Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 50 additions & 0 deletions .agent/context/20260913T012306Z-remove-circle-paid-api.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# Session context: remove Circle paid API surface

- Date: 2026-09-13
- User goal: create a new branch that removes the Circle x402 paid-API product, the repository's own paid API seller/proxy, and related product documentation while preserving `.agent/context/` history.
- Branch: `feature/remove-circle-paid-api`
- Base: `origin/develop` at `b942732b0229f8e749da13df36a8f6d378894ec1`

## Assumptions and non-goals

- Remove active Circle paid-API buyer/seller/proxy routes, UI, Gateway funding/signing helpers, contracts, adapters, runtime configuration, and user-facing documentation.
- Preserve Team Report, direct Arc/User Wallet payment, Privy authentication, generic Arc receipt verification, and recovery for the remaining direct-payment flow.
- Preserve historical `paid_api_requests` migrations and existing context records; do not rewrite applied migration history or destroy production data.
- This branch removes the product surface; it does not attempt to reconcile or delete already-created paid-API intents.

## Safety and acceptance criteria

- No active `/v1/paid-api*` or `/api/premium/*` product route remains.
- The web console contains no Circle paid-API purchase, Gateway funding, or x402 signing controls.
- Team Report and direct USER_WALLET payment paths remain available and preserve at-most-once settlement behavior.
- Historical migrations remain ordered and schema-digest checks remain valid.
- Circle paid-API packages, seller deployment artifacts, dependencies, tests, and non-context documentation are removed or updated without secrets.
- Existing durable paid-API records remain untouched and are not blindly retried or deleted.

## Plan

1. Remove active paid-API API, worker, supplier, seller, web, contract, and configuration paths.
2. Remove paid-API-specific tests/dependencies and regenerate contracts.
3. Remove user-facing Circle paid-API/proxy documentation while preserving context history and migration history.
4. Run focused tests, full validation, generated checks, browser checks, conflict scan, and secret scan.

## Gate state

- Gate A: not run.
- Gate B: not run.
- Commit/PR: not created.

## Local validation

- `pnpm test`: passed — 76 files / 1032 tests.
- `pnpm test:browser`: passed — 8/8.
- `pnpm typecheck`: passed.
- `pnpm lint`: passed.
- `pnpm format:check`: passed.
- `pnpm check:generated`: passed.
- `git diff --check`: passed.
- PostgreSQL-gated integration tests were not run locally because no container runtime was available.

## Handoff

- The feature removal is intentionally separate from any settlement-reconciliation repair. Existing paid-API records remain durable for audit; this branch does not claim that their prior UNKNOWN outcomes are resolved.
287 changes: 287 additions & 0 deletions .agent/context/legacy-plan-20260913.md

Large diffs are not rendered by default.

18 changes: 0 additions & 18 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -13,22 +13,6 @@ ONESHOT_WORKSPACE_ID=team-testnet-workspace
ONESHOT_API_RATE_LIMIT_MAX_REQUESTS=60
ONESHOT_API_RATE_LIMIT_WINDOW_MS=60000

# Circle Gateway x402 paid API. Configure the same resource URL for the API and
# payment-worker Cloud Run deployments. The seller route is deployed separately;
# use the same-domain Cloudflare path after SELLER_BACKEND_URL is configured.
# Never commit a private key; x402 uses the Privy wallet's EIP-712 signer and a
# pre-funded Gateway balance.
# ONESHOT_X402_URL=https://oneshot.kapustazh.dev/api/premium/dataset
# ONESHOT_X402_BUSINESS_INTENT_ID=x402-demo-2026-09-11
# ONESHOT_X402_GATEWAY_FUNDED=true
# ONESHOT_X402_MAX_AMOUNT_ATOMIC=10000

# Circle seller service. The address is public and receives testnet Gateway
# payments; this service does not require a seller private key.
# ONESHOT_X402_SELLER_ADDRESS=0x<40-hex-testnet-seller-address>
# ONESHOT_X402_SELLER_PORT=8081
# ONESHOT_X402_FACILITATOR_URL=https://gateway-api-testnet.circle.com

# Production worker effect boundary. Public identifiers are placeholders;
# secrets must be injected by the deployment secret store, never committed.
ONESHOT_ARC_PROFILE=arc-testnet
Expand Down Expand Up @@ -66,8 +50,6 @@ ONESHOT_GRAPH_API_KEY=<set-in-secret-store-not-here>
# Optional bounded manual wallet-activity refresh for the authenticated cabinet.
# When unset, activity reports Graph as unavailable without affecting payments.
# ONESHOT_GRAPH_QUERY_URL=https://api.studio.thegraph.com/query/<studio-id>/<subgraph>/<version>
# For Circle x402 activity, use the Gateway wallet address:
# ONESHOT_ACTIVITY_WALLET_ADDRESS=0x0077777d7EBA4688BDeF3E311b846F25870A19B9
# ONESHOT_SUBGRAPH_MCP_SERVER_VERSION=1.0.0
ONESHOT_SUBGRAPH_DEPLOYMENT_ID=0x<64-hex-deployment-id>
ONESHOT_SUBGRAPH_MANIFEST_CID=<subgraph-manifest-cid>
Expand Down
29 changes: 0 additions & 29 deletions Dockerfile.seller

This file was deleted.

29 changes: 4 additions & 25 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,8 @@ The cardinality it protects is:

## The problem

An autonomous agent is told to buy a paid API result for 1.25 USDC. It submits
the payment. The connection drops before the response arrives.
An autonomous agent is told to make a business payment for 1.25 USDC. It
submits the payment. The connection drops before the response arrives.

The agent now cannot tell the difference between:

Expand Down Expand Up @@ -201,8 +201,8 @@ The Team Report browser flow uses a separate user-funded path: after the quote,
the connected Privy Ethereum wallet is shown the exact Arc Testnet USDC
transfer and signs it in the browser. The API stores the payer binding and
accepts the job only after verifying the submitted receipt. The server-side
Privy execution wallet remains for worker-owned integrations such as the
Circle x402 demo; it is not the payer for a Team Report started from Tools.
Privy execution wallet remains for worker-owned settlement operations; it is
not the payer for a Team Report started from Tools.

Bootstrap an operator by setting `VITE_PRIVY_APP_ID`, starting the web app,
signing in, copying the DID shown by the console, adding that DID to
Expand Down Expand Up @@ -261,22 +261,6 @@ shown for retries; users do not need to invent one. After settlement, the job
list links directly to ArcScan and keeps the supplier result separate from
payment evidence.

The Tools cabinet also supports **Paid API purchase via Circle x402**. Deploy
the repository's Circle Arc Testnet seller from
[`docs/CIRCLE_X402_SELLER.md`](docs/CIRCLE_X402_SELLER.md), then configure its
same-domain dataset endpoint in the API environment. The connected Privy
wallet is durably bound to the quote and signs the Circle Gateway authorization;
OneShot forwards that signed authorization to the seller and verifies the Arc
receipt. The server-side Privy wallet remains available for the legacy worker
buyer adapter and is not used for the website's user-funded path. Approval
includes the exact quote shown to the operator; the API rejects a changed
price, recipient or destination before creating durable payment work.
`pnpm demo:x402` remains an operator fallback. A lost or ambiguous x402
response is held as `UNKNOWN`; it is never retried blindly. See
[`docs/CIRCLE_X402_DEMO.md`](docs/CIRCLE_X402_DEMO.md). This rail is not the
direct Arc settlement proof; the paid API result has its own durable payment
state and recovery evidence.

| Method | Path | Purpose |
| ------ | -------------------------------- | ------------------------------------------------------------- |
| `POST` | `/v1/intents` | Create an intent; an identical replay returns the same result |
Expand All @@ -285,11 +269,6 @@ state and recovery evidence.
| `GET` | `/v1/intents/{id}/recovery-view` | Local authority plus labelled provider observations |
| `POST` | `/v1/jobs` | Start/replay one workspace-scoped team report task |
| `POST` | `/v1/jobs/quote` | Return a non-chargeable quote before explicit approval |
| `POST` | `/v1/paid-api/quote` | Return a non-chargeable Circle x402 quote |
| `POST` | `/v1/paid-api` | Start/replay one workspace-scoped paid API request |
| `POST` | `/v1/paid-api/user-wallet/prepare` | Bind quote and connected payer before signing |
| `POST` | `/v1/paid-api/{id}/user-wallet/submit` | Forward signed x402 payment and verify settlement |
| `GET` | `/v1/paid-api/{id}` | Read paid API state, transaction hash, and result |
| `GET` | `/v1/jobs` | List workspace jobs and delivery state |
| `GET` | `/v1/jobs/{jobId}` | Read a workspace-owned job |
| `POST` | `/v1/jobs/{jobId}/resume` | Resume original supplier delivery; never submits payment |
Expand Down
Loading
Loading