Repository navigation
Releases: tempoxyz/pympp
Releases · tempoxyz/pympp
Release list
v0.11.0
Immutable
release. Only release title and notes can be modified.
Minor Changes
- Added a
VerifiableIntentprotocol with separatevalidateandbroadcasthooks plus boundMpp.validate_credential()andMpp.broadcast_credential()APIs, introduced aRelayadapter that delegates Tempo charge validation and finalization to the Tempo API relay (surfacing only safe machine-readable error codes and retryable 402 challenges on decline), and added a runnablecharge-relayFastAPI example with a payer client. Relay idempotency keys use thepympp_namespace, existing Stripe idempotency behavior remains unchanged, and Python validation details use snake_case. (by @parvahuja, #204) - Added configurable
max_payment_retriesparameter toPaymentTransportandClient, allowing callers to override the default retry limit of 3 instead of relying on a hardcoded constant. (by @mpp-agricola[bot], #223)
Patch Changes
- Fixed currency validation during challenge matching by introducing a
_method_accepts_currencyhelper that enforces case-insensitive currency comparison when a method has a configured currency constraint. Applied the check in bothPaymentRuntimeandMcpClientchallenge matching and credential creation paths. (by @DerekCofausper, #232) - Added MACH as a supported Tempo charge currency and selected a supported stablecoin with enough balance to cover unsponsored MACH transaction fees. (by @parvahuja, #237)
- Fixed payment challenge request and opaque serialization to use RFC 8785 JSON Canonicalization Scheme (JCS) via the
rfc8785library, replacing ad-hocjson.dumpscalls across HTTP and MCP transports. This ensures challenge IDs are reproducible from the exact bytes emitted on the wire, including non-ASCII characters and JCS number formatting. (by @brendanryan, #235) - Fixed initial requests to advertise supported payment methods via the
Accept-Paymentheader, derived from the configured payment methods and their intents. ExistingAccept-Paymentheaders are preserved when explicitly set by the caller. (by @mpp-agricola[bot], #225) - Fixed
verify_or_challengeraisingTypeErrorwhen a challenge carried a timezone-naiveexpiresvalue. A naive timestamp parsed successfully but could not be compared to an awarenow, surfacing as a server error instead of a fail-closed rejection; it is now rejected like any other invalidexpires. (by @brendanryan, #234) - Reverted early termination on repeated actionable challenges, allowing the payment transport to retry payment even when the same challenge ID is received multiple times. (by @mpp-agricola[bot], #224)
- Changed Stripe PaymentIntent and Tempo relay idempotency keys to use the SDK-independent
mpp_prefix while preserving their existing suffix construction. (by @parvahuja, #220) - Added a
requires_authserver option that usesPayment-Authorizationfor Payment credentials soAuthorizationremains available for application authentication. (by @ryanaubrey, #230) - Used the bootstrapped Tempo localnet image for reproducible integration tests, replacing the dynamic
latesttag pull-and-cache approach with a pinnedtempo-localnetimage digest. Removed the dev-key-based account funding fallback in favour of exclusively using the localnet faucet viatempo_fundAddress. (by @brendanryan, #226) - Fixed challenge selection to match on both method name and intent, preventing methods from being incorrectly matched to challenges with unsupported intents. Added
intentsproperty to theMethodprotocol to declare which payment intents each method supports. (by @mpp-agricola[bot], #216)
What's Changed
- fix: Challenge selection ignores the intent by @mpp-agricola[bot] in #216
- fix: support Core Metadata 2.5 releases by @parvahuja in #218
- fix: preserve release changelog attribution by @parvahuja in #219
- feat: add Tempo relay and verifiable intents by @parvahuja in #204
- fix: use mpp idempotency prefix by @parvahuja in #220
- fix: Repeated actionable challenges terminate payment handling early by @mpp-agricola[bot] in #224
- test: use bootstrapped Tempo localnet by @brendanjryan in #226
- ci(dependabot): approve and merge updates via github-sts by @sds in #227
- ci: open the release PR via github-sts by @sds in #228
- feat(server): compose payment handlers by @bensandler-stripe in #229
- fix: Initial requests do not advertise supported payment methods by @mpp-agricola[bot] in #225
- fix: Automatic payment retry limit is fixed by @mpp-agricola[bot] in #223
- feat: add requires_auth so Payment credentials use Payment-Authorization by @raubrey-stripe in #230
- fix: validate configured currency during challenge matching by @decofe in #232
- feat(server): add payment method hooks by @bensandler-stripe in #231
- fix(server): reject timezone-naive expires instead of raising by @brendanjryan in #234
- fix: Challenge selection ignores the offered intent by @mpp-agricola[bot] in #212
- fix: canonicalize challenge-bound JSON by @brendanjryan in #235
- feat(tempo): support MACH charges by @parvahuja in #237
- chore: release
v0.11.0by @github-actions[bot] in #217
New Contributors
- @sds made their first contribution in #227
- @raubrey-stripe made their first contribution in #230
Full Changelog: v0.10.1...v0.11.0
v0.10.1
Patch Changes
- Preserved request details across paid retries and rejected payment challenges reached through cross-origin redirects. (by @mpp-agricola[bot], #214)
- Fixed handling of fresh 402 payment challenges returned after a paid retry, enabling clients to recover from failed verification and complete multi-round payment flows. Introduced a retry loop with a maximum attempt limit to support these sequential challenge-response exchanges. (by @mpp-agricola[bot], #214)
What's Changed
New Contributors
- @mpp-agricola[bot] made their first contribution in #210
Full Changelog: v0.10.0...v0.10.1
v0.10.0
Minor Changes
- Added a transport-neutral
PaymentRuntimeclass that provides reusable primitives for matching payment challenges and creating credentials without depending on HTTPX. RefactoredPaymentTransportandClientto accept either amethodslist or a pre-builtruntimeinstance, and consolidated theMethodprotocol intompp.runtime. (by @parvahuja, #202) - Add
hintfield toPaymentErrorproblem details.PaymentRequiredError,MalformedCredentialError, andPaymentMethodUnsupportedErrornow include a default hint pointing users to wallet documentation. (by @parvahuja, #202) - Improved HTTP challenge parsing to correctly split merged
WWW-Authenticateheaders with quoted commas, added pass-through support for streaming request bodies on ordinary and unrelated 402 responses, and introducedPaymentOutcomeUnknownError(consolidated from the MCP client into core) to surface explicit errors when a paid retry outcome is uncertain due to network failures or task cancellation. (by @parvahuja, #202)
Patch Changes
- Added Python 3.14 to the list of declared supported versions in package classifiers and added Python 3.11 to the CI test matrix. (by @parvahuja, #202)
- Preserved MCP challenge metadata when converting MCP challenges to core payment challenges. (by @parvahuja, #202)
- Prevent the optional MCP SDK from resolving to incompatible 2.x releases. (by @parvahuja, #202)
- Handle multipart (
files=) and streaming bodies on paid 402 retry. Multipart bodies are buffered and replayed identically; async generator bodies raisePaymentErrorbefore any I/O. (by @parvahuja, #202) - Preserve
subscriptionIdwhen parsing and formatting payment receipts. (by @parvahuja, #202) - Fixed MCP payment error detection to support the current MCP SDK's
McpErrorshape, where error code and data are nested under anerrorattribute rather than directly on the exception. Added helper functions_error_codeand_error_datato extract these fields from both error shapes. (by @parvahuja, #202)
What's Changed
- Fix MCP payment error detection for current SDK by @parvahuja in #163
- chore(deps): bump the actions group with 2 updates by @dependabot[bot] in #165
- feat: add hint field to PaymentError problem details by @bensandler-stripe in #162
- fix(client): mcp challenge metadata conversion by @parvahuja in #169
- fix: decode Tempo calldata with eth-abi by @brendanjryan in #171
- ci: Add GitHub Actions scanner by @decofe in #173
- fix(client): handle multipart and streaming bodies on paid 402 retry by @bennytimz in #166
- fix: preserve receipt subscription ids by @Osraka in #172
- ci: test declared Python versions by @parvahuja in #183
- chore: batch Dependabot updates by @brendanjryan in #199
- fix: constrain MCP SDK to supported major by @parvahuja in #195
- feat: add reusable payment runtime by @parvahuja in #201
- fix: harden async payment retries by @parvahuja in #202
- chore: release
v0.10.0by @github-actions[bot] in #164
New Contributors
- @bensandler-stripe made their first contribution in #162
- @bennytimz made their first contribution in #166
- @Osraka made their first contribution in #172
Full Changelog: v0.9.1...v0.10.0
v0.9.1
Patch Changes
- Fixed rejection of ABI-encoded calldata with trailing padding bytes in Tempo transfer, approve, and swap calls. Added exact-length validation constants and updated
_match_single_transfer_calldata,_match_transfer_calldata, and_validate_call_scopeto reject any calldata that does not match the expected byte length precisely. (by @brendanryan, #160)
What's Changed
- chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 in the actions group by @dependabot[bot] in #157
- fix: harden Claude changelog workflow by @brendanjryan in #159
- fix: reject padded Tempo calldata by @brendanjryan in #160
- chore: release
v0.9.1by @github-actions[bot] in #161
Full Changelog: v0.9.0...v0.9.1
v0.9.0
Minor Changes
- Validate the credential
sourceon the Tempo hash-credential verification path. The server now parses thedid:pkh:eip155source before reserving the transaction hash, requires TIP-20 transfers to originate from the declared source address (falling back to the receipt sender when no source is provided), and rejects malformed or chain-mismatched sources with a uniform error. Adds avalidate_sendercallback (withSenderValidation/ValidateSender) toChargeIntentto authorize smart-account / relayer flows where the on-chain transfer sender differs from the declared source. (by @stevencartavia, #154) - Sponsored (fee-payer) charges now dry-run the co-signed transaction via
tempo_simulateV1before broadcasting. If the transaction would revert on-chain, the sponsor rejects it instead of paying gas for a failing transaction. The check fails closed: if the simulation RPC is unavailable, the charge is rejected. (by @stevencartavia, #154)
Patch Changes
- Preserve all sender-signed fields when decoding and re-signing fee-payer (0x78) envelopes. Two fields that are part of the sender's signing hash were being lost when the fee payer reconstructed the transaction to cosign it, causing valid transactions to be rejected ("Sender address does not match recovered signer") or mis-attributed:
keyAuthorization: the decoder rebuilt it from onlychain_id,key_type,key_id, andexpiry, droppinglimitsand the T6 (TIP-1049)allowed_calls,witness,is_admin, andaccountfields. It now round-trips the authorization RLP verbatim (decode and encode), so it works for both legacy and T6 authorizations — including non-secp256k1 root signatures — without requiring a T6-awarepytempo.tempo_authorization_list: was dropped entirely during cosigning; it is now carried through.- Access-key (keychain) and other non-secp256k1 sender signatures, which a fee payer cannot verify offline, are now rejected with a clear error instead of an opaque ECDSA recovery failure, and the envelope decoder fails closed on unexpected field counts.
- Pre-broadcast simulation (
tempo_simulateV1) is skipped for locally co-signed transactions that carry akeyAuthorizationor a non-emptytempo_authorization_list. These fields are preserved verbatim as opaque RLP for the broadcast transaction but cannot yet be faithfully re-serialized into the simulation JSON (keyAuthorization/aaAuthorizationList), so the transaction is broadcast without the extra revert check rather than simulated as a different transaction. (by @stevencartavia, #154)
What's Changed
- ci: add conformance gate by @emmajam in #146
- chore(deps): bump wevm/changelogs from de0250123a1d70a2b64a458bd5efcf313986df7a to 57e22cb5bd8367edc8cc1450b9eb0aea75d6e019 in the actions group by @dependabot[bot] in #147
- feat: validate hash credential source by @stevencartavia in #148
- feat: add server body digest and route scope conformance by @figtracer in #149
- chore(deps): bump the actions group with 3 updates by @dependabot[bot] in #152
- feat: simulate sponsored txs before broadcast by @stevencartavia in #150
- feat: preserve sender-signed fields when cosigning fee-payer envelopes by @stevencartavia in #154
- chore: release
v0.9.0by @github-actions[bot] in #151
New Contributors
- @stevencartavia made their first contribution in #148
- @figtracer made their first contribution in #149
Full Changelog: v0.8.2...v0.9.0
v0.8.2
Patch Changes
- Hardened Tempo transaction credential verification by enforcing challenge-bound attribution memos and reserving transaction hashes before broadcast to avoid duplicate rebroadcasts. (by @EmmaJamieson-Hoare, #144)
What's Changed
Full Changelog: v0.8.1...v0.8.2
v0.8.1
Patch Changes
- Added strict validation for payment method IDs, requiring them to match
1*LOWERALPHA(lowercase letters only). UpdatedReceiptdefault method from empty string to"tempo"and fixed test fixtures to use valid method IDs. (by @EmmaJamieson-Hoare, #142)
What's Changed
New Contributors
Full Changelog: v0.8.0...v0.8.1
v0.8.0
Minor Changes
- Added client and server payment lifecycle hooks (
EventDispatcher,PaymentEvent) for observing challenge selection, credential creation, payment responses, successes, and failures. BothPaymentTransport/ClientandMpp/paynow expose typedon_*registration methods with unsubscribe callbacks. (by @brendanryan, #140)
What's Changed
- feat: add payment lifecycle hooks by @brendanjryan in #140
- chore: release
v0.8.0by @github-actions[bot] in #141
Full Changelog: v0.7.0...v0.8.0
v0.7.0
Minor Changes
- Added fee payer policy enforcement for sponsored Tempo transactions, validating gas limits, fee caps, total fee budgets, validity windows, and access lists against per-chain policy defaults. Added call pattern validation to restrict sponsored transactions to approved selectors (transfers, and optionally an approve+swap prefix via the stablecoin DEX). (by @brendanryan, #135)
Patch Changes
- Fixed client chain policy enforcement to reject challenges that attempt to switch the client to a different chain. Clients pinned to a chain (via
chain_idorrpc_url) now raise aValueErrorimmediately instead of silently following the challenge'schainId. (by @brendanryan, #135)
What's Changed
- perf: cache Tempo chain IDs per RPC URL by @brendanjryan in #114
- perf: use eth_sendRawTransactionSync in Tempo verify by @brendanjryan in #115
- chore: harden CI workflows and add Dependabot by @grandizzy in #117
- chore: release
v0.6.1by @github-actions[bot] in #116 - fix: deserialize key_authorization in fee payer envelope decode by @decofe in #120
- chore: standardize dependabot cooldowns to weekly by @decofe in #121
- chore: switch to OIDC trusted publishing and harden workflows by @decofe in #119
- chore(deps): bump the actions group across 1 directory with 6 updates by @dependabot[bot] in #122
- fix: default chain_id to 4217 (mainnet), remove hardcoded fee payer by @brendanjryan in #125
- ci: run integration tests against live Tempo container, remove mocks by @brendanjryan in #127
- chore: release
v0.6.2by @github-actions[bot] in #124 - fix: accept attribution memos in pull-mode preflight by @brendanjryan in #130
- chore: release
v0.6.3by @github-actions[bot] in #131 - chore(deps): bump the actions group with 3 updates by @dependabot[bot] in #132
- fix: enforce pympp client chain policy by @brendanjryan in #134
- fee-payer: enforce call pattern and gas policy by @brendanjryan in #135
- chore: release
v0.7.0by @github-actions[bot] in #136 - chore(deps): bump wevm/changelogs from a5032a56dabbb6e8bd7dc1847bde11d755be4c52 to 056ab043d7affcd6871e8d972b5b5362e7349b57 in the actions group by @dependabot[bot] in #133
- fix: align sponsored tempo tx fees with policy by @brendanjryan in #123
- ci: fix PyPI publish 403 by granting OIDC perms to changelogs job by @brendanjryan in #137
- ci: use OIDC trusted publishing via wevm/changelogs by @brendanjryan in #138
New Contributors
- @grandizzy made their first contribution in #117
- @dependabot[bot] made their first contribution in #122
Full Changelog: v0.6.0...v0.7.0
v0.6.0
Minor Changes
- Added split payments support for Tempo charges, allowing a single charge to be split across multiple recipients. Port of mpp-rs PR #180. (by @brendanryan, #104)
- Added Stripe payment method (
mpp.methods.stripe) supporting the Shared Payment Token (SPT) flow for HTTP 402 authentication. Includes client-sideStripeMethodandstripe()factory, server-sideChargeIntentfor PaymentIntent verification via Stripe SDK or raw HTTP, Pydantic schemas, and astripeoptional dependency group. (by @brendanryan, #104) - Added split payments support for Tempo charges, allowing a single charge to be split across multiple recipients. Port of mpp-rs PR #180. (by @brendanryan, #104)
Full Changelog: v0.5.4...v0.6.0