Skip to content

Consolidate x402 host and payment flows in one package - #2057

Merged
asim merged 1 commit into
mainfrom
codex/x402-package
Oct 9, 2026
Merged

asim merged 1 commit into
mainfrom
codex/x402-package

Conversation

@asim

@asim asim commented Oct 9, 2026

Copy link
Copy Markdown
Member

The x402 host's pages, account redirects, payment gate and billing implementation were scattered across the consumer site. That made the developer account flow depend on switching hosts and made changes affect unrelated pages.

This moves ownership to a top-level x402 package. The server detects the host once and sends every request through its router. The package owns the dark landing, filtered tools catalogue, pricing, username/password sign-in, account, service tokens, OAuth consent and usage flow. Browser sessions use a host-only x402_session cookie; explicit API credentials take precedence. Sign-in and payment returns stay on the developer host.

x402/billing now contains the existing credit ledger, allowances, subscriptions, Stripe checkout/webhooks, crypto top-ups, usage rendering and browser checkout code. Both hosts call that implementation. x402/payment contains the moved protocol/facilitator implementation, and x402/gateway contains the shared API payment and quota enforcement. The old implementations and cross-host redirect flow are deleted. Identity, credential storage, service dispatch and ledger filenames are unchanged.

Service tokens created on the developer host use the shared account and service scopes, expire after 90 days, and work on its MCP/REST endpoints. They are not a separate balance or a new host-specific token format. The host provides existing-account password sign-in; it does not expose Google sign-in or registration.

Validation: go build ./..., go test ./... -short, go vet ./..., gofmt -l . and git diff --check pass. Integration coverage exercises login, host-only cookies, CSRF, token creation and use on MCP, explicit credential precedence, logout, unknown routes, and checkout returns on both hosts. Browser checks at 390px and 1280px show no horizontal overflow, three desktop columns on both tools catalogues, and spacing above the pricing top-up button. Payment provider calls are mocked in tests; no live charge was made.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T10:18:07.882595Z 2420e62 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@asim
asim merged commit 04813f0 into main Oct 9, 2026
1 check passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

destination, err := startSubscription(r.Context(), acc, app.BaseURL(r), r.PostForm.Get("tier"))

P1 Badge Use the shared Stripe webhook for host subscriptions

When a user starts a subscription on X402_HOST, this passes the developer-host origin into startSubscription, whose ensureSubscriptionWebhook consequently requires a Stripe endpoint at that second hostname. Existing installations have the shared webhook on the primary hostname, and the single STRIPE_WEBHOOK_SECRET cannot normally verify independently configured endpoints on both hosts, so the advertised developer-host checkout fails before reaching Stripe. Keep return URLs on the originating host, but validate/deliver renewals through the shared configured webhook origin.

AGENTS.md reference: AGENTS.md:L373-L377


sb.WriteString(`<form class="form" method="POST" action="/account/transfer">`)

P2 Badge Include a CSRF token in the transfer form

When an authenticated user submits this form on X402_HOST, x402.Handler applies auth.StrictCSRF to the POST before dispatching it, but the form supplies neither _csrf nor an X-CSRF-Token header. Every developer-host credit transfer therefore receives a 403 before handleTransfer runs; add app.CSRFField(auth.CSRFToken(r)) as the other shared billing forms do.

AGENTS.md reference: AGENTS.md:L373-L377

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant