Commit Graph

89 Commits

Author SHA1 Message Date
github-actions[bot] b31883b528 Version Packages (#318)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-10 20:32:20 -04:00
sylwang-stripe ac17965507 Surface SpendRequest idempotency key (#317) 2026-09-10 20:26:59 -04:00
github-actions[bot] fed0ac2137 Version Packages (#313)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-09 09:27:05 -07:00
drapeau-stripe c6464e3750 feat: Add --attempt-trace to link-cli report (#289)
A step-by-step account of the path the agent took on a domain, written so
another agent could follow it. `--step` already records where the agent was
when the outcome occurred; `--attempt-trace` is the whole path.

Sent for every outcome, not just `success`. The dead ends on a failed attempt
are what stop the next agent from spending tokens on them.

The field's value is set almost entirely by how it is described, so the schema
description asks for a specific shape — one numbered line per step, each with
the URL path, the label acted on, the action, and the observed result — and
`skills/create-payment-credential/SKILL.md` carries a worked example. Agents
match an example far more reliably than they follow prose.

Deliberately no zod `.max()`. The API truncates past
`REPORT_ATTEMPT_TRACE_MAX_LENGTH` (8000) and still records the report, so
rejecting client-side would trade a long narrative for a lost outcome.
`--step` and `--freeform-context` keep their `.max(500)` because the API
rejects those outright.

Both the description and the docs tell agents to keep the buyer's personal
data out of it and write `[email]`/`[address]` instead.

Requires the server-side `attempt_trace` field on `POST /agent_observations`,
which ships separately and is not deployed yet. Until it is, the API ignores
the extra key, so sending it is a no-op rather than an error.

Test plan
- `pnpm run test` — 310 tests pass, including new SDK coverage for sending
  `attempt_trace` in the body, omitting it, and passing an over-cap value
  through unchanged for the server to truncate.
- `pnpm run typecheck` and `pnpm biome check .` clean.
- `node packages/cli/dist/cli.js report --schema` shows `attemptTrace` with no
  `maxLength`, while `step`/`freeformContext` keep theirs.


Committed-By-Agent: claude
Orbit-Session-Id: e89d7110-bf81-4181-974b-21b0d5dc0c30

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-09 09:18:16 -07:00
github-actions[bot] 6807413b15 Version Packages (#305)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-08 11:54:38 -04:00
kreese-stripe a4ab1630b0 Remove explicit frontend amount validation (#304) 2026-09-08 11:52:28 -04:00
github-actions[bot] 6ffce88220 Version Packages (#303)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-06 21:37:24 -04:00
sylwang-stripe 02d4dcfe1a Simplify user-info verification guidance (#302) 2026-09-06 21:33:32 -04:00
github-actions[bot] 87af291e01 Version Packages (#300)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-06 21:15:10 -04:00
sylwang-stripe 1fe657f23c Expose Agent Wallet verification action URL (#299) 2026-09-06 21:10:55 -04:00
github-actions[bot] 54756f4ae8 Version Packages (#296)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-04 16:18:16 -04:00
sylwang-stripe ca643dce42 Expand user info to include spend limits and step-up status (#295)
Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-09-04 16:05:24 -04:00
github-actions[bot] ed4d571f7a Version Packages (#286)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-03 13:48:21 -04:00
kreese-stripe ec7fc04217 Changeset (#291) 2026-09-03 13:39:29 -04:00
bensandler-stripe f7661734d7 Document email-prefilled Link URLs (#287)
- Tell agents to add a URL-encoded fromEmail parameter when the user's email is already known.
- Cover OAuth verification and spend-request action URLs with one concise rule per skill.
- Add a patch changeset for the published Link CLI skill updates.

Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-09-02 15:20:57 -04:00
jlau-stripe bd20966ce2 [LINK_AI_WALLET-320] Do not render approval qr code for delegated spend requests (#285) 2026-09-01 13:40:56 -04:00
github-actions[bot] f2e143a6dd Version Packages (#284)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-31 17:04:38 -04:00
kreese-stripe 033cee0f07 fix: Sanitize shell quotes during mpp flow (#281)
* Sanitize shell quotes

* comments

* Changeset
2026-08-31 17:03:40 -04:00
github-actions[bot] 771f8a077b Version Packages (#280)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-28 16:19:04 -04:00
kreese-stripe a1c68720f6 Fix: allow shipping address nickname to be optional in resource (#279) 2026-08-28 19:50:45 +00:00
github-actions[bot] 72991457e7 Version Packages (#278)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-28 09:37:48 -04:00
sylwang-stripe 91f5e8ecd1 Support Link Pay Token for delegated approval spend requests (#273)
* Support delegated approval for Link Pay Token spend requests

--approve now works with --execution-method link_pay_token as long as
--no-request-approval is also passed, so OAuth clients authorized for
spend_requests:approve can create already-approved LPT requests via
create_delegated without going through consumer approval.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

* Trim PR to just the delegated-approval guard change per review

Drop the README/CLAUDE.md docs and CLI help-text additions for
--approve/--request-approval — delegated LPT users already have their
own skill file, so the CLI's public docs and help text don't need to
cover this path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Committed-By-Agent: claude

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-28 09:31:59 -04:00
github-actions[bot] 8e1fd801a8 Version Packages (#277)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-28 09:24:49 -04:00
Jason f77d7451d4 Split the Cursor plugin into plugins/cursor-link with MCP-first skills (#276)
* Split the Cursor plugin into plugins/cursor-link with MCP-first skills

Cursor reaches Link through the hosted MCP server at
api.cursor.com/rest-mcp/stripe-link/mcp, but the plugin's skills were the
CLI-oriented ones shared with Claude and Codex via a symlink to the repo
root. They told Cursor users to npm install @stripe/link-cli and to register
a second, local stdio MCP server, which conflicts with the hosted one.

Give Cursor its own self-contained plugin directory with no shared files, and
write its skills against the tools the hosted server actually exposes:
get_userinfo, list_spend_requests, get_spend_request, list_payment_methods,
list_shipping_addresses, sign_web_bot_auth, and report_agent_observation.

That server exposes no spend-request writes, so the purchase skill covers
finding and spending against a request the user already approved and stops
when none exists. Transactions, balances, and sources are not reachable yet,
so no financial-insights skill ships here; plugins/link still covers that for
CLI-based clients.

With a real .mcp.json in the new directory there is no longer a symlinked
.mcp.json to dodge, so the .link-cursor-mcp.json override is gone.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Route spend approvals through request_virtual_card

The skills described approval as something the agent could not do, which is
true of the Link MCP server but not of Cursor, where request_virtual_card
raises an approval card for exactly this. Rewrite the purchase flow around
that tool: its argument contract (cents including tax and shipping, a 7-word
title, a 100 to 140 character context, line items summing exactly to the
total), the turn ending on the call, the already-pending and denied outcomes,
and the 5/15/30/60 second poll of get_spend_request before retrieving the
card.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Call the product Link, not Stripe Link

Review feedback from @danhill-stripe on the marketplace description.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-28 09:12:57 -04:00
github-actions[bot] d80f4609ab Version Packages (#275)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-27 19:33:23 -04:00
Dan Hill 7e18e3c812 fix: improve cursor plugin (#274) 2026-08-27 19:31:45 -04:00
github-actions[bot] 1fb33a35c2 Version Packages (#266)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-25 14:30:05 -04:00
Steve Kaliski 8ee4dea771 Prepare Link SDK for publication (#265)
Committed-By-Agent: codex

Committed-By-Agent: codex

Co-authored-by: codex <noreply@openai.com>
2026-08-25 14:19:10 -04:00
github-actions[bot] d8ba5927d1 Version Packages (#252)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-17 16:32:45 -04:00
Dan Hill b1640b208d Updates the published limits to $500 (#251)
* fix: correct limits

* fix: correct limits

* add changeset
2026-08-17 13:34:41 -04:00
github-actions[bot] d540389e03 Version Packages (#247)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-13 14:36:54 -04:00
Selina Feng 70453ff2d0 Add changelog entry for financial insights command and skill file changes (#249) 2026-08-13 14:26:11 -04:00
kreese-stripe 1675a70648 feat: Handle duplicate spend request rate limit response (#246)
* Handle duplicate spend request rate limit response

* Some formatting improvements

* CI

* Changest
2026-08-13 12:47:35 -04:00
github-actions[bot] 69c2089b00 Version Packages (#241)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-12 09:59:30 -04:00
kreese-stripe e9a8f69b74 security: Sanitize output of decodeStripeChallenge call (#244)
* security improvements for mpp commands

* rm comment

* Add changeset
2026-08-12 08:39:23 -04:00
nvp-stripe 9103637d63 Bind Link Pay Tokens to the checkout merchant (#243)
* lpt merchant binding

* readme updates

* approve link_pay_token
2026-08-11 15:22:10 -04:00
Steve Kaliski f05d954e0f add patch changeset (#239) 2026-08-11 09:42:55 -04:00
github-actions[bot] e0bf195daf Version Packages (#220)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-27 16:48:12 -04:00
kreese-stripe 1c2fd6e603 feat: Support metadata in spend-request create command (#219)
* Support metadata in spend-request create command

* Changeset
2026-07-27 16:44:41 -04:00
github-actions[bot] df13387255 Version Packages (#216)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-23 10:02:43 -04:00
kreese-stripe b097a579e0 fix: Improve security posture of mpp pay command + skillfile (#215)
* Improve security posture of mpp pay command + skillfile

* rn addition

* commit changeset
2026-07-23 09:58:49 -04:00
github-actions[bot] c2b63db596 Version Packages (#206)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-21 09:02:47 -04:00
kreese-stripe 4b5f5be4b0 Harden the security of the serve command (#205)
* Harden the security of the serve command

* fmt

* fix version
2026-07-20 16:00:05 -04:00
github-actions[bot] 1ac34e94a9 Version Packages (#179)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-26 14:17:06 -04:00
sylwang-stripe 1a0bf3099d update readme (#178) 2026-06-26 12:02:56 -04:00
github-actions[bot] acf04687f0 Version Packages (#173)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-24 08:42:45 -07:00
drapeau-stripe dd0e30329b chore: add changeset for report command docs (#170)
#150 added the report-outcomes docs to the README (which ships in the npm
package) and the create-payment-credential skill, but merged without a
changeset. Add a patch changeset so the next release publishes the updated
README.


Committed-By-Agent: claude

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 08:34:41 -07:00
github-actions[bot] d65a4ce616 Version Packages (#168)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-23 15:11:26 -04:00
sylwang7 5827e02f6c v0.8.0 changeset (#167) 2026-06-23 13:11:21 -04:00
github-actions[bot] f70d1fc375 Version Packages (#160)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-15 12:37:31 -04:00