Skip to content

0.7.0 (1/7): x402 read checks on any chain, fix hints, wasit serve - #4

Merged
dzakwannajmi merged 4 commits into
mainfrom
0.7.0/1-read-checks-any-chain
Oct 8, 2026
Merged

dzakwannajmi merged 4 commits into
mainfrom
0.7.0/1-read-checks-any-chain

Conversation

@dzakwannajmi

Copy link
Copy Markdown
Collaborator

Part 1 of 7 of 0.7.0, which is on npm since 2026-10-08. The PRs follow the release branch's commit order and are merged with merge commits, so every commit keeps its hash.

What changes

  • X402-04 and X402-05 read every payment option, on any chain, and name the one at fault by its index. X402-05 requires CAIP-2, with each namespace's own rules where its definition fixes them (stellar, eip155, solana).
  • The payment checks pay only on the option for the network the run names (--network, MCP network).
  • X402-04 checks every field the advertised x402 version requires, with its type.
  • Every FAIL says what to change: a Fix line and a Docs link in the CLI, fix and docs in --json and the MCP result.
  • wasit serve: a local x402 paywall that misbehaves on purpose, to test an agent that pays.
  • The check catalogue gains "Common failures and fixes".

Commits

  • 2bf26a7 feat(core): x402 read checks on any chain, payment on the named network
  • b5c6cc5 feat(core): every failure says what to change; X402-04 checks all fields
  • 3da6b5f feat(cli): wasit serve, a paywall that misbehaves on purpose
  • c57c96a docs(checks): common failures and fixes, by check

Verification

Unit tests and the clean install run in CI. The full 0.7.0 run, every suite on every chain with each settlement read back, is in docs/evidence/2026-10-08-0.7.0-verification-runs.md, part 2 (PR 7/7).

🤖 Generated with Claude Code

X402-04 and X402-05 read only accepts[0], and X402-05 accepted only
stellar:testnet and stellar:pubnet. A conformant x402 service on another
chain failed it, and a challenge offering several networks was judged on
whichever came first.

Both checks now read every payment option and name a broken one by its
index. X402-05 requires CAIP-2, as x402 v2 does (spec 11.1), and applies
the rules each namespace's CAIP-2 definition fixes: stellar is testnet or
pubnet, eip155 a base-10 chain id, solana the first 32 base58 characters
of the genesis hash. A well-formed id in another namespace passes, and the
result says only the format was checked, since failing it would report
Wasit's lack of rules as the target's defect. The rules move to
x402/requirements.ts so they are tested without a network.

The payment checks pay only on the network the run names. x402Client
picks the first option it supports, which could be the other Stellar
network; a policy now filters to --network. A challenge with no option on
that network, or none in the exact scheme, skips X402-06/07 with the
networks it offers and sends nothing. An unsupported --network, or pubnet
without an RPC endpoint, stops at preflight instead of after paying with
no way to verify the settlement.

24 new offline tests, mutation-checked. Run against a local stand-in
offering Base Sepolia and Solana devnet (5/5 read-only, payment checks
skipped, nothing sent) and against the Stellar fixture (7/7, X402-06
settled on-chain).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A FAIL said what was wrong and left the fix to the reader. Builders new
to x402 then had to read the spec to find it. A FAIL now carries a fix
and a docs link, in the CLI's text and --json output and in the MCP
server's structuredContent (fix, docs).

Where a check can tell the cause, the fix is specific: eip155:0x14a34 is
told to write eip155:84532, a 200 on an unpaid request to put the payment
middleware in front of the route, a missing PAYMENT-RESPONSE what to
return. Otherwise the check's catalogue entry supplies a general fix, and
every entry now has one, so no catalogued check can fail without
guidance. Only a FAIL gets any: a skip or a no-verdict is not a defect.
Core gains fixFor(), catalogueEntry(), docsUrlFor() and an optional hint
on CheckResult; X402-07's verdict is split out so it is testable offline.

X402-04 checked three fields. x402 v2 requires six in every option
(scheme, network, amount, asset, payTo, maxTimeoutSeconds) and v1 eight;
it now checks the advertised version's list, and reports a field of the
wrong type as such rather than as missing. The official server SDK fills
every field, so services built with it are unaffected.

The CLI's payment warning now says it applies only when the target
offers an option on the run's network.

41 new offline tests; 18 mutants, all killed. Run against a hand-built
broken challenge through the CLI and the MCP server.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Every check tests a service that sells. Builders whose agent pays had
nothing to test it against: a real paywall behaves, and the lying servers
written for the 0.6.0 A/B were never committed.

wasit serve runs a local x402 paywall in one of four modes. no-settle
serves for any payment without settling or sending PAYMENT-RESPONSE;
wrong-settlement reports success for a transaction that is not the
payment (a random hash by default, or --settlement-tx); wrong-network
asks for stellar:pubnet; overprice asks for one million USDC. It prints
one line per request saying what the agent did and what a careful agent
does instead. It never settles or forwards a payment, so nothing it
receives can move funds.

Each mode lies in one way only: its challenge is a well-formed x402 v2
challenge that Wasit's read checks pass, carrying the extra field the
exact scheme on Stellar requires, so an agent that falls for it fell for
the misbehaviour. Against wasit test, the settlement modes reproduce the
0.6.0 A/B exactly (X402-06 and X402-07 fail), and wrong-network gets the
payment checks skipped with nothing sent.

The CLI guide gains "Testing an agent that pays" (/docs/cli/serve).
17 new offline tests; 12 mutants, all killed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Every FAIL now carries its own fix, but a builder reading the docs before
a run, or comparing two failures, had nowhere that collected them. The
check catalogue gains a "Common failures and fixes" page: for each check,
what the failure looks like, why, and what fixes it.

It draws only on what is established: the hints in core, the divergence
classes in the conformance findings, Findings 4 and 5 for MPP, and the
0.6.0 verification run. The CAIP-2 table lists Stellar's two networks,
the x402 v2 spec's own Base and Solana examples, and BNB Smart Chain's
EIP-155 chain ids (ethereum-lists/chains). No table row opens with a
check id, so the site's check count and the catalogue test still see 13.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
wasit Ready Ready Preview Oct 8, 2026 6:34am UTC

@dzakwannajmi
dzakwannajmi merged commit ec137ba into main Oct 8, 2026
5 checks passed
@dzakwannajmi
dzakwannajmi deleted the 0.7.0/1-read-checks-any-chain branch October 8, 2026 06:42

This branch was successfully deployed

1 active deployment
Preview — c57c96ad Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant