Skip to content

Fix x402 account sign-in and explain how to connect an agent - #2056

Merged
asim merged 2 commits into
mainfrom
codex/x402-signin
Oct 9, 2026
Merged

asim merged 2 commits into
mainfrom
codex/x402-signin

Conversation

@asim

@asim asim commented Oct 9, 2026

Copy link
Copy Markdown
Member

Account actions from the x402 pricing page currently leave the browser on the payment host. Google state cookies can then disagree with the configured callback host, and account sessions and browser-origin checks do not share a consistent origin.

Redirect browser GET/HEAD account, login/signup and Google OAuth pages to the configured primary host before authentication starts, preserving the destination and query. Keep MCP, service APIs, OAuth protocol endpoints, authenticated API requests and POST bodies untouched. Do not redirect when the primary origin is absent or would loop.

After sign-in, keep billing on the primary host and explain the next step. Account and top-up pages link to service-token setup; the service-token form includes the configured x402 MCP endpoint, a configuration example, catalogue/API links and usage access. This guidance remains available after checkout without handing browser sessions between domains.

Validation: tests passed for internal/server, account and internal/auth; vet passed for account and internal/server; diff check passed. Regression coverage includes proxy hosts, preserved destinations, non-browser requests, redirect loops, successful password login on the primary origin, matching Google state/callback origin, and the service-token setup guidance. Live Google provider login and browser visual verification were not performed.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T09:39:38.956845Z d202c17 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d202c17a93

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/server/x402_account.go Outdated
// OAuth state, passkeys and session cookies all use the same host. This does
// not redirect protocol requests or forward credentials between origins.
func redirectHostAccount(w http.ResponseWriter, r *http.Request) bool {
if !origin.IsX402Host(r) || (r.Method != http.MethodGet && r.Method != http.MethodHead) || app.WantsJSON(r) || r.Header.Get("Authorization") != "" {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve legacy token requests on the x402 host

Exempt X-Micro-Token here alongside Authorization. The server explicitly supports that header as a legacy credential, but an authenticated GET/HEAD for /account or its subroutes without Accept: application/json now receives a cross-origin 303 before authentication rather than the previous response; redirect-following clients may also replay this unrecognized custom credential header on the primary host. This changes an existing authenticated client flow despite the function's promise not to redirect protocol requests.

AGENTS.md reference: AGENTS.md:L98-L100

Useful? React with 👍 / 👎.

@asim
asim merged commit c538693 into main Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant