Skip to content

Releases: tempoxyz/pympp

v0.11.0

Choose a tag to compare

@tempo-github-sts tempo-github-sts released this 28 Aug 21:23
Immutable release. Only release title and notes can be modified.
e514a95

Minor Changes

  • Added a VerifiableIntent protocol with separate validate and broadcast hooks plus bound Mpp.validate_credential() and Mpp.broadcast_credential() APIs, introduced a Relay adapter that delegates Tempo charge validation and finalization to the Tempo API relay (surfacing only safe machine-readable error codes and retryable 402 challenges on decline), and added a runnable charge-relay FastAPI example with a payer client. Relay idempotency keys use the pympp_ namespace, existing Stripe idempotency behavior remains unchanged, and Python validation details use snake_case. (by @parvahuja, #204)
  • Added configurable max_payment_retries parameter to PaymentTransport and Client, allowing callers to override the default retry limit of 3 instead of relying on a hardcoded constant. (by @mpp-agricola[bot], #223)

Patch Changes

  • Fixed currency validation during challenge matching by introducing a _method_accepts_currency helper that enforces case-insensitive currency comparison when a method has a configured currency constraint. Applied the check in both PaymentRuntime and McpClient challenge matching and credential creation paths. (by @DerekCofausper, #232)
  • Added MACH as a supported Tempo charge currency and selected a supported stablecoin with enough balance to cover unsponsored MACH transaction fees. (by @parvahuja, #237)
  • Fixed payment challenge request and opaque serialization to use RFC 8785 JSON Canonicalization Scheme (JCS) via the rfc8785 library, replacing ad-hoc json.dumps calls across HTTP and MCP transports. This ensures challenge IDs are reproducible from the exact bytes emitted on the wire, including non-ASCII characters and JCS number formatting. (by @brendanryan, #235)
  • Fixed initial requests to advertise supported payment methods via the Accept-Payment header, derived from the configured payment methods and their intents. Existing Accept-Payment headers are preserved when explicitly set by the caller. (by @mpp-agricola[bot], #225)
  • Fixed verify_or_challenge raising TypeError when a challenge carried a timezone-naive expires value. A naive timestamp parsed successfully but could not be compared to an aware now, surfacing as a server error instead of a fail-closed rejection; it is now rejected like any other invalid expires. (by @brendanryan, #234)
  • Reverted early termination on repeated actionable challenges, allowing the payment transport to retry payment even when the same challenge ID is received multiple times. (by @mpp-agricola[bot], #224)
  • Changed Stripe PaymentIntent and Tempo relay idempotency keys to use the SDK-independent mpp_ prefix while preserving their existing suffix construction. (by @parvahuja, #220)
  • Added a requires_auth server option that uses Payment-Authorization for Payment credentials so Authorization remains available for application authentication. (by @ryanaubrey, #230)
  • Used the bootstrapped Tempo localnet image for reproducible integration tests, replacing the dynamic latest tag pull-and-cache approach with a pinned tempo-localnet image digest. Removed the dev-key-based account funding fallback in favour of exclusively using the localnet faucet via tempo_fundAddress. (by @brendanryan, #226)
  • Fixed challenge selection to match on both method name and intent, preventing methods from being incorrectly matched to challenges with unsupported intents. Added intents property to the Method protocol to declare which payment intents each method supports. (by @mpp-agricola[bot], #216)
What's Changed
  • fix: Challenge selection ignores the intent by @mpp-agricola[bot] in #216
  • fix: support Core Metadata 2.5 releases by @parvahuja in #218
  • fix: preserve release changelog attribution by @parvahuja in #219
  • feat: add Tempo relay and verifiable intents by @parvahuja in #204
  • fix: use mpp idempotency prefix by @parvahuja in #220
  • fix: Repeated actionable challenges terminate payment handling early by @mpp-agricola[bot] in #224
  • test: use bootstrapped Tempo localnet by @brendanjryan in #226
  • ci(dependabot): approve and merge updates via github-sts by @sds in #227
  • ci: open the release PR via github-sts by @sds in #228
  • feat(server): compose payment handlers by @bensandler-stripe in #229
  • fix: Initial requests do not advertise supported payment methods by @mpp-agricola[bot] in #225
  • fix: Automatic payment retry limit is fixed by @mpp-agricola[bot] in #223
  • feat: add requires_auth so Payment credentials use Payment-Authorization by @raubrey-stripe in #230
  • fix: validate configured currency during challenge matching by @decofe in #232
  • feat(server): add payment method hooks by @bensandler-stripe in #231
  • fix(server): reject timezone-naive expires instead of raising by @brendanjryan in #234
  • fix: Challenge selection ignores the offered intent by @mpp-agricola[bot] in #212
  • fix: canonicalize challenge-bound JSON by @brendanjryan in #235
  • feat(tempo): support MACH charges by @parvahuja in #237
  • chore: release v0.11.0 by @github-actions[bot] in #217

New Contributors

Full Changelog: v0.10.1...v0.11.0

v0.10.1

Choose a tag to compare

@github-actions github-actions released this 09 Aug 15:45
09b4497

Patch Changes

  • Preserved request details across paid retries and rejected payment challenges reached through cross-origin redirects. (by @mpp-agricola[bot], #214)
  • Fixed handling of fresh 402 payment challenges returned after a paid retry, enabling clients to recover from failed verification and complete multi-round payment flows. Introduced a retry loop with a maximum attempt limit to support these sequential challenge-response exchanges. (by @mpp-agricola[bot], #214)
What's Changed
  • fix: A fresh 402 challenge after payment is not handled by @mpp-agricola[bot] in #210
  • fix: Canonical operation http.payment_request is not declared by @mpp-agricola[bot] in #214
  • chore: release v0.10.1 by @github-actions[bot] in #211

New Contributors

  • @mpp-agricola[bot] made their first contribution in #210

Full Changelog: v0.10.0...v0.10.1

v0.10.0

Choose a tag to compare

@github-actions github-actions released this 03 Aug 19:42
7f7164a

Minor Changes

  • Added a transport-neutral PaymentRuntime class that provides reusable primitives for matching payment challenges and creating credentials without depending on HTTPX. Refactored PaymentTransport and Client to accept either a methods list or a pre-built runtime instance, and consolidated the Method protocol into mpp.runtime. (by @parvahuja, #202)
  • Add hint field to PaymentError problem details. PaymentRequiredError, MalformedCredentialError, and PaymentMethodUnsupportedError now include a default hint pointing users to wallet documentation. (by @parvahuja, #202)
  • Improved HTTP challenge parsing to correctly split merged WWW-Authenticate headers with quoted commas, added pass-through support for streaming request bodies on ordinary and unrelated 402 responses, and introduced PaymentOutcomeUnknownError (consolidated from the MCP client into core) to surface explicit errors when a paid retry outcome is uncertain due to network failures or task cancellation. (by @parvahuja, #202)

Patch Changes

  • Added Python 3.14 to the list of declared supported versions in package classifiers and added Python 3.11 to the CI test matrix. (by @parvahuja, #202)
  • Preserved MCP challenge metadata when converting MCP challenges to core payment challenges. (by @parvahuja, #202)
  • Prevent the optional MCP SDK from resolving to incompatible 2.x releases. (by @parvahuja, #202)
  • Handle multipart (files=) and streaming bodies on paid 402 retry. Multipart bodies are buffered and replayed identically; async generator bodies raise PaymentError before any I/O. (by @parvahuja, #202)
  • Preserve subscriptionId when parsing and formatting payment receipts. (by @parvahuja, #202)
  • Fixed MCP payment error detection to support the current MCP SDK's McpError shape, where error code and data are nested under an error attribute rather than directly on the exception. Added helper functions _error_code and _error_data to extract these fields from both error shapes. (by @parvahuja, #202)
What's Changed

New Contributors

Full Changelog: v0.9.1...v0.10.0

v0.9.1

Choose a tag to compare

@github-actions github-actions released this 01 Jul 18:53
ee68e9b

Patch Changes

  • Fixed rejection of ABI-encoded calldata with trailing padding bytes in Tempo transfer, approve, and swap calls. Added exact-length validation constants and updated _match_single_transfer_calldata, _match_transfer_calldata, and _validate_call_scope to reject any calldata that does not match the expected byte length precisely. (by @brendanryan, #160)
What's Changed
  • chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 in the actions group by @dependabot[bot] in #157
  • fix: harden Claude changelog workflow by @brendanjryan in #159
  • fix: reject padded Tempo calldata by @brendanjryan in #160
  • chore: release v0.9.1 by @github-actions[bot] in #161

Full Changelog: v0.9.0...v0.9.1

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 23 Jun 15:09
e24d634

Minor Changes

  • Validate the credential source on the Tempo hash-credential verification path. The server now parses the did:pkh:eip155 source before reserving the transaction hash, requires TIP-20 transfers to originate from the declared source address (falling back to the receipt sender when no source is provided), and rejects malformed or chain-mismatched sources with a uniform error. Adds a validate_sender callback (with SenderValidation / ValidateSender) to ChargeIntent to authorize smart-account / relayer flows where the on-chain transfer sender differs from the declared source. (by @stevencartavia, #154)
  • Sponsored (fee-payer) charges now dry-run the co-signed transaction via tempo_simulateV1 before broadcasting. If the transaction would revert on-chain, the sponsor rejects it instead of paying gas for a failing transaction. The check fails closed: if the simulation RPC is unavailable, the charge is rejected. (by @stevencartavia, #154)

Patch Changes

  • Preserve all sender-signed fields when decoding and re-signing fee-payer (0x78) envelopes. Two fields that are part of the sender's signing hash were being lost when the fee payer reconstructed the transaction to cosign it, causing valid transactions to be rejected ("Sender address does not match recovered signer") or mis-attributed:
  • keyAuthorization: the decoder rebuilt it from only chain_id, key_type, key_id, and expiry, dropping limits and the T6 (TIP-1049) allowed_calls, witness, is_admin, and account fields. It now round-trips the authorization RLP verbatim (decode and encode), so it works for both legacy and T6 authorizations — including non-secp256k1 root signatures — without requiring a T6-aware pytempo.
  • tempo_authorization_list: was dropped entirely during cosigning; it is now carried through.
  • Access-key (keychain) and other non-secp256k1 sender signatures, which a fee payer cannot verify offline, are now rejected with a clear error instead of an opaque ECDSA recovery failure, and the envelope decoder fails closed on unexpected field counts.
  • Pre-broadcast simulation (tempo_simulateV1) is skipped for locally co-signed transactions that carry a keyAuthorization or a non-empty tempo_authorization_list. These fields are preserved verbatim as opaque RLP for the broadcast transaction but cannot yet be faithfully re-serialized into the simulation JSON (keyAuthorization / aaAuthorizationList), so the transaction is broadcast without the extra revert check rather than simulated as a different transaction. (by @stevencartavia, #154)
What's Changed
  • ci: add conformance gate by @emmajam in #146
  • chore(deps): bump wevm/changelogs from de0250123a1d70a2b64a458bd5efcf313986df7a to 57e22cb5bd8367edc8cc1450b9eb0aea75d6e019 in the actions group by @dependabot[bot] in #147
  • feat: validate hash credential source by @stevencartavia in #148
  • feat: add server body digest and route scope conformance by @figtracer in #149
  • chore(deps): bump the actions group with 3 updates by @dependabot[bot] in #152
  • feat: simulate sponsored txs before broadcast by @stevencartavia in #150
  • feat: preserve sender-signed fields when cosigning fee-payer envelopes by @stevencartavia in #154
  • chore: release v0.9.0 by @github-actions[bot] in #151

New Contributors

Full Changelog: v0.8.2...v0.9.0

v0.8.2

Choose a tag to compare

@github-actions github-actions released this 02 Jun 07:42
a14351d

Patch Changes

  • Hardened Tempo transaction credential verification by enforcing challenge-bound attribution memos and reserving transaction hashes before broadcast to avoid duplicate rebroadcasts. (by @EmmaJamieson-Hoare, #144)
What's Changed
  • fix: harden tempo transaction verification by @emmajam in #144
  • chore: release v0.8.2 by @github-actions[bot] in #145

Full Changelog: v0.8.1...v0.8.2

v0.8.1

Choose a tag to compare

@github-actions github-actions released this 01 Jun 16:50
c63a5fc

Patch Changes

  • Added strict validation for payment method IDs, requiring them to match 1*LOWERALPHA (lowercase letters only). Updated Receipt default method from empty string to "tempo" and fixed test fixtures to use valid method IDs. (by @EmmaJamieson-Hoare, #142)
What's Changed
  • fix: reject invalid payment method ids by @emmajam in #142
  • chore: release v0.8.1 by @github-actions[bot] in #143

New Contributors

Full Changelog: v0.8.0...v0.8.1

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 16 May 17:24
ba49e65

Minor Changes

  • Added client and server payment lifecycle hooks (EventDispatcher, PaymentEvent) for observing challenge selection, credential creation, payment responses, successes, and failures. Both PaymentTransport/Client and Mpp/pay now expose typed on_* registration methods with unsubscribe callbacks. (by @brendanryan, #140)
What's Changed
  • feat: add payment lifecycle hooks by @brendanjryan in #140
  • chore: release v0.8.0 by @github-actions[bot] in #141

Full Changelog: v0.7.0...v0.8.0

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 02 May 19:31
add1c6b

Minor Changes

  • Added fee payer policy enforcement for sponsored Tempo transactions, validating gas limits, fee caps, total fee budgets, validity windows, and access lists against per-chain policy defaults. Added call pattern validation to restrict sponsored transactions to approved selectors (transfers, and optionally an approve+swap prefix via the stablecoin DEX). (by @brendanryan, #135)

Patch Changes

  • Fixed client chain policy enforcement to reject challenges that attempt to switch the client to a different chain. Clients pinned to a chain (via chain_id or rpc_url) now raise a ValueError immediately instead of silently following the challenge's chainId. (by @brendanryan, #135)
What's Changed
  • perf: cache Tempo chain IDs per RPC URL by @brendanjryan in #114
  • perf: use eth_sendRawTransactionSync in Tempo verify by @brendanjryan in #115
  • chore: harden CI workflows and add Dependabot by @grandizzy in #117
  • chore: release v0.6.1 by @github-actions[bot] in #116
  • fix: deserialize key_authorization in fee payer envelope decode by @decofe in #120
  • chore: standardize dependabot cooldowns to weekly by @decofe in #121
  • chore: switch to OIDC trusted publishing and harden workflows by @decofe in #119
  • chore(deps): bump the actions group across 1 directory with 6 updates by @dependabot[bot] in #122
  • fix: default chain_id to 4217 (mainnet), remove hardcoded fee payer by @brendanjryan in #125
  • ci: run integration tests against live Tempo container, remove mocks by @brendanjryan in #127
  • chore: release v0.6.2 by @github-actions[bot] in #124
  • fix: accept attribution memos in pull-mode preflight by @brendanjryan in #130
  • chore: release v0.6.3 by @github-actions[bot] in #131
  • chore(deps): bump the actions group with 3 updates by @dependabot[bot] in #132
  • fix: enforce pympp client chain policy by @brendanjryan in #134
  • fee-payer: enforce call pattern and gas policy by @brendanjryan in #135
  • chore: release v0.7.0 by @github-actions[bot] in #136
  • chore(deps): bump wevm/changelogs from a5032a56dabbb6e8bd7dc1847bde11d755be4c52 to 056ab043d7affcd6871e8d972b5b5362e7349b57 in the actions group by @dependabot[bot] in #133
  • fix: align sponsored tempo tx fees with policy by @brendanjryan in #123
  • ci: fix PyPI publish 403 by granting OIDC perms to changelogs job by @brendanjryan in #137
  • ci: use OIDC trusted publishing via wevm/changelogs by @brendanjryan in #138

New Contributors

Full Changelog: v0.6.0...v0.7.0

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 07 Apr 15:31
f13ed57

Minor Changes

  • Added split payments support for Tempo charges, allowing a single charge to be split across multiple recipients. Port of mpp-rs PR #180. (by @brendanryan, #104)
  • Added Stripe payment method (mpp.methods.stripe) supporting the Shared Payment Token (SPT) flow for HTTP 402 authentication. Includes client-side StripeMethod and stripe() factory, server-side ChargeIntent for PaymentIntent verification via Stripe SDK or raw HTTP, Pydantic schemas, and a stripe optional dependency group. (by @brendanryan, #104)
  • Added split payments support for Tempo charges, allowing a single charge to be split across multiple recipients. Port of mpp-rs PR #180. (by @brendanryan, #104)

Full Changelog: v0.5.4...v0.6.0