Commit Graph

142 Commits

Author SHA1 Message Date
github-actions[bot] d80f4609ab Version Packages (#275)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-27 19:33:23 -04:00
Ryan Aubrey cf96ad08f2 Send link-cli User-Agent on mpp pay merchant requests (#269)
* Send link-cli User-Agent on mpp pay merchant requests.

MPP probes and paid retries used global fetch, so merchants saw Node's default User-Agent and LINK_HTTP_PROXY was skipped. Route those calls through the CLI's configured fetch so User-Agent applies unless -H overrides it.

Co-authored-by: Cursor <cursoragent@cursor.com>
Committed-By-Agent: cursor

* Set mpp pay User-Agent in buildHeaders instead of wrapping fetch.

The fetchImpl wiring was more than this needed; default the header on merchant requests and leave -H User-Agent as an override.

Co-authored-by: Cursor <cursoragent@cursor.com>
Committed-By-Agent: cursor

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-27 09:15:15 -04:00
Steve Kaliski 23c6468ac1 remove provenance entry in sdk package.json (#267) 2026-08-25 14:51:58 -04:00
github-actions[bot] 1fb33a35c2 Version Packages (#266)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-25 14:30:05 -04:00
Steve Kaliski 8ee4dea771 Prepare Link SDK for publication (#265)
Committed-By-Agent: codex

Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-25 14:19:10 -04:00
jlau-stripe 9395ba8bef Bump package version (#264)
* Add changesets for PRs #255, #257, #258, #260, #261

Covers spend-request expires-at, SDK transport hardening, canonical
SDK resource adoption, response validation, and moving auth ownership
into the CLI — none of which shipped with a changeset, so CI had
nothing to version since @stripe/link-cli@0.13.1.

Committed-By-Agent: claude

* Version Packages

Release @stripe/link-cli@0.14.0 via changesets: consume pending changesets and update CHANGELOG.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-25 11:51:25 -04:00
Steve Kaliski a29ae922ec Document the credential-only SDK (#262)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-25 11:23:07 -04:00
Steve Kaliski b098ef2f6e Move authentication ownership into CLI (#261)
* Move authentication ownership into CLI

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Test legacy CLI auth storage compatibility

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

---------

Co-authored-by: codex <noreply@openai.com>
2026-08-25 11:04:14 -04:00
Steve Kaliski c949b62610 Validate SDK resource responses (#260)
* Validate SDK resource responses

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Fix approval response fixtures

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Use Zod for SDK response validation

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Keep spend request responses forward-compatible

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Normalize approval response URLs

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

---------

Co-authored-by: codex <noreply@openai.com>
2026-08-25 10:29:37 -04:00
Steve Kaliski ac44abcbb6 Adopt canonical SDK resource methods in CLI (#258)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-24 12:39:56 -04:00
Steve Kaliski 2a5996def8 Harden SDK transport primitives (#257)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-24 11:45:47 -04:00
jlau-stripe ea1ed1d59b Add the ability to set extended spend request expiration (#255)
* Add --expires-at support to spend-request create

Mirrors the mint PR (stripe-internal/mint#2484603) that lets allow-listed
OAuth clients request a spend request expiration up to 7 days out instead
of the default 12 hours, for extended/repeat-use agent scenarios.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Hide --expires-at from docs and CLI schema output

Most OAuth clients aren't allow-listed for the server-side flag; leaving
it documented in SKILL.md/README.md/schema descriptions would prompt
general agents to try it and hit a 400. The flag stays functional
(same as the existing `approve` field) but drops its description so it
no longer shows up meaningfully in --schema/--llms-full.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Note the unit for --expires-at in its schema description

Bare field with no description gave zero signal, but agents seeing an
undocumented integer field could just as easily guess wrong (e.g.
milliseconds). Clarifying the unit alone doesn't explain the gating or
bounds, so it stays unlikely to be tried speculatively.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Fix biome formatting on expiresAt schema field

CI was failing pnpm biome check on the line-length wrap for the
one-line describe() call added in 1b6021f.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-20 10:17:21 -04:00
github-actions[bot] d8ba5927d1 Version Packages (#252)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-17 16:32:45 -04:00
Dan Hill b1640b208d Updates the published limits to $500 (#251)
* fix: correct limits

* fix: correct limits

* add changeset
2026-08-17 13:34:41 -04:00
github-actions[bot] d540389e03 Version Packages (#247)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-13 14:36:54 -04:00
sylwang-stripe 9dc8c650e8 Handle spend request requires_action state across create/retrieve/approval flows (#248) 2026-08-13 14:16:21 -04:00
kreese-stripe 1675a70648 feat: Handle duplicate spend request rate limit response (#246)
* Handle duplicate spend request rate limit response

* Some formatting improvements

* CI

* Changest
2026-08-13 12:47:35 -04:00
github-actions[bot] 69c2089b00 Version Packages (#241)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-12 09:59:30 -04:00
Selina Feng c3e70e1225 Expose financial insights CLI commands and skill file (#240) 2026-08-12 09:57:19 -04:00
kreese-stripe e9a8f69b74 security: Sanitize output of decodeStripeChallenge call (#244)
* security improvements for mpp commands

* rm comment

* Add changeset
2026-08-12 08:39:23 -04:00
nvp-stripe 9103637d63 Bind Link Pay Tokens to the checkout merchant (#243)
* lpt merchant binding

* readme updates

* approve link_pay_token
2026-08-11 15:22:10 -04:00
Steve Kaliski 9612d71d97 update npm deps (#238)
* update npm deps

* fix ci
2026-08-10 14:04:29 -04:00
Selina Feng 5ab1f96ca3 Update table styling for balances and sources commands (#228)
* update table styling for balances and sources commands

* test

* fix: rename Account name column to Source name for consistency

Committed-By-Agent: claude
2026-08-07 13:37:08 -04:00
jlau-stripe b3493d202b fix: prevent [object Object] in API error messages across all resources (#234)
- Handle nested `{ error: { message } }` error shape in auth resources
  (both CLI and SDK implementations) by replacing the cast-only
  `err?.error` interpolation with `extractOAuthErrorMessage`, which
  does a runtime typeof check before descending into the object
- Fix `switch (err.error)` in `pollDeviceAuth` to switch on
  `extractOAuthErrorCode(err)` so polling continues correctly when a
  non-string error arrives (object would never match a string case)
- Fix `error_description` truthy guard to a nullish check so an empty
  string from the server is preserved rather than falling back to the
  error code
- Replace inline cast-only error extraction in payment-methods,
  shipping-address, user-info, and web-bot-auth resources with
  `extractErrorMessage` from base.ts, which already handles both
  string and nested-object error shapes
- Replace `String(err)` in `useAsyncAction` with `JSON.stringify(err)`
  so thrown plain objects produce readable output instead of
  [object Object]
- Add tests covering all of the above


Committed-By-Agent: claude

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-07 10:11:42 -04:00
dknudsen-stripe b3b37731ee feat: add auth upgrade command to widen access to a superset (#229)
Committed-By-Agent: claude
2026-08-06 12:39:11 -07:00
sylwang-stripe f89efad09e open verification URL in browser on spend request step-up failure (#227) 2026-08-06 10:27:40 -04:00
kreese-stripe 06587fa405 Surface card_brand and card_last4 on spend-request retrieve (#225)
The link-api PR (mint#2412595, LINK_AI_WALLET-365) added top-level
`card_brand` and `card_last4` to the RetrieveSpendRequest response so
integrators can identify a card for debugging without expanding the full
`card` object via `include=card`.

Add both fields to the SDK `SpendRequest` type and display them in the
interactive `retrieve` view when the full card is not expanded. The SDK
already passed these through to `--format json` output via its
pass-through cast; this closes the typing and interactive-display gap.

Docs (README, SKILL.md, CLAUDE.md) updated to match.


Committed-By-Agent: claude

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-04 16:55:00 -04:00
kreese-stripe a20a948aec fix: Add metadata to SpendRequest type + add some test cases (#222)
* Add  to type + add some test cases

* fmt
2026-07-31 09:58:24 -04:00
github-actions[bot] e0bf195daf Version Packages (#220)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-27 16:48:12 -04:00
kreese-stripe 1c2fd6e603 feat: Support metadata in spend-request create command (#219)
* Support metadata in spend-request create command

* Changeset
2026-07-27 16:44:41 -04:00
dknudsen-stripe b87f7d5a9d feat: persist and display oauth scope + auth details (#217)
Committed-By-Agent: claude
2026-07-24 13:43:59 -07:00
github-actions[bot] df13387255 Version Packages (#216)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-23 10:02:43 -04:00
kreese-stripe b097a579e0 fix: Improve security posture of mpp pay command + skillfile (#215)
* Improve security posture of mpp pay command + skillfile

* rn addition

* commit changeset
2026-07-23 09:58:49 -04:00
sylwang-stripe f64d2a1c45 add activity_url and transaction_id to SpendRequest (#214)
* add transaction_id and activity_url to SpendRequest

* scope to only finalized succeeded state

* fix formatting
2026-07-22 10:43:25 -04:00
bensandler-stripe 45d2839fe8 Auto-install skill files on npm install (#212)
Add a postinstall script that copies the SKILL.md into
~/.claude/skills/ and ~/.codex/skills/ so the skill is
available globally without being inside the repo. Updated
prepack to bundle the skills directory into dist/.


Committed-By-Agent: claude

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-21 12:42:40 -04:00
kreese-stripe 384b5b2d23 Update README and some test data references (#210)
* Replace testmode card number

* Update readme for testmode
2026-07-21 11:01:06 -04:00
sylwang-stripe 62ada5e6ac surface support_url on identity_verification_failed errors (#204)
Committed-By-Agent: claude
2026-07-21 10:05:20 -04:00
github-actions[bot] c2b63db596 Version Packages (#206)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-21 09:02:47 -04:00
Ryan Aubrey eaf0b32269 Improve mpp pay command (#202)
* Add MPP inspect command

* feat: rework mpp pay to handle full end-to-end 402 flow

mpp pay now probes the URL for a 402 challenge, parses the
WWW-Authenticate header to extract network_id and amount, creates a
spend request, yields the approval URL for the agent to present, and
completes payment with the SPT after approval.

- Remove mpp inspect (subsumed into pay flow)
- Add --context, --amount, --payment-method-id, --test flags
- Make --spend-request-id optional (backward compat)
- Agent mode yields approval URL immediately with _next hints
- Interactive mode handles full flow inline with polling
- Update SKILL.md and CLAUDE.md with new flow docs

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: update mpp pay tests to handle generator array output

The mpp pay command now uses an async generator (`async *run`) which
wraps yielded values in an array in JSON output mode. Update three
tests to extract [0] from the output array.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* refactor: remove auto-generated context and step translation layer in mpp pay

Context is now required (min 100 chars) for the full MPP flow — agents must
provide a meaningful description. Also refactors onStep to emit typed Step
values directly, removing the string-to-enum mapping in the component.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* revert version bump in SKILL.md

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: remove extra blank line to pass biome format check

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-20 16:49:09 -04:00
kreese-stripe 4b5f5be4b0 Harden the security of the serve command (#205)
* Harden the security of the serve command

* fmt

* fix version
2026-07-20 16:00:05 -04:00
Ryan Aubrey 4343245afc feat(mpp): support decoding session challenges alongside charge (#203)
* feat(mpp): support stripe session challenges alongside charge

Add intent="session" support to the MPP flow. Session challenges use an
open/grantedToken credential shape instead of the bare SPT payload.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Committed-By-Agent: claude

* chore: retrigger CI

Committed-By-Agent: claude

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-20 12:43:00 -04:00
Selina Feng 573b541b19 Add support for the --source filter flag in the balances command (#199) 2026-07-16 14:33:56 -04:00
jlau-stripe 543ea36ce0 bump version to 0.9.0 (#201) 2026-07-16 12:55:54 -04:00
dknudsen-stripe 3cfe555915 feat(financial-insights): Add auth support for Financial Insights (#200)
* feat(financial-insights): add specifying authorization_details for financial insights resources
2026-07-16 08:47:58 -07:00
jlau-stripe ced5e47490 introduce approval_details to spend request creation (#198)
* introduce approval_details to spend request creation

* fix: biome formatting

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-15 14:36:45 -04:00
Selina Feng e3629cc943 Add support for balances list CLI command (#194) 2026-07-15 12:21:29 -04:00
Selina Feng c7a4a3169b Add support for sources list CLI command (#193) 2026-07-15 11:37:39 -04:00
Selina Feng 83b7d41916 Extract shared HTTP transport layer into BaseResource (#192) 2026-07-15 10:29:54 -04:00
jlau-stripe 7dadfcd1ef patch version (#187) 2026-07-07 10:34:46 -04:00
jlau-stripe b3b25946c9 feat: surface verification_url in spend-request error output (#186)
* feat: surface verification_url in spend-request error output

When the API returns additional_verification_required, surface the
verification_url so users know where to complete stepup verification.
Also fixes interactive mode hanging on error by calling useApp().exit().

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

* fix: resolve biome lint and format errors in spend-request commands

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-07 10:20:27 -04:00