Skip to content

Use Crossmint SDK authorization throughout approval flows - #1

Closed
manu-xmint wants to merge 9 commits into
mainfrom
codex/evaluate-agent-commerce-sdk
Closed

manu-xmint wants to merge 9 commits into
mainfrom
codex/evaluate-agent-commerce-sdk

Conversation

@manu-xmint

@manu-xmint manu-xmint commented Sep 25, 2026 •

Copy link
Copy Markdown

Change

Approval screens previously created and verified agent cards through a custom application flow. They now mount AuthorizeAgentCard, backed by Crossmint SDK 4.8.0, across desktop, mobile, messaging, approval links and checkout approval. The SDK handles card selection, registration, order-intent creation, CVC and verification.

The new /agent-card-requests/:id/authorized endpoint accepts the resulting order-intent ID and validates it with a buyer-JWT-scoped Crossmint read before associating it. Atomic transitions protect against duplicate callbacks and concurrent denial; retries reuse the same ID. The old /approve and /verified endpoints are removed.

New authorization requests require explicit merchant details. Chat, MCP, CLI and checkout persistence carry those details. Existing cards can still fund checkouts. Crossmint remains configured for production with the existing Stytch test session.

Compatibility and setup

  • Apply 0005_sdk_authorization_merchant.sql when using PostgreSQL. The migration was generated but not applied to any external database; the local evaluation uses memory storage.
  • Custom RequestStore implementations must implement the new atomic transition method.
  • Legacy requests without merchant details must be recreated. Browser recovery retains the opaque order-intent ID after the SDK callback. Recovery before that callback still needs interactive evaluation.

Validation and QA

  • 141 tests passed; workspace typecheck and lint passed.
  • Package builds and the production web build passed.
  • Local /app returns HTTP 200; the unauthenticated browser smoke check had no console warnings/errors.
  • Callback diagnostics and the SDK evaluation notes/report are updated. These checks validate the application integration; authenticated SDK behavior remains pending a joint QA session. No production authorization or purchase was submitted during implementation.

Keep this PR in draft for component evaluation. The owner will merge it.

@vercel

vercel Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
agent-commerce-sample-app Ready Ready Preview Sep 28, 2026 3:26pm UTC

Request Review

…commerce-sdk

# Conflicts:
#	apps/web/next.config.ts
#	apps/web/package.json
#	packages/ui/package.json
#	pnpm-lock.yaml
@manu-xmint manu-xmint changed the title Prepare Crossmint SDK 4.8.0 evaluation and development diagnostics Use Crossmint SDK authorization throughout approval flows Sep 28, 2026
@aigustin

Copy link
Copy Markdown
Collaborator

Thanks, Manu. We are launching this repo publicly, so we replaced the history with one clean initial commit. This PR is based on the old history and cannot merge now, so I am closing it. Your branch stays. If you still need these changes, open a new PR from the new main.

@aigustin aigustin closed this Sep 28, 2026

This branch was successfully deployed

1 active deployment
Preview — 0b19a527 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants