Skip to content

0.10.0: accept signing keys certified by the payout wallet - #18

Merged
Fizzl13 merged 1 commit into
mainfrom
claude/x402-agents-solana-payments-nceg9b
Sep 27, 2026
Merged

Fizzl13 merged 1 commit into
mainfrom
claude/x402-agents-solana-payments-nceg9b

Conversation

@Fizzl13

@Fizzl13 Fizzl13 commented Sep 27, 2026

Copy link
Copy Markdown
Owner

What

  • Certified keys. Receipt checks in the preflight, diagnose and presign actions now also accept a key that the payout wallet 0x6B0F…5F25 has certified for that service (x402-doctor or presign-guard) through receipt.cert. When a service rotates its key, no plugin update is needed.
  • New setting FIZZL_RECEIPT_AUTHORITY. Defaults to the payout wallet. Set it to none to accept pinned keys only.
  • Updated: README, and the version to 0.10.0.

Tests

41/41 pass. The fixtures can now sign with a certificate.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TsD5haPKxeWjYmErHzvU48


Generated by Claude Code

…an update, 0.10.0)

The plugin pinned each service's signing key, so a new key needed a new
release. Both services now carry a certificate in every receipt: the Fizzl
payout wallet's personal_sign over "fizzl receipt signer / service / signer /
valid_from". The plugin accepts a signer that is pinned or certified by that
wallet for the right service (signatures on or after valid_from).
FIZZL_RECEIPT_AUTHORITY overrides the wallet; "none" keeps pinned-only.

Also: the canonical JSON regex used a literal U+FFFF character; it is an
escape sequence again (same behaviour).

Tests: a rotated Doctor key and a rotated presign-guard key with a valid
certificate are trusted; a certificate for the other service, by another
wallet, or with the authority switched off is not.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TsD5haPKxeWjYmErHzvU48
@Fizzl13
Fizzl13 merged commit c1c34f4 into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants