Repository navigation
0.7.0 (1/7): x402 read checks on any chain, fix hints, wasit serve - #4
Merged
Merged
Conversation
X402-04 and X402-05 read only accepts[0], and X402-05 accepted only stellar:testnet and stellar:pubnet. A conformant x402 service on another chain failed it, and a challenge offering several networks was judged on whichever came first. Both checks now read every payment option and name a broken one by its index. X402-05 requires CAIP-2, as x402 v2 does (spec 11.1), and applies the rules each namespace's CAIP-2 definition fixes: stellar is testnet or pubnet, eip155 a base-10 chain id, solana the first 32 base58 characters of the genesis hash. A well-formed id in another namespace passes, and the result says only the format was checked, since failing it would report Wasit's lack of rules as the target's defect. The rules move to x402/requirements.ts so they are tested without a network. The payment checks pay only on the network the run names. x402Client picks the first option it supports, which could be the other Stellar network; a policy now filters to --network. A challenge with no option on that network, or none in the exact scheme, skips X402-06/07 with the networks it offers and sends nothing. An unsupported --network, or pubnet without an RPC endpoint, stops at preflight instead of after paying with no way to verify the settlement. 24 new offline tests, mutation-checked. Run against a local stand-in offering Base Sepolia and Solana devnet (5/5 read-only, payment checks skipped, nothing sent) and against the Stellar fixture (7/7, X402-06 settled on-chain). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A FAIL said what was wrong and left the fix to the reader. Builders new to x402 then had to read the spec to find it. A FAIL now carries a fix and a docs link, in the CLI's text and --json output and in the MCP server's structuredContent (fix, docs). Where a check can tell the cause, the fix is specific: eip155:0x14a34 is told to write eip155:84532, a 200 on an unpaid request to put the payment middleware in front of the route, a missing PAYMENT-RESPONSE what to return. Otherwise the check's catalogue entry supplies a general fix, and every entry now has one, so no catalogued check can fail without guidance. Only a FAIL gets any: a skip or a no-verdict is not a defect. Core gains fixFor(), catalogueEntry(), docsUrlFor() and an optional hint on CheckResult; X402-07's verdict is split out so it is testable offline. X402-04 checked three fields. x402 v2 requires six in every option (scheme, network, amount, asset, payTo, maxTimeoutSeconds) and v1 eight; it now checks the advertised version's list, and reports a field of the wrong type as such rather than as missing. The official server SDK fills every field, so services built with it are unaffected. The CLI's payment warning now says it applies only when the target offers an option on the run's network. 41 new offline tests; 18 mutants, all killed. Run against a hand-built broken challenge through the CLI and the MCP server. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Every check tests a service that sells. Builders whose agent pays had nothing to test it against: a real paywall behaves, and the lying servers written for the 0.6.0 A/B were never committed. wasit serve runs a local x402 paywall in one of four modes. no-settle serves for any payment without settling or sending PAYMENT-RESPONSE; wrong-settlement reports success for a transaction that is not the payment (a random hash by default, or --settlement-tx); wrong-network asks for stellar:pubnet; overprice asks for one million USDC. It prints one line per request saying what the agent did and what a careful agent does instead. It never settles or forwards a payment, so nothing it receives can move funds. Each mode lies in one way only: its challenge is a well-formed x402 v2 challenge that Wasit's read checks pass, carrying the extra field the exact scheme on Stellar requires, so an agent that falls for it fell for the misbehaviour. Against wasit test, the settlement modes reproduce the 0.6.0 A/B exactly (X402-06 and X402-07 fail), and wrong-network gets the payment checks skipped with nothing sent. The CLI guide gains "Testing an agent that pays" (/docs/cli/serve). 17 new offline tests; 12 mutants, all killed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Every FAIL now carries its own fix, but a builder reading the docs before a run, or comparing two failures, had nowhere that collected them. The check catalogue gains a "Common failures and fixes" page: for each check, what the failure looks like, why, and what fixes it. It draws only on what is established: the hints in core, the divergence classes in the conformance findings, Findings 4 and 5 for MPP, and the 0.6.0 verification run. The CAIP-2 table lists Stellar's two networks, the x402 v2 spec's own Base and Solana examples, and BNB Smart Chain's EIP-155 chain ids (ethereum-lists/chains). No table row opens with a check id, so the site's check count and the catalogue test still see 13. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 1 of 7 of 0.7.0, which is on npm since 2026-10-08. The PRs follow the release branch's commit order and are merged with merge commits, so every commit keeps its hash.
What changes
X402-04andX402-05read every payment option, on any chain, and name the one at fault by its index.X402-05requires CAIP-2, with each namespace's own rules where its definition fixes them (stellar,eip155,solana).--network, MCPnetwork).X402-04checks every field the advertised x402 version requires, with its type.Fixline and aDocslink in the CLI,fixanddocsin--jsonand the MCP result.wasit serve: a local x402 paywall that misbehaves on purpose, to test an agent that pays.Commits
2bf26a7feat(core): x402 read checks on any chain, payment on the named networkb5c6cc5feat(core): every failure says what to change; X402-04 checks all fields3da6b5ffeat(cli): wasit serve, a paywall that misbehaves on purposec57c96adocs(checks): common failures and fixes, by checkVerification
Unit tests and the clean install run in CI. The full 0.7.0 run, every suite on every chain with each settlement read back, is in
docs/evidence/2026-10-08-0.7.0-verification-runs.md, part 2 (PR 7/7).🤖 Generated with Claude Code