the bazaar server e…
rascal-3 Jul 24, 2026
fab6795
Add NEAR x402 Facilitator (facilitators table + ecosystem partner ent…
mikedotexe Jul 24, 2026
c932510
docs: update clone URL to x402-foundation/x402 (#2949)
notorious-d-e-v Jul 24, 2026
13fe5cd
fix py fmt (#2946)
phdargen Jul 24, 2026
90688e5
Adds bazaar indexing troubleshooting guide (#2947)
phdargen Jul 24, 2026
59bbc51
docs: update NEAR facilitator for Base support (#2960)
mikedotexe Jul 27, 2026
4453a92
Fix silent auth drop when createAuthHeaders returns a flat object (#2…
cristianizzo Jul 27, 2026
04c94b6
feat(py): server-provided recent blockhash in the exact 402 challenge…
phdargen Jul 27, 2026
6d08ffa
chore: version typescript packages (#2969)
phdargen Jul 27, 2026
6437935
chore: version python package (#2970)
phdargen Jul 27, 2026
895f350
chore(go): release (#2971)
phdargen Jul 27, 2026
183b270
fix: add request timeouts to HTTPFacilitatorClient and guard eager in…
notorious-d-e-v Jul 29, 2026
e335d4f
fix(ts/go/py): always add client buildercodes (#2994)
phdargen Jul 30, 2026
d2e1275
fix(go/http): add Cache-Control: no-store to 402 responses (#2956)
Sertug17 Jul 30, 2026
ee1b148
fix(ts/py): add cache control, no-store for 402, private for 200 (#2990)
phdargen Jul 30, 2026
17fc989
fix: verify eip3009 transfer event in go (#2727)
wnjoon Aug 1, 2026
7c3d63e
docs: fix DEFAULT_ASSETS.md examples and stale file references (#3024)
GigaHierz Aug 3, 2026
242d6e9
feat(evm): add Celo mainnet (42220) and Celo Sepolia (11142220) defau…
GigaHierz Aug 3, 2026
03bc083
Update docs/core-concepts/network-and-token-support.mdx (#3026)
mintlify[bot] Aug 3, 2026
667bfec
fix(go): propagate payment response hook errors (#3022)
256dino Aug 3, 2026
e805616
fix(ts/go/py): merge server and client builder-code s arrays (#3027)
ethanoroshiba Aug 4, 2026
db9dabd
feat(evm): add Flare mainnet (14) default stablecoin (#3031)
whawk46 Aug 4, 2026
c427425
fix(mcp): re-approve before signing corrective 402 recovery payment (…
SashaMIT Aug 4, 2026
5192e50
fix: wildcard line terminator bypass (#3036)
CarsonRoscoe Aug 4, 2026
3c63262
fix(python): verify Transfer event after exact/eip3009 settle (#3032)
SashaMIT Aug 4, 2026
08e84ab
fix(mcp): plumb spend policies through createx402MCPClient factory (#…
SashaMIT Aug 4, 2026
49a3c7e
Update docs/guides/mcp-server-with-x402.md (#3038)
mintlify[bot] Aug 4, 2026
dea7937
fix(evm): verify Transfer event in receipt after exact/eip3009 settle…
Mameta29 Aug 4, 2026
6b04d5e
fix: reject external / in bazaar discovery schema (SSRF) (#3039)
CarsonRoscoe Aug 4, 2026
1fd1a6d
Update docs/extensions/bazaar.mdx (#3040)
mintlify[bot] Aug 4, 2026
5e20460
chore: version typescript packages  (#3041)
phdargen Aug 4, 2026
a4e23be
chore: version python package  (#3042)
phdargen Aug 4, 2026
34cb6bd
chore(go): release (#3043)
phdargen Aug 4, 2026
158adb0
fix: match payment-gated routes on the escaped request path (#3044)
CarsonRoscoe Aug 6, 2026
c7e0ac8
fix(python): match wildcard routes containing a line feed (#3055)
saneGuy Aug 7, 2026
8bef6f7
Specs(exact): propose Canton exact scheme for x402 (spec-only) (#2634)
Denend Aug 7, 2026
db5da2e
feat(ts): payment flow handlers (#3053)
phdargen Aug 8, 2026
1fec3aa
Document payment flows and settle phases (#3088)
mintlify[bot] Aug 8, 2026
112c1e3
fix(go): compile route patterns with (?s) so wildcards match line fee…
hung-yueh Aug 9, 2026
76bda78
fix(evm): correct Monad USDC EIP-712 domain name to "USDC" (#3102) (#…
chopmob-cloud Aug 10, 2026
2c83d1c
Update docs/core-concepts/network-and-token-support.mdx (#3108)
mintlify[bot] Aug 10, 2026
e6f354c
label networks in prs (#3090)
phdargen Aug 10, 2026
1601942
fix(ts/py): path normalization (#3073)
phdargen Aug 10, 2026
1d15062
E2e refactor (#2976)
phdargen Aug 10, 2026
927fea8
feat(svm): make facilitator transaction limits operator-configurable …
notorious-d-e-v Aug 11, 2026
37412e7
fix(ts): escape backslashes in normalizePath instead of folding them …
CarsonRoscoe Aug 11, 2026
0b79a6a
Update docs/schemes/exact.mdx (#3127)
mintlify[bot] Aug 11, 2026
a52417e
chore(go): release (#3130)
phdargen Aug 11, 2026
a98c19d
chore: version python package  (#3129)
phdargen Aug 11, 2026
c8247c4
chore: version typescript packages  (#3128)
phdargen Aug 11, 2026
16a23d0
fix(ts): require TransferChecked discriminator in svm exact (#3132)
phdargen Aug 12, 2026
79b6259
feat(ts): svm upto paymentflow (#3094)
phdargen Aug 12, 2026
9a9d4f9
Document upto SVM payment scheme (#3135)
mintlify[bot] Aug 12, 2026
f62a9fa
feat(go): payment flows for go sdk (#3115)
phdargen Aug 12, 2026
74038ba
Update docs/advanced-concepts/lifecycle-hooks.mdx (#3139)
mintlify[bot] Aug 13, 2026
c2612d3
fix(ts): bind SIWX client challenge to the request origin (#3133)
phdargen Aug 13, 2026
50d2ec6
Document SIWX origin binding: required requestUrl argument (#3143)
mintlify[bot] Aug 13, 2026
4f58723
feat(TS): spend controls (#3124)
phdargen Aug 13, 2026
2d23a16
Document spendControls client safety feature (#3147)
mintlify[bot] Aug 13, 2026
a1af647
fix(evm): correct Monad USDC v1 EIP-712 domain name to "USDC" (#3153)
Im-Madhur-Gupta Aug 14, 2026
167a828
feat(ts): add ComputeBudget instructions to svm upto transactions (#3…
notorious-d-e-v Aug 14, 2026
f12f879
docs(migration): use real Solana genesis-hash CAIP-2 ids (#3179)
soulee-dev Aug 17, 2026
ab1a31a
fix(ts): handle missing accepted requirements (#3180)
JasonColapietro Aug 17, 2026
8c308ce
feat(svm): allow injecting an RPC client into the upto facilitator (#…
notorious-d-e-v Aug 17, 2026
2a706b2
feat: add solana upto to go sdk (+ typescript parity fixes) (#3141)
CarsonRoscoe Aug 17, 2026
6dba93e
feat: add settlement pending state (#3083)
CarsonRoscoe Aug 17, 2026
e69d9c8
Go SDK now supports upto SVM scheme (#3190)
mintlify[bot] Aug 18, 2026
67ca554
Update docs/core-concepts/facilitator.md (#3191)
mintlify[bot] Aug 18, 2026
656437e
feat(py): add spend controls (#3154)
phdargen Aug 18, 2026
b4db321
Update docs/getting-started/quickstart-for-buyers.mdx (#3195)
mintlify[bot] Aug 18, 2026
5246387
feat(go): spend controls (#3156)
phdargen Aug 18, 2026
3fc84cc
Document Go spend controls support (#3196)
mintlify[bot] Aug 18, 2026
37862b2
py port (#3192)
phdargen Aug 18, 2026
b0a4c0a
go port (#3193)
phdargen Aug 18, 2026
ddf98ee
Update Go SDK feature parity for onPaymentRequired hook (#3198)
mintlify[bot] Aug 18, 2026
17d319f
chore: version typescript packages  (#3200)
phdargen Aug 18, 2026
2b92f72
chore: version python package  (#3202)
phdargen Aug 18, 2026
270a08b
chore(go): release (#3201)
phdargen Aug 18, 2026
75b519d
bump gh-action-pypi-publish (#3204)
phdargen Aug 18, 2026
7d5363a
docs: add fireblocks facilitator (#3194)
matthew1809 Aug 20, 2026
292e849
docs(svm): add `batch-settlement` SVM scheme specification (#2698)
lgalabru Aug 21, 2026
230e6a9
Update docs/schemes/batch-settlement.mdx (#3222)
mintlify[bot] Aug 21, 2026
2f65c79
docs(specs): refresh the contributing guide and impl template (#3235)
zjzJoez Aug 23, 2026
6557149
feat(evm): add Sei default stablecoins (#3227)
alexander-sei Aug 24, 2026
692c7dc
docs(ts): align contributor prerequisites with workspace (#3254)
Moyuin-aka Aug 24, 2026
8707ab7
fix(mcp-ts): handle facilitator failure before resource delivery (#3246)
phdargen Aug 24, 2026
f41d9be
fix(ts/go/py): Validate batch settlement response (#3251)
phdargen Aug 24, 2026
f8dfe4d
feat(py): payment flow (#3247)
phdargen Aug 24, 2026
06c028e
Python payment flow handlers: phase examples & MCP hook parity (#3255)
mintlify[bot] Aug 24, 2026
ec0f71e
fix(svm): validate smart wallet limits (#3122)
notorious-d-e-v Aug 24, 2026
121c98f
fix(go/py): align default asset declaration with ts (#3241)
phdargen Aug 24, 2026
aeb0fdd
Update docs/core-concepts/network-and-token-support.mdx (#3257)
mintlify[bot] Aug 24, 2026
82ba36f
feat: settlement pending auto-recovery (#3214)
CarsonRoscoe Aug 25, 2026
bde6fe5
Update docs/core-concepts/facilitator.md (#3259)
mintlify[bot] Aug 25, 2026
f8a3682
Auth-capture spec update: v1.1 (#3197)
phdargen Aug 25, 2026
bb46ffc
feat(ts/go): upfront paymentflow for exact mechanism (#3240)
phdargen Aug 25, 2026
cdfa491
Document upfront payment flow for exact scheme (#3267)
mintlify[bot] Aug 25, 2026
01b0a68
feat(Ts/Go): avoid fee-payer signing svm exact /verify + Go smart wal…
phdargen Aug 26, 2026
b1a88ef
Update docs/schemes/exact.mdx (#3272)
mintlify[bot] Aug 26, 2026
ab1b418
feat(evm): add Upto-only deployment entrypoint (#3199)
huaweigu Aug 26, 2026
b32b564
fix: upto proxy canonical address (#3276)
CarsonRoscoe Aug 26, 2026
acaa904
fix(ts/go): refactor svm upto rpc config (#3274)
phdargen Aug 26, 2026
8468e3a
Fix SVM upto facilitator RPC configuration examples (#3277)
mintlify[bot] Aug 26, 2026
44f6b17
feat(ts/go): auth-capture client v1.1 (#3283)
phdargen Aug 27, 2026
f257584
chore: version typescript packages  (#3287)
phdargen Aug 27, 2026
d22ae96
chore: version python package  (#3288)
phdargen Aug 27, 2026
8ac521c
chore(go): release (#3289)
phdargen Aug 27, 2026
b703a0e
Update docs/sdk-features.md (#3286)
mintlify[bot] Aug 27, 2026
e398a9e
disable spend controls in stellar integration test (#3290)
marcelosalloum Aug 28, 2026
dd25875
fix(e2e): scope EVM/SVM client signer derivation to selected families…
Eras256 Aug 31, 2026
cd43052
fix(go): use maxTimeoutSeconds for EIP-3009 validBefore (#3282)
Tehsapper Aug 31, 2026
6838428
feat(python): make facilitator gas limit configurable (#3233)
nniiovoo Aug 31, 2026
240492e
docs(specs): correct v2 §8 discovery fields to match the wire format …
onlyarche Aug 31, 2026
675bb5d
fix(go): prevent settlement override percent overflow (#2962)
wnjoon Aug 31, 2026
18ecba0
e2e: add script to check wallet balances (#3297)
phdargen Aug 31, 2026
87a19a7
Fix e2e warnings (#3308)
phdargen Aug 31, 2026
d2bc9ba
fix: improve facilitator evm latency (#3312)
CarsonRoscoe Aug 31, 2026
e187dda
fix(py): add server-only extension_responses sidechannel (#3306)
phdargen Aug 31, 2026
a3c6004
validate builder-code app attribution on (#3313)
phdargen Aug 31, 2026
a140d2b
fix #3019 (#3309)
phdargen Aug 31, 2026
138d415
Document builder-code `a` field validation and v1 behavior (#3315)
mintlify[bot] Aug 31, 2026
68e529b
Update withX402 docs for keyed route patterns (#3316)
mintlify[bot] Aug 31, 2026
1bc2ae8
fix(core): server-only extensionResponses sidechannel (#3278)
Bartok9 Aug 31, 2026
94f9951
fix(e2e): svm smart wallet config (#3319)
phdargen Aug 31, 2026
bbcb974
fix(core): throw when no scheme server is registered (#3051)
VedantAnand17 Sep 1, 2026
71dd629
docs(ts/mcp): update README for current API and payment shapes (#3089)
Xeift Sep 1, 2026
0344bdf
fix(e2e): HTTP-only swig-setup RPC with devnet fallback (#3327)
phdargen Sep 1, 2026
fed6a04
fix: replace crypto dependency with @noble/hashes in @x402/svm (#3335)
CarsonRoscoe Sep 2, 2026
6c1a4b2
fix(go): validate builder-code app attribution (#3302)
wnjoon Sep 2, 2026
b0febf2
docs: list FTP Canton Facilitator (#3243)
nicky2pc Sep 2, 2026
eb0d899
fix(go): return EXTENSION-RESPONSES on verify and settle (#3301)
wnjoon Sep 2, 2026
23173ac
Expand asset transfer methods with `upfront` payment flows, family sp…
IkerAlus Sep 2, 2026
7488a46
fix(stellar): accept CAP-71 V2 address credentials for Protocol 28 (#…
jeesunikim Sep 2, 2026
626df07
fix(stellar): include feeBumpSigner in facilitator-safety checks (#3336)
Eras256 Sep 3, 2026
78412bc
fix(go): bound HTTP response body reads (#2973)
wnjoon Sep 3, 2026
3e9631d
fix(python): validate builder-code app attribution on v2 (#3320)
PhilBot402 Sep 3, 2026
4999dc6
fix(ts,go): update auth-capture v1.1 contracts to canonical deploymen…
phdargen Sep 3, 2026
299b9bc
feat(ts): add delegated receiver authorizer for SVM upto (#3346)
phdargen Sep 3, 2026
15f7192
feat(go): add delegated receiver authorizer for SVM upto (#3347)
PhilBot402 Sep 3, 2026
5bbf418
Update docs/schemes/upto.mdx (#3356)
mintlify[bot] Sep 3, 2026
85f2d90
chore: version typescript packages  (#3357)
phdargen Sep 3, 2026
23c7a97
chore: version python package  (#3358)
phdargen Sep 3, 2026
0369831
feat: optimize go facilitator SDK - EVM and SVM (#3355)
CarsonRoscoe Sep 3, 2026
2cc7e9a
chore(go): release (#3359)
phdargen Sep 4, 2026
5df361d
fix(java): buffer response body until settlement succeeds (#3074)
rileybuilds Sep 4, 2026
14e9c2a
feat(svm): use linear backoff for upto channel re-reads (#3367)
PhilBot402 Sep 5, 2026
20e525c
perf(evm): reuse verify ERC-6492 payer classification in settle (#3365)
PhilBot402 Sep 5, 2026
1d289fc
fix(python): reuse verify ERC-6492 payer code in settle (#3366)
PhilBot402 Sep 5, 2026
560fdb0
Update docs/schemes/upto.mdx (#3380)
mintlify[bot] Sep 5, 2026
0c04a84
fix(python): exit on fatal HTTP adapter initialize errors (#3364)
PhilBot402 Sep 5, 2026
1ef4606
docs: add x402aff to third-party extensions (#3395)
aaronjmars Sep 7, 2026
48fac89
fix(ts): buffer hono/next settlement replies and raise facilitator HT…
phdargen Sep 7, 2026
e2bbe93
improve e2e breakdown (#3382)
phdargen Sep 7, 2026
76fe973
feat(ts): Add optional extra.minDeposit hint for EVM batch-settlement…
phdargen Sep 7, 2026
102e5d6
Document minDeposit hint for batch-settlement scheme (#3398)
mintlify[bot] Sep 7, 2026
241df66
Enforce file-size and complexity limits with coverage thresholds (#3393)
phdargen Sep 7, 2026
95255a6
fix(hono): settlement-failure tests construct a real Response (#3402)
saneGuy Sep 8, 2026
92d717b
fix(python): default HTTPFacilitatorClient timeout to 90s (#3409)
PhilBot402 Sep 8, 2026
4e15690
fix(go): raise HTTPFacilitatorClient default timeout to 90s (#3408)
PhilBot402 Sep 8, 2026
8ae5ff6
fix(extensions): decode routeTemplate to a fixed point before travers…
ygd58 Sep 9, 2026
42ee42b
feat: add Cardano implementation for Typescript package (#2537)
fabianbormann Sep 9, 2026
6777eaa
Document Cardano exact scheme support (#3429)
mintlify[bot] Sep 9, 2026
fdeda56
feat(mcp,ts): use accept's maxTimeoutSeconds for tool timeout + Carda…
phdargen Sep 9, 2026
3c2ddfb
fix(svm): split upto delegated-auth store errors from unauthenticated…
phdargen Sep 9, 2026
273ecef
fix(python): decode routeTemplate to a fixed point before traversal c…
PhilBot402 Sep 11, 2026
04c750e
fix(go): decode routeTemplate to a fixed point before traversal check…
PhilBot402 Sep 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
34 changes: 34 additions & 0 deletions .agents/skills/authoring-specs/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
---
name: authoring-specs
description: Guidelines for authoring x402 specification files. Use when writing or proposing a new x402 spec, such as a per-network scheme spec (scheme_<name>_<chain>.md).
---

# Authoring x402 specs

Guidance for writing x402 specification files under `specs/`. Use RFC-2119 keywords for normative statements (MUST / MUST NOT, SHOULD / SHOULD NOT, MAY).

## General rules

These apply to every spec type (scheme, extension). The references below add type-specific detail.

### Naming

- Name schemes and extensions in lowercase, hyphen-separated kebab-case (e.g. `batch-settlement`, `offer-receipt`), never camelCase.

### Protocol version, networks, and units

- Target protocol v2 only: `x402Version: 2`, the `amount` field (not v1's `maxAmount`), and the `PAYMENT-REQUIRED` / `PAYMENT-SIGNATURE` / `PAYMENT-RESPONSE` headers (not v1's `X-PAYMENT` / `X-PAYMENT-RESPONSE`). See the [v1 to v2 migration guide](../../../docs/guides/migration-v1-to-v2.mdx).
- Use canonical CAIP-2 network notation (e.g. `eip155:84532`, not `base-sepolia`).
- Use atomic units for all amounts.

### Wire format

- Be transport agnostic: specify message contents, not how a particular transport carries them.
- Reference core types (`PaymentRequirements`, `PaymentPayload`, `SettlementResponse`) from [`x402-specification-v2.md`](../../../specs/x402-specification-v2.md).
- Every field a spec defines on the wire must be consumed by a downstream role. Do not include human-readable or otherwise purely informational fields.
- Reuse field names, patterns, and conventions established by existing specs instead of coining new ones.

## References

- New network scheme spec (`scheme_<name>_<chain>.md`): see [references/new-network-scheme-spec.md](references/new-network-scheme-spec.md).
- New extension spec: to be added.
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# New network scheme spec

Checklist for authoring a new per-network scheme spec file (`scheme_<name>_<chain>.md`). Follow the [general spec rules](../SKILL.md) as well.

## Spec contents

- Scheme-specific information (e.g. in `PaymentRequired`) goes in `extra`, not in `extensions` or at the top level.
- Define any scheme-specific `extra` fields (optional/required, with description), and show them in `PaymentRequired`, `PaymentPayload`, and `SettlementResponse` messages or `supported/` examples.
- Every field placed in `PaymentRequired.extra` must be consumed by the client to construct the payment or by the facilitator to verify or settle it; do not include human-readable or otherwise purely informational fields.

## Compliance and conventions

- Comply with the network-agnostic scheme definition (e.g. `scheme_exact_<network>.md` complies with [`scheme_exact.md`](../../../../specs/schemes/exact/scheme_exact.md)).
- Reuse field names already established by existing schemes instead of coining new ones. For example, when the scheme must name the account that sponsors network fees (typically the facilitator), use `extra.feePayer` as in [`scheme_exact_svm.md`](../../../../specs/schemes/exact/scheme_exact_svm.md); when the scheme offers more than one payload format, use `extra.assetTransferMethod` to select among them as in [`scheme_exact_evm.md`](../../../../specs/schemes/exact/scheme_exact_evm.md).

## Fee sponsorship and infrastructure

- Fee sponsorship is strongly preferred; clients and servers should not need to pay gas or hold the native token.
- The server should not need an RPC; the client may use an RPC; a facilitator RPC can be considered a given.

## Statelessness

- Stateless design is strongly preferred for client and server, and especially the facilitator. A short-lived cache is acceptable but needs to be well justified (see the duplicate-settlement mitigation in [`scheme_exact_svm.md`](../../../../specs/schemes/exact/scheme_exact_svm.md#duplicate-settlement-mitigation-recommended)). Persistent storage warrants discussion with maintainers.

## Nonces

- Sequential nonces are strongly discouraged. They effectively lock the client account until the server route handler completes and the transaction settles, which may take several minutes (bounded only by `maxTimeoutSeconds`, on which the protocol enforces no upper limit). If the client submits another transaction from that account between verification and settlement, the nonce is consumed, settlement fails, and the work the server already performed is wasted.

## Verification and settlement

- Do not introduce new facilitator endpoints beyond `verify/`, `settle/`, and `supported/`. A scheme must express all facilitator interactions through these existing endpoints.
- Use transaction simulation, not only structural payload checks, to confirm the transaction would actually succeed onchain. If that is not possible, at least targeted checks of onchain state MUST be done (e.g. sufficient client token balance, nonce unconsumed).
- Verify should provide the strongest possible guarantee that settlement will succeed. If settle fails, the client does NOT get access to the resource; but if verify succeeded, the server did unnecessary work, wasting resources (compute). This is a server protection.
- The facilitator must confirm transaction success onchain before returning success to the server.
- The facilitator must protect its own funds and bound its fee exposure. Its signature must authorize only the network fee: the facilitator must not appear as the authority, source, or sender of any value-moving instruction (fee-payer isolation), so it cannot be induced to transfer its own funds. It must also cap the fees it pays against client-controlled parameters (e.g. explicit gas limits, compute-unit and priority-fee caps), so a client cannot inflate them.

## Trust model

- The client must treat all server-provided fields as untrusted and must not rely on a server value for anything it can determine authoritatively itself. For example, if a scheme placed token `decimals` in `extra` and the client trusted it, a misconfigured or malicious server could report a wrong value, causing the client to compute too large an atomic `amount` and overpay; the client must instead read `decimals` (and similar token metadata) from onchain state.
- The server and facilitator must consider the client payload untrusted.
- The client should never interact with the facilitator directly, always via the server as proxy.

## Account requirements

- Enumerate every account precondition that must hold before a payment can be verified and settled, naming the responsible role (client, server, or facilitator). Examples: a minimum native balance for rent or fees, an asset trustline or token association / opt-in, and account or associated-token-account creation.
91 changes: 91 additions & 0 deletions .agents/skills/contributing/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
---
name: contributing
description: Guidelines and conventions for contributing to the x402 codebase. Use when preparing a PR to the upstream x402-foundation/x402 repository such as fixing a bug or Issue, implementing a new feature, adding a mechanism/scheme or extension.
---

# Contributing to x402

## Reuse before writing new code

- Before writing anything, check in order whether the standard library (TS: ECMAScript and Node.js built-ins like `node:crypto`; Python: the stdlib; Go: packages like `net/http`, `encoding/json`, `crypto`), a native platform feature, or an already-installed dependency already does it; if so, use it.
- Always reuse shared and core utilities.
- No new dependencies if it can be avoided.

## Keep changes minimal

- Address a single issue per contribution, not multiple.
- Targeted edits, minimal diff, atomic commits.
- No abstractions or boilerplate that were not explicitly requested.
- No edits to legacy/v1 code; it is effectively frozen (security patches only). This includes the paths `typescript/packages/legacy/`, `go/legacy`, `python/legacy` and the `java/` SDK.

## Code style

- Write clean, readable code (e.g. prefer guard clauses over nested conditionals, use descriptive names and small, single-purpose functions).
- Strong typing, avoid any weak types (`any`, `unknown`, and their equivalents in other languages). Research the codebase to find the correct type, reuse existing type definitions rather than redeclaring them and confirm no type errors remain.
- No overly defensive code or silent fallbacks.
- Apply DRY only where it reduces complexity; keep single-use logic inline rather than extracting a helper for it.

## Comments

- Write comments that help a new reader understand the codebase.
- Never narrate in-progress work or describe code being replaced.
- Write onchain - never "on-chain" or "on chain".
- Don't change/remove existing comments, unless strictly needed due to code changes.

## AI-assisted contributions

Follow the repository AI-assisted contribution policy in [CONTRIBUTING.md](../../CONTRIBUTING.md#ai-assisted-contributions). Review all AI-generated output before requesting maintainer review.

## Working on an Issue

- Independently reproduce and verify the Issue first.
- When in doubt, ask clarifying questions on the Issue before writing code.

## Bug fixes

- Add a test that fails before the fix and passes after it.
- Don't write tests for what the type system already guarantees.
- Cover edge cases, not only happy path.

## Commits and PRs

- Verifying (signing) ALL commits is strictly required; maintainers will not check a PR otherwise. See [GitHub: about commit signature verification](https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification).
- PR description: short and matching the diff; explain what and why; link relevant issues; state the root cause in one paragraph, citing file and line.
- Justify design decisions where there were ambiguities and discuss the tradeoffs of the approach you picked against the alternatives you considered.

## Per-language

### Per commit: format, lint, build, test

Format, lint, build, and run unit tests before each commit.

```bash
# TypeScript (from typescript/)
pnpm format && pnpm lint && pnpm build && pnpm test

# Go (from go/)
make fmt && make lint && make build && make test

# Python (from python/x402/)
uvx ruff format && uvx ruff check && uv run pytest
```

### Per PR: changelog

Add a changelog fragment for the SDK you changed.

```bash
# TypeScript (from typescript/)
pnpm changeset

# Go (from go/)
make changelog-new

# Python (from python/x402/)
uv run towncrier create --content "Fixed ..." <PR>.bugfix.md
```

## New mechanism or extension

- New payment mechanism / scheme: see [references/new-mechanism.md](references/new-mechanism.md).
- New extension: see [references/new-extension.md](references/new-extension.md).
61 changes: 61 additions & 0 deletions .agents/skills/contributing/references/new-extension.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# New extension implementation

Checklist for adding a new extension. Follow the [general contributing rules](../SKILL.md) as well.

## Spec first

- A spec file must exist. If it does not, write it first.
- The spec must be approved by maintainers (merged into upstream `main`). If it is not, open a PR with the spec only first (`specs/extensions/...`).
- The implementation must follow the spec file exactly.
- The wire formats `PAYMENT-REQUIRED` (in particular the extension field), `PAYMENT-RESPONSE` and facilitator `supported/` output must match the spec strictly. Include only fields actually consumed downstream or required by the extension. Don't add purely informational fields.
- Spec amendments and edits are allowed, but must be well justified.

## Scope

- One language per PR. Never implement the extension in more than one SDK (TS, Python, Go) in a single PR.
- Implement v2 only. Common v1 tells (see the [V1→V2 migration guide](../../../../docs/guides/migration-v1-to-v2.mdx)): `maxAmount` in payment requirements, `X-PAYMENT`/`X-PAYMENT-RESPONSE` headers (v2 uses `PAYMENT-SIGNATURE`/`PAYMENT-RESPONSE`), string network names like `base-sepolia` (v2 uses CAIP-2 like `eip155:84532`) or `x402Version: 1`.

## Code patterns

- Wire extensions with lifecycle hooks via the extension-hooks adapter pattern.
- Reuse core and extension utilities instead of reimplementing them.
- Do NOT modify other packages (core, http, ...). If this is deemed necessary, discuss with maintainers first.

## Tests

### Unit tests

- Pure-logic tests that run offline. Add them under **TS** `typescript/packages/extensions/test/`; **Go** `go/extensions/<extension>/`; or **Py** `python/x402/tests/unit/extensions/<extension>/`. Run them and confirm all pass.
- New additions must have **>80%** line coverage.

```bash
# from typescript/
pnpm --filter @x402/extensions test
# go/
make test
# python/x402/
uv run pytest tests/unit/extensions/
```

### Integration tests

- In-process client/server/facilitator flow tests within the SDK. Requires funded testnet accounts.
- Add them under **TS** `typescript/packages/extensions/test/integrations/`; **Go** `go/extensions/<extension>/`; or **Py** `python/x402/tests/integrations/`. Suites skip when required env vars are missing.
- Run them and confirm all pass.

```bash
# from typescript/
pnpm --filter @x402/extensions test:integration
# go/
make test-integration
# python/x402/
uv run pytest tests/integrations/
```

## Examples

Add server, client, and facilitator examples (as appropriate). Manually confirm a successful payment by running facilitator server and client examples locally.

## Docs

- Add READMEs for the SDK and all examples.
86 changes: 86 additions & 0 deletions .agents/skills/contributing/references/new-mechanism.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# New mechanism implementation

Checklist for adding a new payment mechanism / scheme. Follow the [general contributing rules](../SKILL.md) as well.

## Spec first

- A spec file must exist. If it does not, write it first.
- The spec must be approved by maintainers (merged into upstream `main`). If it is not, open a PR with the spec only first (`specs/schemes/...`).
- The implementation must follow the spec file exactly. Facilitator verification rules are security-critical.
- The wire formats `PAYMENT-REQUIRED` (in particular the `extra` field), `PAYMENT-RESPONSE` and facilitator `supported/` output must match the spec strictly. Include only fields actually consumed downstream or required by the scheme. Don't add purely informational fields.
- Spec amendments and edits are allowed, but must be well justified.

## Scope

- One language per PR. Never implement the mechanism in more than one SDK (TypeScript, Python, Go) in a single PR.
- If a reference implementation already exists in another SDK, cross-check against it; otherwise yours is the reference and the spec is the only source of truth.
- Implement v2 only. Common v1 tells (see the [V1→V2 migration guide](../../../../docs/guides/migration-v1-to-v2.mdx)): `maxAmount` in payment requirements, `X-PAYMENT`/`X-PAYMENT-RESPONSE` headers (v2 uses `PAYMENT-SIGNATURE`/`PAYMENT-RESPONSE`), string network names like `base-sepolia` (v2 uses CAIP-2 like `eip155:84532`) or `x402Version: 1`.

## Code patterns

- Wire schemes with the builder pattern, not `register*` helpers. A new v2-only mechanism registers its scheme under the family wildcard: `client.register("<family>:*", new Exact<Chain>Scheme(...))` (and the same on `x402ResourceServer`). Do NOT implement a `registerExact<Chain>Scheme` helper. Those exist only in the EVM/SVM mechanisms to also register the legacy v1 schemes for backward compat.
- Reuse core utilities instead of reimplementing them. For example, import `convertToTokenAmount`, `numberToDecimalString`, and `parseMoney` from `@x402/core/utils` for TS or similar for Go/python SDKs.
- If the mechanism supports `$` string pricing, add `defaultAssets.ts` / `default_assets.go` / `default_assets.py` with `DEFAULT_ASSETS`, `getDefaultAsset`/`GetDefaultAsset`/`get_default_asset`, and `findDefaultAsset`/`FindDefaultAsset`/`find_default_asset` (see [DEFAULT_ASSETS.md](../../../../DEFAULT_ASSETS.md)). Expose the reverse lookup on the client scheme so `@x402/core` spend controls recognize USD-pegged defaults. Chains without a canonical USD stablecoin may omit the file and require explicit `AssetAmount` pricing instead. Do not put default assets in `constants` or bundled network-config maps.
- Do NOT modify other packages (core, http, ...). If this is deemed necessary, discuss with maintainers first.

## Tests

### Unit tests

- Pure-logic tests that run offline with no live RPC or network calls. Add them with comparable coverage to the EVM reference under **TS** `typescript/packages/mechanisms/<chain>/test/unit/`; **Go** `go/mechanisms/<chain>/` or **Py** `python/x402/tests/unit/mechanisms/<chain>/`. Run them and confirm all pass.
- New additions must have **>80%** line coverage.

```bash
# typescript/
pnpm --filter @x402/<chain> test
# go/
make test
# python/x402/
uv run pytest
```

### Integration tests

- In-process client/server/facilitator flow tests within the SDK that exercise real RPC endpoints and may submit onchain transactions. Requires funded testnet accounts.
- Add them with comparable coverage to the EVM reference under **TS** `typescript/packages/mechanisms/<chain>/test/integrations/` (see `exact-evm.test.ts`); **Go** `go/test/integration/`; **Py** `python/x402/tests/integrations/`. Suites skip when required env vars are missing.
- Run them and confirm all pass.

```bash
# typescript/
pnpm --filter @x402/<chain> test:integration
# go/
make test-integration
# python/x402/
uv run pytest tests/integrations/
```

### E2E tests

- The `e2e/` harness runs client × server × facilitator combinations from the mechanisms catalog. Requires funded testnet accounts.
- Add `e2e/config/mechanisms_<id>.json` (`env`, `testnet`/`mainnet`, `routes` with `sdks`). Do **not** edit per-framework route lists or CAIP-2 pattern tables — HTTP/MCP endpoints are derived from the catalog.
- Register the scheme once per language in the shared modules only: `e2e/servers/<lang>/`, `e2e/clients/<lang>/`, `e2e/facilitators/<lang>/`.
- Add wallet/payee placeholders to `e2e/.env-local`.
- Run them and confirm all pass.

```bash
# from e2e/
pnpm install:all && pnpm test --testnet --min --families=<chain> --versions=2
```

## Examples

- Add network to server, client and facilitator examples under `examples/<sdk>/*/advanced/all_networks`.
- Manually confirm a successful payment by running facilitator, server and client examples locally.

## Docs

- Add READMEs for the SDK and all examples.
- Include link to a testnet faucet and detail all necessecary setup steps (e.g. token association/opt-ins or minimum balance requirements).

## Publishing scripts

Mirror the EVM setup per SDK:

- **TS**: Add `publish_npm_scoped_x402_<chain>.yml` workflow and add package to `publish_npm_scoped_x402_all.yml`.
- **Py**: Add an optional extra in `python/x402/pyproject.toml`; uses existing `publish_pypi_x402.yml`.
- **Go**: no new workflow required; ships with the `go/` module.
5 changes: 5 additions & 0 deletions .gitbook.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
root: ./docs/

structure:
readme: README.md
summary: SUMMARY.md
Loading
Loading