Commit Graph

207 Commits

Author SHA1 Message Date
github-actions[bot] 87af291e01 Version Packages (#300)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.17.2 @stripe/link-sdk@0.3.2
2026-09-06 21:15:10 -04:00
sylwang-stripe 1fe657f23c Expose Agent Wallet verification action URL (#299) 2026-09-06 21:10:55 -04:00
github-actions[bot] 54756f4ae8 Version Packages (#296)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.17.1 @stripe/link-sdk@0.3.1
2026-09-04 16:18:16 -04:00
sylwang-stripe ca643dce42 Expand user info to include spend limits and step-up status (#295)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-09-04 16:05:24 -04:00
github-actions[bot] ed4d571f7a Version Packages (#286)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.17.0 @stripe/link-sdk@0.3.0
2026-09-03 13:48:21 -04:00
kreese-stripe ec7fc04217 Changeset (#291) 2026-09-03 13:39:29 -04:00
kreese-stripe b8b9dce9d1 Handle post-approval amount updates in CLI (#290) 2026-09-03 11:46:50 -04:00
bensandler-stripe f7661734d7 Document email-prefilled Link URLs (#287)
- Tell agents to add a URL-encoded fromEmail parameter when the user's email is already known.
- Cover OAuth verification and spend-request action URLs with one concise rule per skill.
- Add a patch changeset for the published Link CLI skill updates.

Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-09-02 15:20:57 -04:00
jlau-stripe bd20966ce2 [LINK_AI_WALLET-320] Do not render approval qr code for delegated spend requests (#285) 2026-09-01 13:40:56 -04:00
github-actions[bot] f2e143a6dd Version Packages (#284)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.16.0 @stripe/link-sdk@0.2.1
2026-08-31 17:04:38 -04:00
kreese-stripe 033cee0f07 fix: Sanitize shell quotes during mpp flow (#281)
* Sanitize shell quotes

* comments

* Changeset
2026-08-31 17:03:40 -04:00
mangeli-stripe bb3cc6bbee add link-cli skill (#283)
updates

update recommended text

updates:
2026-08-31 16:51:34 -04:00
kreese-stripe 526395e806 feat: Use pm.name from API in rendering payment methods list as PM label (#282)
* Use pm.name from API in rendering payment methods list as PM label

* Fix tests

* fmt

* Fix types
2026-08-31 15:57:45 -04:00
github-actions[bot] 771f8a077b Version Packages (#280)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.15.1
2026-08-28 16:19:04 -04:00
kreese-stripe a1c68720f6 Fix: allow shipping address nickname to be optional in resource (#279) 2026-08-28 19:50:45 +00:00
github-actions[bot] 72991457e7 Version Packages (#278)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.15.0
2026-08-28 09:37:48 -04:00
sylwang-stripe 91f5e8ecd1 Support Link Pay Token for delegated approval spend requests (#273)
* Support delegated approval for Link Pay Token spend requests

--approve now works with --execution-method link_pay_token as long as
--no-request-approval is also passed, so OAuth clients authorized for
spend_requests:approve can create already-approved LPT requests via
create_delegated without going through consumer approval.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Trim PR to just the delegated-approval guard change per review

Drop the README/CLAUDE.md docs and CLI help-text additions for
--approve/--request-approval — delegated LPT users already have their
own skill file, so the CLI's public docs and help text don't need to
cover this path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-28 09:31:59 -04:00
github-actions[bot] 8e1fd801a8 Version Packages (#277)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.14.2
2026-08-28 09:24:49 -04:00
Jason f77d7451d4 Split the Cursor plugin into plugins/cursor-link with MCP-first skills (#276)
* Split the Cursor plugin into plugins/cursor-link with MCP-first skills

Cursor reaches Link through the hosted MCP server at
api.cursor.com/rest-mcp/stripe-link/mcp, but the plugin's skills were the
CLI-oriented ones shared with Claude and Codex via a symlink to the repo
root. They told Cursor users to npm install @stripe/link-cli and to register
a second, local stdio MCP server, which conflicts with the hosted one.

Give Cursor its own self-contained plugin directory with no shared files, and
write its skills against the tools the hosted server actually exposes:
get_userinfo, list_spend_requests, get_spend_request, list_payment_methods,
list_shipping_addresses, sign_web_bot_auth, and report_agent_observation.

That server exposes no spend-request writes, so the purchase skill covers
finding and spending against a request the user already approved and stops
when none exists. Transactions, balances, and sources are not reachable yet,
so no financial-insights skill ships here; plugins/link still covers that for
CLI-based clients.

With a real .mcp.json in the new directory there is no longer a symlinked
.mcp.json to dodge, so the .link-cursor-mcp.json override is gone.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Route spend approvals through request_virtual_card

The skills described approval as something the agent could not do, which is
true of the Link MCP server but not of Cursor, where request_virtual_card
raises an approval card for exactly this. Rewrite the purchase flow around
that tool: its argument contract (cents including tax and shipping, a 7-word
title, a 100 to 140 character context, line items summing exactly to the
total), the turn ending on the call, the already-pending and denied outcomes,
and the 5/15/30/60 second poll of get_spend_request before retrieving the
card.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Call the product Link, not Stripe Link

Review feedback from @danhill-stripe on the marketplace description.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-28 09:12:57 -04:00
github-actions[bot] d80f4609ab Version Packages (#275)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.14.1
2026-08-27 19:33:23 -04:00
Dan Hill 7e18e3c812 fix: improve cursor plugin (#274) 2026-08-27 19:31:45 -04:00
Steve Kaliski 44aefbe93d fix ci permissions (#272) 2026-08-27 15:27:23 -04:00
Ryan Aubrey cf96ad08f2 Send link-cli User-Agent on mpp pay merchant requests (#269)
* Send link-cli User-Agent on mpp pay merchant requests.

MPP probes and paid retries used global fetch, so merchants saw Node's default User-Agent and LINK_HTTP_PROXY was skipped. Route those calls through the CLI's configured fetch so User-Agent applies unless -H overrides it.

Co-authored-by: Cursor <cursoragent@cursor.com>
Committed-By-Agent: cursor

* Set mpp pay User-Agent in buildHeaders instead of wrapping fetch.

The fetchImpl wiring was more than this needed; default the header on merchant requests and leave -H User-Agent as an override.

Co-authored-by: Cursor <cursoragent@cursor.com>
Committed-By-Agent: cursor

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-27 09:15:15 -04:00
Dan Hill 99532d0b81 Improve readme (#268)
* improve readme

* Readme cleanup

* Readme cleanup

* Readme cleanup

* Readme cleanup
2026-08-26 10:47:10 -04:00
Steve Kaliski 23c6468ac1 remove provenance entry in sdk package.json (#267) 2026-08-25 14:51:58 -04:00
github-actions[bot] 1fb33a35c2 Version Packages (#266)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-25 14:30:05 -04:00
Steve Kaliski 8ee4dea771 Prepare Link SDK for publication (#265)
Committed-By-Agent: codex

Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-25 14:19:10 -04:00
jlau-stripe 9395ba8bef Bump package version (#264)
* Add changesets for PRs #255, #257, #258, #260, #261

Covers spend-request expires-at, SDK transport hardening, canonical
SDK resource adoption, response validation, and moving auth ownership
into the CLI — none of which shipped with a changeset, so CI had
nothing to version since @stripe/link-cli@0.13.1.

Committed-By-Agent: claude

* Version Packages

Release @stripe/link-cli@0.14.0 via changesets: consume pending changesets and update CHANGELOG.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
@stripe/link-cli@0.14.0
2026-08-25 11:51:25 -04:00
Steve Kaliski a29ae922ec Document the credential-only SDK (#262)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-25 11:23:07 -04:00
Steve Kaliski b098ef2f6e Move authentication ownership into CLI (#261)
* Move authentication ownership into CLI

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Test legacy CLI auth storage compatibility

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

---------

Co-authored-by: codex <noreply@openai.com>
2026-08-25 11:04:14 -04:00
Steve Kaliski c949b62610 Validate SDK resource responses (#260)
* Validate SDK resource responses

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Fix approval response fixtures

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Use Zod for SDK response validation

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Keep spend request responses forward-compatible

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

* Normalize approval response URLs

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

---------

Co-authored-by: codex <noreply@openai.com>
2026-08-25 10:29:37 -04:00
Steve Kaliski ac44abcbb6 Adopt canonical SDK resource methods in CLI (#258)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-24 12:39:56 -04:00
Steve Kaliski 2a5996def8 Harden SDK transport primitives (#257)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-24 11:45:47 -04:00
jlau-stripe ea1ed1d59b Add the ability to set extended spend request expiration (#255)
* Add --expires-at support to spend-request create

Mirrors the mint PR (stripe-internal/mint#2484603) that lets allow-listed
OAuth clients request a spend request expiration up to 7 days out instead
of the default 12 hours, for extended/repeat-use agent scenarios.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Hide --expires-at from docs and CLI schema output

Most OAuth clients aren't allow-listed for the server-side flag; leaving
it documented in SKILL.md/README.md/schema descriptions would prompt
general agents to try it and hit a 400. The flag stays functional
(same as the existing `approve` field) but drops its description so it
no longer shows up meaningfully in --schema/--llms-full.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Note the unit for --expires-at in its schema description

Bare field with no description gave zero signal, but agents seeing an
undocumented integer field could just as easily guess wrong (e.g.
milliseconds). Clarifying the unit alone doesn't explain the gating or
bounds, so it stays unlikely to be tried speculatively.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Fix biome formatting on expiresAt schema field

CI was failing pnpm biome check on the line-length wrap for the
one-line describe() call added in 1b6021f.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-20 10:17:21 -04:00
dependabot[bot] f7e62f792c chore(deps): bump nanoid from 3.3.17 to 3.3.18 (#253)
Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.17 to 3.3.18.
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md)
- [Commits](https://github.com/ai/nanoid/compare/3.3.17...3.3.18)

---
updated-dependencies:
- dependency-name: nanoid
  dependency-version: 3.3.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 11:17:06 -04:00
github-actions[bot] d8ba5927d1 Version Packages (#252)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.13.1
2026-08-17 16:32:45 -04:00
shirleyz-stripe 138fa87ddc Clarify payment method confirmation in SKILL.md (#245)
Updated step 3 to clarify payment method confirmation process and adjusted related instructions. Agent no longer needs to list out payment methods and input into spend request; should make the buying process faster
2026-08-17 13:37:19 -04:00
Dan Hill b1640b208d Updates the published limits to $500 (#251)
* fix: correct limits

* fix: correct limits

* add changeset
2026-08-17 13:34:41 -04:00
github-actions[bot] d540389e03 Version Packages (#247)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.13.0
2026-08-13 14:36:54 -04:00
Selina Feng 70453ff2d0 Add changelog entry for financial insights command and skill file changes (#249) 2026-08-13 14:26:11 -04:00
sylwang-stripe 9dc8c650e8 Handle spend request requires_action state across create/retrieve/approval flows (#248) 2026-08-13 14:16:21 -04:00
kreese-stripe 1675a70648 feat: Handle duplicate spend request rate limit response (#246)
* Handle duplicate spend request rate limit response

* Some formatting improvements

* CI

* Changest
2026-08-13 12:47:35 -04:00
github-actions[bot] 69c2089b00 Version Packages (#241)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@stripe/link-cli@0.12.0
2026-08-12 09:59:30 -04:00
Selina Feng c3e70e1225 Expose financial insights CLI commands and skill file (#240) 2026-08-12 09:57:19 -04:00
kreese-stripe e9a8f69b74 security: Sanitize output of decodeStripeChallenge call (#244)
* security improvements for mpp commands

* rm comment

* Add changeset
2026-08-12 08:39:23 -04:00
nvp-stripe 9103637d63 Bind Link Pay Tokens to the checkout merchant (#243)
* lpt merchant binding

* readme updates

* approve link_pay_token
2026-08-11 15:22:10 -04:00
Steve Kaliski f05d954e0f add patch changeset (#239) 2026-08-11 09:42:55 -04:00
Steve Kaliski 9612d71d97 update npm deps (#238)
* update npm deps

* fix ci
2026-08-10 14:04:29 -04:00
dependabot[bot] 20a964f912 chore(deps): bump ip-address from 10.2.0 to 10.3.1 (#226)
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.3.1.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.3.1)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 13:06:32 -04:00
Selina Feng 5ab1f96ca3 Update table styling for balances and sources commands (#228)
* update table styling for balances and sources commands

* test

* fix: rename Account name column to Source name for consistency

Committed-By-Agent: claude
2026-08-07 13:37:08 -04:00