Skip to content

x402 integration - #846

Open
Technosophorso wants to merge 1 commit into
MeshJS:mainfrom
Technosophorso:main
Open

Technosophorso wants to merge 1 commit into
MeshJS:mainfrom
Technosophorso:main

Conversation

@Technosophorso

Copy link
Copy Markdown
Member

Summary

Adds @meshsdk/x402, a wire-compatible Mesh SDK implementation of the x402 HTTP-402 payment protocol's Cardano exact scheme (client + facilitator), plus the full spend-side lifecycle of Masumi's vested_pay escrow contract — an alternative to the upstream @x402/cardano package (Evolution SDK-based), built entirely on Mesh's own primitives.

  • Client + facilitator support all 3 x402 transfer methods: plain ADA (default), Plutus-script-gated, and Masumi escrow lock
  • Full Masumi vested_pay spend-side lifecycle: SubmitResult, Withdraw, SetRefundRequested, AuthorizeWithdrawal, WithdrawRefund, AuthorizeRefund, WithdrawDisputed (M-of-N CIP-8 admin quorum) — previously only the lock side existed anywhere in the Mesh or x402-foundation ecosystem
  • Security review found and fixed 3 issues in the facilitator's verify path: a trust-boundary gap (verifying against the client's self-reported requirements instead of the resource server's trusted copy), a native-asset unit-conversion bug, and a script-address verification gap when only extra.script (no scriptHash) was given
  • Found and fixed an upstream-relevant bug: @harmoniclabs/plutus-data's dataToCbor encodes non-empty Plutus Data Maps with indefinite-length CBOR, while Aiken's cbor.serialise (used on-chain) uses definite-length — silently broke every WithdrawDisputed admin signature over a non-zero payout. Confirmed via the pinned aiken CLI against the real validator; fixed with a canonical CBOR encoder and locked in with a byte-exact regression test.

Testing

  • Unit: npm test — 9 suites / 32 tests, in-memory only, no live network
  • tsc --noEmit clean
  • Live (Cardano preprod, real transactions against the real deployed contract — not mocks): all 3 payment methods and all 7 vested_pay actions confirmed, including the full dispute lifecycle (lock → SubmitResult → SetRefundRequested → WithdrawDisputed) — example. Requires a funded preprod wallet + Blockfrost key (npm run test:integration), not part of CI.

Adding x402 into Mesh SDK
@Technosophorso Technosophorso changed the title x420 integration x402 integration Sep 22, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant