Skip to content

Add direct USDC checkout and advertise Pay with crypto - #2001

Merged
asim merged 1 commit into
mainfrom
feat/direct-usdc-topup
Oct 2, 2026
Merged

asim merged 1 commit into
mainfrom
feat/direct-usdc-topup

Conversation

@asim

@asim asim commented Oct 2, 2026

Copy link
Copy Markdown
Member

Customers currently have to deposit USDC into a server-held wallet and then convert it. Add direct wallet checkout on the credit top-up page, with a “Pay with crypto” link on Pricing when native USDC on Base is configured. Preserve /wallet and its existing conversion flow.

The browser signs a fixed EIP-3009 authorization through an injected wallet (desktop extension or mobile wallet browser). Mu verifies it, persists the account-bound request before settlement, and adds credits through the existing ledger. Pending payments continue after closing the page and resume after restart. Recovery checks finalized on-chain authorization and Transfer events; expired requests are only released once the finalized chain proves no payment arrived. Retries credit once. Amounts are 1–500 USDC at 100 credits per USDC.

Validation: account, server, shell and CLI tests pass; concurrent payment recovery passes the race detector; full Go build passes with -buildvcs=false (workspace VCS stamping is unavailable); JS syntax and mocked checkout success/cancellation/rejection checks pass. Tests cover CSRF, amount bounds, account/nonce isolation, fixed signed terms, duplicate settlement, restart recovery, wrong transfer/token/recipient/amount, wrong network and finalized expiry.

No real-funds transaction or signed-in browser layout test was performed. This uses browser-provided wallets, not a WalletConnect QR flow. Runtime requires the existing x402 receiving address/facilitator setup and a Base RPC endpoint. No subscription or wallet-transfer changes.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T09:09:23.876418Z 19992e1 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@asim
asim merged commit fb9050e into main Oct 2, 2026
1 check passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 19992e1335

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread account/crypto.go

// CryptoConfigured advertises only native USDC on Base, the checkout supported
// by the browser signer and receipt verifier.
func CryptoConfigured() bool { return cryptoRequirement(100) != nil }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Check facilitator credentials before advertising crypto

When an operator sets only X402_PAY_TO, this predicate returns true and advertises checkout, even though the default Coinbase-hosted facilitator requires CDP credentials (internal/x402/x402.go documents this in Status). In that common configuration the customer can connect and sign, but every VerifySigned request is rejected for missing authentication, so checkout can never complete. Include facilitator authentication/readiness in this predicate for the hosted mainnet facilitator while preserving support for custom facilitators.

Useful? React with 👍 / 👎.

Comment thread account/crypto.go
Comment on lines +312 to +314
if tx == "" && time.Now().Unix() < p.Before {
res, e := x402.SettleSigned(cryptoPayload(p), &p.Requirement)
if e != nil {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Settle with the persisted x402 version

If X402_VERSION is changed through live settings while an authorization is pending or before recovery after a restart, p.Requirement and cryptoPayload(p) retain the version the customer signed, but SettleSigned builds its facilitator request using the current global x402Ver(). The resulting mismatched envelope is rejected on every retry, leaving a valid signed payment pending until expiry. Derive the facilitator request version from the persisted requirement or payload for both verification and settlement.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant