Skip to content

0.7.0 (4/7): x402 payment checks on Solana devnet - #7

Merged
dzakwannajmi merged 3 commits into
mainfrom
0.7.0/4-solana-devnet
Oct 8, 2026
Merged

dzakwannajmi merged 3 commits into
mainfrom
0.7.0/4-solana-devnet

Conversation

@dzakwannajmi

Copy link
Copy Markdown
Collaborator

Part 4 of 7 of 0.7.0, which is on npm since 2026-10-08. The PRs follow the release branch's commit order and are merged with merge commits, so every commit keeps its hash.

What changes

  • The x402 payment checks pay on Solana devnet (solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1); the settlement is read from the confirmed transaction's token balances.
  • wasit serve on Solana devnet, and Solana in the network options.

Commits

  • 165e23c feat(core): pay Solana devnet targets
  • 7ea229f feat(cli): wasit serve on Solana devnet, and Solana in the network options
  • c079445 docs: Solana devnet in the x402 payment checks, and the evidence

Verification

Unit tests and the clean install run in CI. The Solana devnet runs are in docs/evidence/2026-10-05-solana-devnet-verification-run.md (folded into the per-date file in PR 7/7).

🤖 Generated with Claude Code

The payment checks X402-06..10 now also pay on Solana devnet
(solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1), through the official
@x402/svm client: the payer signs a transaction with one TransferChecked
to the payee's token account, and the sponsor named in extra.feePayer
signs as fee payer and submits it. A payer needs devnet USDC and no SOL.
The key is SVM_PRIVATE_KEY, base58 of the 64-byte keypair; a keypair
whose public half is not its seed's is refused before any payment.

X402-06 reads the settlement from the confirmed transaction's token
balances: exactly one transfer, of the advertised amount and mint, to an
account payTo owns, from this run's payer. A cited signature still
missing after 150 slots fails; an RPC that stops advancing gives no
verdict. X402-07 flips one byte of the payer's signature, the only one
present before the sponsor signs.

On Solana a payment's lifetime is its blockhash, which the SDK client
does not derive from maxTimeoutSeconds. So X402-10's expiry is now a
per-chain hook: Stellar and EVM keep the one-second lifetime and hold;
Solana builds on a blockhash 300 slots old, which the RPC confirms is no
longer valid, through the client's extra.recentBlockhash hint.

The block-counting wait moves from the EVM adapter to a shared module.
A Solana fixture (port 3007, needs SVM_PAYEE_ADDRESS) joins fixtures.sh
and run-all.sh. The root package.json overrides typescript so the repo's
TypeScript 7 satisfies @solana/kit 5's optional peer range of ^5.

Offline: 221 core tests; 13 mutants of the adapter's rules killed.
Against Wasit's own Solana fixture, read-only: X402-01..05 pass, the
challenge carrying the facilitator's feePayer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tions

`wasit serve --network solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1` poses
the same four modes on Solana devnet: the SDK's default devnet USDC (6
decimals), wrong-network asking for Solana mainnet, overprice asking for
one million USDC, wrong-settlement citing a random base58 signature. The
exact scheme needs extra.feePayer; serve names the payee, which the spec
allows (merchant-sponsored fees) and which needs no third party, since
nothing is ever submitted. Payee from --pay-to or SVM_PAYEE_ADDRESS.

`wasit test` and the MCP tool list Solana devnet among the networks the
payment checks pay on, and SVM_PRIVATE_KEY among the payer keys.

Against serve on devnet, with an unfunded throwaway payer: no-settle
fails X402-06..10, wrong-settlement fails X402-06 after the chain
advanced 152 slots without the cited signature, wrong-network skips the
payment checks with nothing sent. 63 CLI tests; 5 mutants killed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CHECKS.md describes how X402-06 to X402-10 pay and judge on Solana devnet:
settlement read from the confirmed transaction's token balances, the
payer's signature forged before the sponsor signs, expiry by a blockhash
the RPC confirms has expired. The CLI, MCP and configuration guides, the
CLI and core READMEs, the agent skill and the site's stack strip name
the network, SVM_PRIVATE_KEY and SVM_PAYEE_ADDRESS.

The evidence: against `wasit serve` on devnet the lying modes fail and a
mainnet request gets nothing sent; Wasit's own fixture passes 10/10, the
settlement read back independently with raw JSON-RPC (one
transferChecked of 10000, fee paid by the facilitator, payer at 0 SOL),
and the payer's history shows the refused payments moved nothing. The
other x402 fixtures pass 10/10 on the same build.

The core README notes the npm peer warnings that TypeScript 6 and 7
projects see from @solana/kit 5, measured: the install succeeds and core
runs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
wasit Ready Ready Preview Oct 8, 2026 6:48am UTC

@dzakwannajmi
dzakwannajmi merged commit dc1709a into main Oct 8, 2026
5 checks passed
@dzakwannajmi
dzakwannajmi deleted the 0.7.0/4-solana-devnet branch October 8, 2026 06:48

This branch was successfully deployed

1 active deployment
Preview — c0794458 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant