Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1043 commits
Select commit Hold shift + click to select a range
d3d4f2b
fix: propagate batch settlement storage errors (#2917)
wnjoon Jul 22, 2026
6f544b4
fix(go): return invalid payload for malformed payment signature (#2907)
wnjoon Jul 22, 2026
b7bfa69
Limit s buildercode (#2912)
phdargen Jul 22, 2026
ec4ef24
Document MAX_SERVICE_CODES cap for builder-code extension (#2923)
mintlify[bot] Jul 22, 2026
27fadeb
fix(fetch): preserve Request body during recovery (#2900)
realmehmetali Jul 22, 2026
328bf1e
fix(python): preserve streaming bodies on payment retry (#2899)
realmehmetali Jul 22, 2026
a0b5ba1
docs: add x402-list.com to ecosystem directories (#2925)
mcccsm Jul 22, 2026
21a2e48
add slack link (#2926)
phdargen Jul 22, 2026
bc22b7d
docs(svm): add `upto` SVM scheme specification (#2697)
lgalabru Jul 22, 2026
e5c5051
fix(evm): batch-settlement honors caller-supplied asset on networks o…
fretchen Jul 23, 2026
69652a6
docs+spec: clarify signer authorization in offer-receipt extension (#…
alftom Jul 23, 2026
1e9f650
feat(svm): server-provided recent blockhash in the exact 402 challeng…
lgalabru Jul 23, 2026
7915362
feat(go/svm): support server-provided recent blockhash (#2731)
wnjoon Jul 23, 2026
32464a2
Fix: SVM SIWx small-order Ed25519 verification (#2933)
phdargen Jul 23, 2026
61349de
Fix: Algorand CAIP-2 network IDs (#2931)
phdargen Jul 23, 2026
d027b57
feat: add Solana support to cloudfront-lambda-edge example (#2944)
notorious-d-e-v Jul 24, 2026
8e29d2e
specs(exact): propose Starknet exact scheme for x402 v2 (spec-only) (…
adipundir Jul 24, 2026
8982979
examples(python): demonstrate service metadata in the bazaar server e…
rascal-3 Jul 24, 2026
fab6795
Add NEAR x402 Facilitator (facilitators table + ecosystem partner ent…
mikedotexe Jul 24, 2026
c932510
docs: update clone URL to x402-foundation/x402 (#2949)
notorious-d-e-v Jul 24, 2026
13fe5cd
fix py fmt (#2946)
phdargen Jul 24, 2026
90688e5
Adds bazaar indexing troubleshooting guide (#2947)
phdargen Jul 24, 2026
59bbc51
docs: update NEAR facilitator for Base support (#2960)
mikedotexe Jul 27, 2026
4453a92
Fix silent auth drop when createAuthHeaders returns a flat object (#2…
cristianizzo Jul 27, 2026
04c94b6
feat(py): server-provided recent blockhash in the exact 402 challenge…
phdargen Jul 27, 2026
6d08ffa
chore: version typescript packages (#2969)
phdargen Jul 27, 2026
6437935
chore: version python package (#2970)
phdargen Jul 27, 2026
895f350
chore(go): release (#2971)
phdargen Jul 27, 2026
183b270
fix: add request timeouts to HTTPFacilitatorClient and guard eager in…
notorious-d-e-v Jul 29, 2026
e335d4f
fix(ts/go/py): always add client buildercodes (#2994)
phdargen Jul 30, 2026
d2e1275
fix(go/http): add Cache-Control: no-store to 402 responses (#2956)
Sertug17 Jul 30, 2026
ee1b148
fix(ts/py): add cache control, no-store for 402, private for 200 (#2990)
phdargen Jul 30, 2026
17fc989
fix: verify eip3009 transfer event in go (#2727)
wnjoon Aug 1, 2026
7c3d63e
docs: fix DEFAULT_ASSETS.md examples and stale file references (#3024)
GigaHierz Aug 3, 2026
242d6e9
feat(evm): add Celo mainnet (42220) and Celo Sepolia (11142220) defau…
GigaHierz Aug 3, 2026
03bc083
Update docs/core-concepts/network-and-token-support.mdx (#3026)
mintlify[bot] Aug 3, 2026
667bfec
fix(go): propagate payment response hook errors (#3022)
256dino Aug 3, 2026
e805616
fix(ts/go/py): merge server and client builder-code s arrays (#3027)
ethanoroshiba Aug 4, 2026
db9dabd
feat(evm): add Flare mainnet (14) default stablecoin (#3031)
whawk46 Aug 4, 2026
c427425
fix(mcp): re-approve before signing corrective 402 recovery payment (…
SashaMIT Aug 4, 2026
5192e50
fix: wildcard line terminator bypass (#3036)
CarsonRoscoe Aug 4, 2026
3c63262
fix(python): verify Transfer event after exact/eip3009 settle (#3032)
SashaMIT Aug 4, 2026
08e84ab
fix(mcp): plumb spend policies through createx402MCPClient factory (#…
SashaMIT Aug 4, 2026
49a3c7e
Update docs/guides/mcp-server-with-x402.md (#3038)
mintlify[bot] Aug 4, 2026
dea7937
fix(evm): verify Transfer event in receipt after exact/eip3009 settle…
Mameta29 Aug 4, 2026
6b04d5e
fix: reject external / in bazaar discovery schema (SSRF) (#3039)
CarsonRoscoe Aug 4, 2026
1fd1a6d
Update docs/extensions/bazaar.mdx (#3040)
mintlify[bot] Aug 4, 2026
5e20460
chore: version typescript packages  (#3041)
phdargen Aug 4, 2026
a4e23be
chore: version python package  (#3042)
phdargen Aug 4, 2026
34cb6bd
chore(go): release (#3043)
phdargen Aug 4, 2026
158adb0
fix: match payment-gated routes on the escaped request path (#3044)
CarsonRoscoe Aug 6, 2026
c7e0ac8
fix(python): match wildcard routes containing a line feed (#3055)
saneGuy Aug 7, 2026
8bef6f7
Specs(exact): propose Canton exact scheme for x402 (spec-only) (#2634)
Denend Aug 7, 2026
db5da2e
feat(ts): payment flow handlers (#3053)
phdargen Aug 8, 2026
1fec3aa
Document payment flows and settle phases (#3088)
mintlify[bot] Aug 8, 2026
112c1e3
fix(go): compile route patterns with (?s) so wildcards match line fee…
hung-yueh Aug 9, 2026
76bda78
fix(evm): correct Monad USDC EIP-712 domain name to "USDC" (#3102) (#…
chopmob-cloud Aug 10, 2026
2c83d1c
Update docs/core-concepts/network-and-token-support.mdx (#3108)
mintlify[bot] Aug 10, 2026
e6f354c
label networks in prs (#3090)
phdargen Aug 10, 2026
1601942
fix(ts/py): path normalization (#3073)
phdargen Aug 10, 2026
1d15062
E2e refactor (#2976)
phdargen Aug 10, 2026
927fea8
feat(svm): make facilitator transaction limits operator-configurable …
notorious-d-e-v Aug 11, 2026
37412e7
fix(ts): escape backslashes in normalizePath instead of folding them …
CarsonRoscoe Aug 11, 2026
0b79a6a
Update docs/schemes/exact.mdx (#3127)
mintlify[bot] Aug 11, 2026
a52417e
chore(go): release (#3130)
phdargen Aug 11, 2026
a98c19d
chore: version python package  (#3129)
phdargen Aug 11, 2026
c8247c4
chore: version typescript packages  (#3128)
phdargen Aug 11, 2026
16a23d0
fix(ts): require TransferChecked discriminator in svm exact (#3132)
phdargen Aug 12, 2026
79b6259
feat(ts): svm upto paymentflow (#3094)
phdargen Aug 12, 2026
9a9d4f9
Document upto SVM payment scheme (#3135)
mintlify[bot] Aug 12, 2026
f62a9fa
feat(go): payment flows for go sdk (#3115)
phdargen Aug 12, 2026
74038ba
Update docs/advanced-concepts/lifecycle-hooks.mdx (#3139)
mintlify[bot] Aug 13, 2026
c2612d3
fix(ts): bind SIWX client challenge to the request origin (#3133)
phdargen Aug 13, 2026
50d2ec6
Document SIWX origin binding: required requestUrl argument (#3143)
mintlify[bot] Aug 13, 2026
4f58723
feat(TS): spend controls (#3124)
phdargen Aug 13, 2026
2d23a16
Document spendControls client safety feature (#3147)
mintlify[bot] Aug 13, 2026
a1af647
fix(evm): correct Monad USDC v1 EIP-712 domain name to "USDC" (#3153)
Im-Madhur-Gupta Aug 14, 2026
167a828
feat(ts): add ComputeBudget instructions to svm upto transactions (#3…
notorious-d-e-v Aug 14, 2026
f12f879
docs(migration): use real Solana genesis-hash CAIP-2 ids (#3179)
soulee-dev Aug 17, 2026
ab1a31a
fix(ts): handle missing accepted requirements (#3180)
JasonColapietro Aug 17, 2026
8c308ce
feat(svm): allow injecting an RPC client into the upto facilitator (#…
notorious-d-e-v Aug 17, 2026
2a706b2
feat: add solana upto to go sdk (+ typescript parity fixes) (#3141)
CarsonRoscoe Aug 17, 2026
6dba93e
feat: add settlement pending state (#3083)
CarsonRoscoe Aug 17, 2026
e69d9c8
Go SDK now supports upto SVM scheme (#3190)
mintlify[bot] Aug 18, 2026
67ca554
Update docs/core-concepts/facilitator.md (#3191)
mintlify[bot] Aug 18, 2026
656437e
feat(py): add spend controls (#3154)
phdargen Aug 18, 2026
b4db321
Update docs/getting-started/quickstart-for-buyers.mdx (#3195)
mintlify[bot] Aug 18, 2026
5246387
feat(go): spend controls (#3156)
phdargen Aug 18, 2026
3fc84cc
Document Go spend controls support (#3196)
mintlify[bot] Aug 18, 2026
37862b2
py port (#3192)
phdargen Aug 18, 2026
b0a4c0a
go port (#3193)
phdargen Aug 18, 2026
ddf98ee
Update Go SDK feature parity for onPaymentRequired hook (#3198)
mintlify[bot] Aug 18, 2026
17d319f
chore: version typescript packages  (#3200)
phdargen Aug 18, 2026
2b92f72
chore: version python package  (#3202)
phdargen Aug 18, 2026
270a08b
chore(go): release (#3201)
phdargen Aug 18, 2026
75b519d
bump gh-action-pypi-publish (#3204)
phdargen Aug 18, 2026
7d5363a
docs: add fireblocks facilitator (#3194)
matthew1809 Aug 20, 2026
292e849
docs(svm): add `batch-settlement` SVM scheme specification (#2698)
lgalabru Aug 21, 2026
230e6a9
Update docs/schemes/batch-settlement.mdx (#3222)
mintlify[bot] Aug 21, 2026
2f65c79
docs(specs): refresh the contributing guide and impl template (#3235)
zjzJoez Aug 23, 2026
6557149
feat(evm): add Sei default stablecoins (#3227)
alexander-sei Aug 24, 2026
692c7dc
docs(ts): align contributor prerequisites with workspace (#3254)
Moyuin-aka Aug 24, 2026
8707ab7
fix(mcp-ts): handle facilitator failure before resource delivery (#3246)
phdargen Aug 24, 2026
f41d9be
fix(ts/go/py): Validate batch settlement response (#3251)
phdargen Aug 24, 2026
f8dfe4d
feat(py): payment flow (#3247)
phdargen Aug 24, 2026
06c028e
Python payment flow handlers: phase examples & MCP hook parity (#3255)
mintlify[bot] Aug 24, 2026
ec0f71e
fix(svm): validate smart wallet limits (#3122)
notorious-d-e-v Aug 24, 2026
121c98f
fix(go/py): align default asset declaration with ts (#3241)
phdargen Aug 24, 2026
aeb0fdd
Update docs/core-concepts/network-and-token-support.mdx (#3257)
mintlify[bot] Aug 24, 2026
82ba36f
feat: settlement pending auto-recovery (#3214)
CarsonRoscoe Aug 25, 2026
bde6fe5
Update docs/core-concepts/facilitator.md (#3259)
mintlify[bot] Aug 25, 2026
f8a3682
Auth-capture spec update: v1.1 (#3197)
phdargen Aug 25, 2026
bb46ffc
feat(ts/go): upfront paymentflow for exact mechanism (#3240)
phdargen Aug 25, 2026
cdfa491
Document upfront payment flow for exact scheme (#3267)
mintlify[bot] Aug 25, 2026
01b0a68
feat(Ts/Go): avoid fee-payer signing svm exact /verify + Go smart wal…
phdargen Aug 26, 2026
b1a88ef
Update docs/schemes/exact.mdx (#3272)
mintlify[bot] Aug 26, 2026
ab1b418
feat(evm): add Upto-only deployment entrypoint (#3199)
huaweigu Aug 26, 2026
b32b564
fix: upto proxy canonical address (#3276)
CarsonRoscoe Aug 26, 2026
acaa904
fix(ts/go): refactor svm upto rpc config (#3274)
phdargen Aug 26, 2026
8468e3a
Fix SVM upto facilitator RPC configuration examples (#3277)
mintlify[bot] Aug 26, 2026
44f6b17
feat(ts/go): auth-capture client v1.1 (#3283)
phdargen Aug 27, 2026
f257584
chore: version typescript packages  (#3287)
phdargen Aug 27, 2026
d22ae96
chore: version python package  (#3288)
phdargen Aug 27, 2026
8ac521c
chore(go): release (#3289)
phdargen Aug 27, 2026
b703a0e
Update docs/sdk-features.md (#3286)
mintlify[bot] Aug 27, 2026
e398a9e
disable spend controls in stellar integration test (#3290)
marcelosalloum Aug 28, 2026
dd25875
fix(e2e): scope EVM/SVM client signer derivation to selected families…
Eras256 Aug 31, 2026
cd43052
fix(go): use maxTimeoutSeconds for EIP-3009 validBefore (#3282)
Tehsapper Aug 31, 2026
6838428
feat(python): make facilitator gas limit configurable (#3233)
nniiovoo Aug 31, 2026
240492e
docs(specs): correct v2 §8 discovery fields to match the wire format …
onlyarche Aug 31, 2026
675bb5d
fix(go): prevent settlement override percent overflow (#2962)
wnjoon Aug 31, 2026
18ecba0
e2e: add script to check wallet balances (#3297)
phdargen Aug 31, 2026
87a19a7
Fix e2e warnings (#3308)
phdargen Aug 31, 2026
d2bc9ba
fix: improve facilitator evm latency (#3312)
CarsonRoscoe Aug 31, 2026
e187dda
fix(py): add server-only extension_responses sidechannel (#3306)
phdargen Aug 31, 2026
a3c6004
validate builder-code app attribution on (#3313)
phdargen Aug 31, 2026
a140d2b
fix #3019 (#3309)
phdargen Aug 31, 2026
138d415
Document builder-code `a` field validation and v1 behavior (#3315)
mintlify[bot] Aug 31, 2026
68e529b
Update withX402 docs for keyed route patterns (#3316)
mintlify[bot] Aug 31, 2026
1bc2ae8
fix(core): server-only extensionResponses sidechannel (#3278)
Bartok9 Aug 31, 2026
94f9951
fix(e2e): svm smart wallet config (#3319)
phdargen Aug 31, 2026
bbcb974
fix(core): throw when no scheme server is registered (#3051)
VedantAnand17 Sep 1, 2026
71dd629
docs(ts/mcp): update README for current API and payment shapes (#3089)
Xeift Sep 1, 2026
0344bdf
fix(e2e): HTTP-only swig-setup RPC with devnet fallback (#3327)
phdargen Sep 1, 2026
fed6a04
fix: replace crypto dependency with @noble/hashes in @x402/svm (#3335)
CarsonRoscoe Sep 2, 2026
6c1a4b2
fix(go): validate builder-code app attribution (#3302)
wnjoon Sep 2, 2026
b0febf2
docs: list FTP Canton Facilitator (#3243)
nicky2pc Sep 2, 2026
eb0d899
fix(go): return EXTENSION-RESPONSES on verify and settle (#3301)
wnjoon Sep 2, 2026
23173ac
Expand asset transfer methods with `upfront` payment flows, family sp…
IkerAlus Sep 2, 2026
7488a46
fix(stellar): accept CAP-71 V2 address credentials for Protocol 28 (#…
jeesunikim Sep 2, 2026
626df07
fix(stellar): include feeBumpSigner in facilitator-safety checks (#3336)
Eras256 Sep 3, 2026
78412bc
fix(go): bound HTTP response body reads (#2973)
wnjoon Sep 3, 2026
3e9631d
fix(python): validate builder-code app attribution on v2 (#3320)
PhilBot402 Sep 3, 2026
4999dc6
fix(ts,go): update auth-capture v1.1 contracts to canonical deploymen…
phdargen Sep 3, 2026
299b9bc
feat(ts): add delegated receiver authorizer for SVM upto (#3346)
phdargen Sep 3, 2026
15f7192
feat(go): add delegated receiver authorizer for SVM upto (#3347)
PhilBot402 Sep 3, 2026
5bbf418
Update docs/schemes/upto.mdx (#3356)
mintlify[bot] Sep 3, 2026
85f2d90
chore: version typescript packages  (#3357)
phdargen Sep 3, 2026
23c7a97
chore: version python package  (#3358)
phdargen Sep 3, 2026
0369831
feat: optimize go facilitator SDK - EVM and SVM (#3355)
CarsonRoscoe Sep 3, 2026
2cc7e9a
chore(go): release (#3359)
phdargen Sep 4, 2026
5df361d
fix(java): buffer response body until settlement succeeds (#3074)
rileybuilds Sep 4, 2026
14e9c2a
feat(svm): use linear backoff for upto channel re-reads (#3367)
PhilBot402 Sep 5, 2026
20e525c
perf(evm): reuse verify ERC-6492 payer classification in settle (#3365)
PhilBot402 Sep 5, 2026
1d289fc
fix(python): reuse verify ERC-6492 payer code in settle (#3366)
PhilBot402 Sep 5, 2026
560fdb0
Update docs/schemes/upto.mdx (#3380)
mintlify[bot] Sep 5, 2026
0c04a84
fix(python): exit on fatal HTTP adapter initialize errors (#3364)
PhilBot402 Sep 5, 2026
1ef4606
docs: add x402aff to third-party extensions (#3395)
aaronjmars Sep 7, 2026
48fac89
fix(ts): buffer hono/next settlement replies and raise facilitator HT…
phdargen Sep 7, 2026
e2bbe93
improve e2e breakdown (#3382)
phdargen Sep 7, 2026
76fe973
feat(ts): Add optional extra.minDeposit hint for EVM batch-settlement…
phdargen Sep 7, 2026
102e5d6
Document minDeposit hint for batch-settlement scheme (#3398)
mintlify[bot] Sep 7, 2026
241df66
Enforce file-size and complexity limits with coverage thresholds (#3393)
phdargen Sep 7, 2026
95255a6
fix(hono): settlement-failure tests construct a real Response (#3402)
saneGuy Sep 8, 2026
92d717b
fix(python): default HTTPFacilitatorClient timeout to 90s (#3409)
PhilBot402 Sep 8, 2026
4e15690
fix(go): raise HTTPFacilitatorClient default timeout to 90s (#3408)
PhilBot402 Sep 8, 2026
8ae5ff6
fix(extensions): decode routeTemplate to a fixed point before travers…
ygd58 Sep 9, 2026
42ee42b
feat: add Cardano implementation for Typescript package (#2537)
fabianbormann Sep 9, 2026
6777eaa
Document Cardano exact scheme support (#3429)
mintlify[bot] Sep 9, 2026
fdeda56
feat(mcp,ts): use accept's maxTimeoutSeconds for tool timeout + Carda…
phdargen Sep 9, 2026
3c2ddfb
fix(svm): split upto delegated-auth store errors from unauthenticated…
phdargen Sep 9, 2026
273ecef
fix(python): decode routeTemplate to a fixed point before traversal c…
PhilBot402 Sep 11, 2026
04c750e
fix(go): decode routeTemplate to a fixed point before traversal check…
PhilBot402 Sep 11, 2026
4fb5d07
feat(evm): add Celo USDT and USAT as default assets; link Celo facili…
GigaHierz Sep 15, 2026
3a6605e
Add Celo USDT and USAT token support to docs (#3477)
mintlify[bot] Sep 15, 2026
b444ce6
fix(next): preserve request body when reading through the adapter (#3…
viviviviviid Sep 15, 2026
bb05610
fix(next): preserve leading empty query parameter values (#3456)
sunruize93-cmyk Sep 15, 2026
ba7fc20
fix(hono): preserve repeated query parameter values (#3455)
sunruize93-cmyk Sep 15, 2026
cbc4593
fix(axios): preserve base paths and params in payment hook URLs (#3454)
sunruize93-cmyk Sep 15, 2026
909b4fa
feat(python): add extra.minDeposit hint for EVM batch-settlement (#3480)
PhilBot402 Sep 15, 2026
2a3ab7a
fix(python): size MCP tool-call timeouts from accept maxTimeoutSecond…
PhilBot402 Sep 15, 2026
f59930b
fix(mcp,go): size tool-call timeouts from accept maxTimeoutSeconds (#…
PhilBot402 Sep 15, 2026
812fbaf
update codeowners (#3434)
phdargen Sep 15, 2026
c10d3bb
feat(evm): cache positive asset-contract checks (#3363)
PhilBot402 Sep 15, 2026
fab6ea8
feat(python): cache positive EVM asset-contract checks (#3362)
PhilBot402 Sep 15, 2026
f4c3f61
feat(ts): add Casper TypeScript SDK (#2877)
davidatwhiletrue Sep 15, 2026
6b93027
Add Casper TypeScript SDK setup docs to exact scheme (#3484)
mintlify[bot] Sep 15, 2026
087872f
prepare casper release (#3485)
phdargen Sep 15, 2026
78ef8f0
fix(mcp): cap tool-call timeouts (default 10m) (#3481)
phdargen Sep 15, 2026
a7ea804
Document MCP client timeout cap option (#3486)
mintlify[bot] Sep 15, 2026
57b4ef4
fix(MCP,Go): client dispatch HandlePaymentResponse after paid tool ca…
phdargen Sep 15, 2026
978b3ce
Pull request for mintlify/docs-update-1789494158578 (#3489)
mintlify[bot] Sep 15, 2026
cd10916
chore: version python package  (#3488)
phdargen Sep 15, 2026
dcfc16a
chore(go): release (#3490)
phdargen Sep 15, 2026
9b37f37
chore: version typescript packages  (#3487)
phdargen Sep 15, 2026
cf07e96
feat(go): add extra.minDeposit hint for EVM batch-settlement (#3410)
PhilBot402 Sep 16, 2026
8e0d718
fix(go): update MCP hook test mock for PaymentPayloadContext (#3492)
PhilBot402 Sep 16, 2026
1944976
docs(mcp): check paymentResponse before logging a settled payment (#3…
loveaihq Sep 16, 2026
c608a71
fix(python): snapshot MCP 402 accepts before enrichers (#3495)
PhilBot402 Sep 16, 2026
165ff37
fix(python-mcp): expose bare InvalidReason on FastMCP 402s (#3494)
PhilBot402 Sep 16, 2026
c8c71f2
fix(stellar): make the exact facilitator inclusion fee configurable (…
DiegoPoveda01 Sep 17, 2026
c9160a6
docs: mark T54 XRPL facilitator as production-grade (#3526)
shrey32 Sep 20, 2026
68b6fba
docs: mark PayAI Facilitator as production-grade (#3539)
notorious-d-e-v Sep 21, 2026
6323ec7
fix(python): close literal-route bypass via percent-encoded path sepa…
CarsonRoscoe Sep 21, 2026
59f1347
fix(evm): reject malformed CAIP-2 network identifiers in getEvmChainI…
HereForTheTechNFT Sep 21, 2026
7496533
feat: expand x402.org/protected routes (#3522)
CarsonRoscoe Sep 21, 2026
5d3a2b2
fix(ts): match HTTP routes on escaped and decoded paths (#3542)
PhilBot402 Sep 22, 2026
279f12c
fix(go): match HTTP routes on escaped and decoded paths (#3543)
PhilBot402 Sep 22, 2026
1f3ccfc
chore: harden verify-package-exports for @x402 releases (#3550)
phdargen Sep 22, 2026
5976943
chore: version typescript packages  (#3553)
phdargen Sep 22, 2026
74ee0f5
chore(go): release (#3555)
phdargen Sep 22, 2026
71eb9a5
chore: version python package  (#3554)
phdargen Sep 22, 2026
d6d2c58
specs(exact): correct Starknet settlement rules (follow-up to #2849) …
adipundir Sep 23, 2026
6fe0d4b
Specify exact Lightning on lnbtc (#2861)
benthecarman Sep 23, 2026
80c2fa4
docs(contracts): record Arc proxy deployments (#3523)
huaweigu Sep 23, 2026
8228bd6
spec(exact-hedera): add transferExecutor asset transfer method (#3205)
kierzniak Sep 24, 2026
0cb1a1f
fix: x402 site eip6492 pricing (#3565)
CarsonRoscoe Sep 24, 2026
75e12f0
fix(python): cap solana below 0.40 in the svm extra (#3573)
JulienKervarrec Sep 25, 2026
600131c
feat(svm): add batch settlement scheme (#3164)
lgalabru Sep 25, 2026
4fcf836
Pull request for mintlify/docs-update-1790356082356 (#3584)
mintlify[bot] Sep 25, 2026
9db8584
docs: link the merged Bitcoin Lightning exact spec (#3578)
Bartok9 Sep 27, 2026
5b7078e
fix(e2e): stop the mechanisms catalog from importing a built package …
PhilBot402 Sep 27, 2026
02e80f3
fix(e2e): retry public Solana devnet 429s in swig setup (#3595)
PhilBot402 Sep 27, 2026
dd89698
feat(evm): add Arc default stablecoins (#3590)
NotMcAfee Sep 28, 2026
5e97d9a
docs: fix broken relative links in guides, examples and specs (#3596)
JulienKervarrec Sep 28, 2026
c84154b
perf(svm): cache derived payment-channel PDAs (#3601)
notorious-d-e-v Sep 28, 2026
a9955ae
feat(evm): add Monad testnet USDC default asset (#3570)
phdargen Sep 28, 2026
5eee1e3
docs: show EVM and Solana in middleware README examples (#3619)
notorious-d-e-v Sep 29, 2026
a349e7f
feat(svm): Go batch-settlement, unified PaymentChannelStorage, and pa…
phdargen Sep 29, 2026
da8c2f4
chore: version python package  (#3628)
phdargen Sep 29, 2026
ced627c
chore: version typescript packages  (#3627)
phdargen Sep 29, 2026
9320504
Pull request for mintlify/docs-update-1790707394690 (#3626)
mintlify[bot] Sep 29, 2026
6b6ee91
chore(go): release (#3629)
phdargen Sep 29, 2026
46beddd
fix(svm): restore server-signed channel refunds (#3637)
notorious-d-e-v Oct 2, 2026
43aaecb
feat(paywall): add rpcUrls config for the SVM paywall (#3599)
notorious-d-e-v Oct 2, 2026
03b3919
fix(svm): restore server-signed channel refunds after restart (#3664)
PhilBot402 Oct 2, 2026
e213c63
fix: svm upto example (#3639)
phdargen Oct 2, 2026
606ced0
fix: fastify path bypass (#3577)
CarsonRoscoe Oct 2, 2026
8355435
fix: derive batch-settlement charge baseline from onchain totalClaime…
CarsonRoscoe Oct 2, 2026
751590a
fix(svm): enforce settled + amount minimum at batch facilitator verif…
phdargen Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
34 changes: 34 additions & 0 deletions .agents/skills/authoring-specs/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
---
name: authoring-specs
description: Guidelines for authoring x402 specification files. Use when writing or proposing a new x402 spec, such as a per-network scheme spec (scheme_<name>_<chain>.md).
---

# Authoring x402 specs

Guidance for writing x402 specification files under `specs/`. Use RFC-2119 keywords for normative statements (MUST / MUST NOT, SHOULD / SHOULD NOT, MAY).

## General rules

These apply to every spec type (scheme, extension). The references below add type-specific detail.

### Naming

- Name schemes and extensions in lowercase, hyphen-separated kebab-case (e.g. `batch-settlement`, `offer-receipt`), never camelCase.

### Protocol version, networks, and units

- Target protocol v2 only: `x402Version: 2`, the `amount` field (not v1's `maxAmount`), and the `PAYMENT-REQUIRED` / `PAYMENT-SIGNATURE` / `PAYMENT-RESPONSE` headers (not v1's `X-PAYMENT` / `X-PAYMENT-RESPONSE`). See the [v1 to v2 migration guide](../../../docs/guides/migration-v1-to-v2.mdx).
- Use canonical CAIP-2 network notation (e.g. `eip155:84532`, not `base-sepolia`).
- Use atomic units for all amounts.

### Wire format

- Be transport agnostic: specify message contents, not how a particular transport carries them.
- Reference core types (`PaymentRequirements`, `PaymentPayload`, `SettlementResponse`) from [`x402-specification-v2.md`](../../../specs/x402-specification-v2.md).
- Every field a spec defines on the wire must be consumed by a downstream role. Do not include human-readable or otherwise purely informational fields.
- Reuse field names, patterns, and conventions established by existing specs instead of coining new ones.

## References

- New network scheme spec (`scheme_<name>_<chain>.md`): see [references/new-network-scheme-spec.md](references/new-network-scheme-spec.md).
- New extension spec: to be added.
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# New network scheme spec

Checklist for authoring a new per-network scheme spec file (`scheme_<name>_<chain>.md`). Follow the [general spec rules](../SKILL.md) as well.

## Spec contents

- Scheme-specific information (e.g. in `PaymentRequired`) goes in `extra`, not in `extensions` or at the top level.
- Define any scheme-specific `extra` fields (optional/required, with description), and show them in `PaymentRequired`, `PaymentPayload`, and `SettlementResponse` messages or `supported/` examples.
- Every field placed in `PaymentRequired.extra` must be consumed by the client to construct the payment or by the facilitator to verify or settle it; do not include human-readable or otherwise purely informational fields.

## Compliance and conventions

- Comply with the network-agnostic scheme definition (e.g. `scheme_exact_<network>.md` complies with [`scheme_exact.md`](../../../../specs/schemes/exact/scheme_exact.md)).
- Reuse field names already established by existing schemes instead of coining new ones. For example, when the scheme must name the account that sponsors network fees (typically the facilitator), use `extra.feePayer` as in [`scheme_exact_svm.md`](../../../../specs/schemes/exact/scheme_exact_svm.md); when the scheme offers more than one payload format, use `extra.assetTransferMethod` to select among them as in [`scheme_exact_evm.md`](../../../../specs/schemes/exact/scheme_exact_evm.md).

## Fee sponsorship and infrastructure

- Fee sponsorship is strongly preferred; clients and servers should not need to pay gas or hold the native token.
- The server should not need an RPC; the client may use an RPC; a facilitator RPC can be considered a given.

## Statelessness

- Stateless design is strongly preferred for client and server, and especially the facilitator. A short-lived cache is acceptable but needs to be well justified (see the duplicate-settlement mitigation in [`scheme_exact_svm.md`](../../../../specs/schemes/exact/scheme_exact_svm.md#duplicate-settlement-mitigation-recommended)). Persistent storage warrants discussion with maintainers.

## Nonces

- Sequential nonces are strongly discouraged. They effectively lock the client account until the server route handler completes and the transaction settles, which may take several minutes (bounded only by `maxTimeoutSeconds`, on which the protocol enforces no upper limit). If the client submits another transaction from that account between verification and settlement, the nonce is consumed, settlement fails, and the work the server already performed is wasted.

## Verification and settlement

- Do not introduce new facilitator endpoints beyond `verify/`, `settle/`, and `supported/`. A scheme must express all facilitator interactions through these existing endpoints.
- Use transaction simulation, not only structural payload checks, to confirm the transaction would actually succeed onchain. If that is not possible, at least targeted checks of onchain state MUST be done (e.g. sufficient client token balance, nonce unconsumed).
- Verify should provide the strongest possible guarantee that settlement will succeed. If settle fails, the client does NOT get access to the resource; but if verify succeeded, the server did unnecessary work, wasting resources (compute). This is a server protection.
- The facilitator must confirm transaction success onchain before returning success to the server.
- The facilitator must protect its own funds and bound its fee exposure. Its signature must authorize only the network fee: the facilitator must not appear as the authority, source, or sender of any value-moving instruction (fee-payer isolation), so it cannot be induced to transfer its own funds. It must also cap the fees it pays against client-controlled parameters (e.g. explicit gas limits, compute-unit and priority-fee caps), so a client cannot inflate them.

## Trust model

- The client must treat all server-provided fields as untrusted and must not rely on a server value for anything it can determine authoritatively itself. For example, if a scheme placed token `decimals` in `extra` and the client trusted it, a misconfigured or malicious server could report a wrong value, causing the client to compute too large an atomic `amount` and overpay; the client must instead read `decimals` (and similar token metadata) from onchain state.
- The server and facilitator must consider the client payload untrusted.
- The client should never interact with the facilitator directly, always via the server as proxy.

## Account requirements

- Enumerate every account precondition that must hold before a payment can be verified and settled, naming the responsible role (client, server, or facilitator). Examples: a minimum native balance for rent or fees, an asset trustline or token association / opt-in, and account or associated-token-account creation.
91 changes: 91 additions & 0 deletions .agents/skills/contributing/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
---
name: contributing
description: Guidelines and conventions for contributing to the x402 codebase. Use when preparing a PR to the upstream x402-foundation/x402 repository such as fixing a bug or Issue, implementing a new feature, adding a mechanism/scheme or extension.
---

# Contributing to x402

## Reuse before writing new code

- Before writing anything, check in order whether the standard library (TS: ECMAScript and Node.js built-ins like `node:crypto`; Python: the stdlib; Go: packages like `net/http`, `encoding/json`, `crypto`), a native platform feature, or an already-installed dependency already does it; if so, use it.
- Always reuse shared and core utilities.
- No new dependencies if it can be avoided.

## Keep changes minimal

- Address a single issue per contribution, not multiple.
- Targeted edits, minimal diff, atomic commits.
- No abstractions or boilerplate that were not explicitly requested.
- No edits to legacy/v1 code; it is effectively frozen (security patches only). This includes the paths `typescript/packages/legacy/`, `go/legacy`, `python/legacy` and the `java/` SDK.

## Code style

- Write clean, readable code (e.g. prefer guard clauses over nested conditionals, use descriptive names and small, single-purpose functions).
- Strong typing, avoid any weak types (`any`, `unknown`, and their equivalents in other languages). Research the codebase to find the correct type, reuse existing type definitions rather than redeclaring them and confirm no type errors remain.
- No overly defensive code or silent fallbacks.
- Apply DRY only where it reduces complexity; keep single-use logic inline rather than extracting a helper for it.

## Comments

- Write comments that help a new reader understand the codebase.
- Never narrate in-progress work or describe code being replaced.
- Write onchain - never "on-chain" or "on chain".
- Don't change/remove existing comments, unless strictly needed due to code changes.

## AI-assisted contributions

Follow the repository AI-assisted contribution policy in [CONTRIBUTING.md](../../../CONTRIBUTING.md#ai-assisted-contributions). Review all AI-generated output before requesting maintainer review.

## Working on an Issue

- Independently reproduce and verify the Issue first.
- When in doubt, ask clarifying questions on the Issue before writing code.

## Bug fixes

- Add a test that fails before the fix and passes after it.
- Don't write tests for what the type system already guarantees.
- Cover edge cases, not only happy path.

## Commits and PRs

- Verifying (signing) ALL commits is strictly required; maintainers will not check a PR otherwise. See [GitHub: about commit signature verification](https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification).
- PR description: short and matching the diff; explain what and why; link relevant issues; state the root cause in one paragraph, citing file and line.
- Justify design decisions where there were ambiguities and discuss the tradeoffs of the approach you picked against the alternatives you considered.

## Per-language

### Per commit: format, lint, build, test

Format, lint, build, and run unit tests before each commit.

```bash
# TypeScript (from typescript/)
pnpm format && pnpm lint && pnpm build && pnpm test

# Go (from go/)
make fmt && make lint && make build && make test

# Python (from python/x402/)
uvx ruff format && uvx ruff check && uv run pytest
```

### Per PR: changelog

Add a changelog fragment for the SDK you changed.

```bash
# TypeScript (from typescript/)
pnpm changeset

# Go (from go/)
make changelog-new

# Python (from python/x402/)
uv run towncrier create --content "Fixed ..." <PR>.bugfix.md
```

## New mechanism or extension

- New payment mechanism / scheme: see [references/new-mechanism.md](references/new-mechanism.md).
- New extension: see [references/new-extension.md](references/new-extension.md).
61 changes: 61 additions & 0 deletions .agents/skills/contributing/references/new-extension.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# New extension implementation

Checklist for adding a new extension. Follow the [general contributing rules](../SKILL.md) as well.

## Spec first

- A spec file must exist. If it does not, write it first.
- The spec must be approved by maintainers (merged into upstream `main`). If it is not, open a PR with the spec only first (`specs/extensions/...`).
- The implementation must follow the spec file exactly.
- The wire formats `PAYMENT-REQUIRED` (in particular the extension field), `PAYMENT-RESPONSE` and facilitator `supported/` output must match the spec strictly. Include only fields actually consumed downstream or required by the extension. Don't add purely informational fields.
- Spec amendments and edits are allowed, but must be well justified.

## Scope

- One language per PR. Never implement the extension in more than one SDK (TS, Python, Go) in a single PR.
- Implement v2 only. Common v1 tells (see the [V1→V2 migration guide](../../../../docs/guides/migration-v1-to-v2.mdx)): `maxAmount` in payment requirements, `X-PAYMENT`/`X-PAYMENT-RESPONSE` headers (v2 uses `PAYMENT-SIGNATURE`/`PAYMENT-RESPONSE`), string network names like `base-sepolia` (v2 uses CAIP-2 like `eip155:84532`) or `x402Version: 1`.

## Code patterns

- Wire extensions with lifecycle hooks via the extension-hooks adapter pattern.
- Reuse core and extension utilities instead of reimplementing them.
- Do NOT modify other packages (core, http, ...). If this is deemed necessary, discuss with maintainers first.

## Tests

### Unit tests

- Pure-logic tests that run offline. Add them under **TS** `typescript/packages/extensions/test/`; **Go** `go/extensions/<extension>/`; or **Py** `python/x402/tests/unit/extensions/<extension>/`. Run them and confirm all pass.
- New additions must have **>80%** line coverage.

```bash
# from typescript/
pnpm --filter @x402/extensions test
# go/
make test
# python/x402/
uv run pytest tests/unit/extensions/
```

### Integration tests

- In-process client/server/facilitator flow tests within the SDK. Requires funded testnet accounts.
- Add them under **TS** `typescript/packages/extensions/test/integrations/`; **Go** `go/extensions/<extension>/`; or **Py** `python/x402/tests/integrations/`. Suites skip when required env vars are missing.
- Run them and confirm all pass.

```bash
# from typescript/
pnpm --filter @x402/extensions test:integration
# go/
make test-integration
# python/x402/
uv run pytest tests/integrations/
```

## Examples

Add server, client, and facilitator examples (as appropriate). Manually confirm a successful payment by running facilitator server and client examples locally.

## Docs

- Add READMEs for the SDK and all examples.
86 changes: 86 additions & 0 deletions .agents/skills/contributing/references/new-mechanism.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# New mechanism implementation

Checklist for adding a new payment mechanism / scheme. Follow the [general contributing rules](../SKILL.md) as well.

## Spec first

- A spec file must exist. If it does not, write it first.
- The spec must be approved by maintainers (merged into upstream `main`). If it is not, open a PR with the spec only first (`specs/schemes/...`).
- The implementation must follow the spec file exactly. Facilitator verification rules are security-critical.
- The wire formats `PAYMENT-REQUIRED` (in particular the `extra` field), `PAYMENT-RESPONSE` and facilitator `supported/` output must match the spec strictly. Include only fields actually consumed downstream or required by the scheme. Don't add purely informational fields.
- Spec amendments and edits are allowed, but must be well justified.

## Scope

- One language per PR. Never implement the mechanism in more than one SDK (TypeScript, Python, Go) in a single PR.
- If a reference implementation already exists in another SDK, cross-check against it; otherwise yours is the reference and the spec is the only source of truth.
- Implement v2 only. Common v1 tells (see the [V1→V2 migration guide](../../../../docs/guides/migration-v1-to-v2.mdx)): `maxAmount` in payment requirements, `X-PAYMENT`/`X-PAYMENT-RESPONSE` headers (v2 uses `PAYMENT-SIGNATURE`/`PAYMENT-RESPONSE`), string network names like `base-sepolia` (v2 uses CAIP-2 like `eip155:84532`) or `x402Version: 1`.

## Code patterns

- Wire schemes with the builder pattern, not `register*` helpers. A new v2-only mechanism registers its scheme under the family wildcard: `client.register("<family>:*", new Exact<Chain>Scheme(...))` (and the same on `x402ResourceServer`). Do NOT implement a `registerExact<Chain>Scheme` helper. Those exist only in the EVM/SVM mechanisms to also register the legacy v1 schemes for backward compat.
- Reuse core utilities instead of reimplementing them. For example, import `convertToTokenAmount`, `numberToDecimalString`, and `parseMoney` from `@x402/core/utils` for TS or similar for Go/python SDKs.
- If the mechanism supports `$` string pricing, add `defaultAssets.ts` / `default_assets.go` / `default_assets.py` with `DEFAULT_ASSETS`, `getDefaultAsset`/`GetDefaultAsset`/`get_default_asset`, and `findDefaultAsset`/`FindDefaultAsset`/`find_default_asset` (see [DEFAULT_ASSETS.md](../../../../DEFAULT_ASSETS.md)). Expose the reverse lookup on the client scheme so `@x402/core` spend controls recognize USD-pegged defaults. Chains without a canonical USD stablecoin may omit the file and require explicit `AssetAmount` pricing instead. Do not put default assets in `constants` or bundled network-config maps.
- Do NOT modify other packages (core, http, ...). If this is deemed necessary, discuss with maintainers first.

## Tests

### Unit tests

- Pure-logic tests that run offline with no live RPC or network calls. Add them with comparable coverage to the EVM reference under **TS** `typescript/packages/mechanisms/<chain>/test/unit/`; **Go** `go/mechanisms/<chain>/` or **Py** `python/x402/tests/unit/mechanisms/<chain>/`. Run them and confirm all pass.
- New additions must have **>80%** line coverage.

```bash
# typescript/
pnpm --filter @x402/<chain> test
# go/
make test
# python/x402/
uv run pytest
```

### Integration tests

- In-process client/server/facilitator flow tests within the SDK that exercise real RPC endpoints and may submit onchain transactions. Requires funded testnet accounts.
- Add them with comparable coverage to the EVM reference under **TS** `typescript/packages/mechanisms/<chain>/test/integrations/` (see `exact-evm.test.ts`); **Go** `go/test/integration/`; **Py** `python/x402/tests/integrations/`. Suites skip when required env vars are missing.
- Run them and confirm all pass.

```bash
# typescript/
pnpm --filter @x402/<chain> test:integration
# go/
make test-integration
# python/x402/
uv run pytest tests/integrations/
```

### E2E tests

- The `e2e/` harness runs client × server × facilitator combinations from the mechanisms catalog. Requires funded testnet accounts.
- Add `e2e/config/mechanisms_<id>.json` (`env`, `testnet`/`mainnet`, `routes` with `sdks`). Do **not** edit per-framework route lists or CAIP-2 pattern tables — HTTP/MCP endpoints are derived from the catalog.
- Register the scheme once per language in the shared modules only: `e2e/servers/<lang>/`, `e2e/clients/<lang>/`, `e2e/facilitators/<lang>/`.
- Add wallet/payee placeholders to `e2e/.env-local`.
- Run them and confirm all pass.

```bash
# from e2e/
pnpm install:all && pnpm test --testnet --min --families=<chain> --versions=2
```

## Examples

- Add network to server, client and facilitator examples under `examples/<sdk>/*/advanced/all_networks`.
- Manually confirm a successful payment by running facilitator, server and client examples locally.

## Docs

- Add READMEs for the SDK and all examples.
- Include link to a testnet faucet and detail all necessecary setup steps (e.g. token association/opt-ins or minimum balance requirements).

## Publishing scripts

Mirror the EVM setup per SDK:

- **TS**: Add `publish_npm_scoped_x402_<chain>.yml` workflow and add package to `publish_npm_scoped_x402_all.yml`.
- **Py**: Add an optional extra in `python/x402/pyproject.toml`; uses existing `publish_pypi_x402.yml`.
- **Go**: no new workflow required; ships with the `go/` module.
5 changes: 5 additions & 0 deletions .gitbook.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
root: ./docs/

structure:
readme: README.md
summary: SUMMARY.md
Loading
Loading