Skip to content

Fix EMAIL_OTP verification flow and retry logic - #1146

Closed
shreyav wants to merge 3 commits into
mainfrom
claude/fix-request-if4mev
Closed

shreyav wants to merge 3 commits into
mainfrom
claude/fix-request-if4mev

Conversation

@shreyav

@shreyav shreyav commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Updated the embedded wallet sign-in documentation and helper script to fix issues with the EMAIL_OTP verification flow. The main problems were incorrect JSON serialization of the encrypted OTP bundle and missing retry logic for asynchronous wallet provider processing.

Key Changes

  • Fixed encryptedOtpBundle serialization: The field must be a string containing JSON text, not a nested object. Updated documentation and examples to use jq to wrap the helper output as a string value rather than splicing it directly into the request body.

  • Added retry loop for verification: The wallet provider may return {"status":"PROCESSING"} while finishing the login. Added an until loop that re-sends the identical signed request (same body and headers) every 2 seconds until a session is returned.

  • Reuse verify request body: Build the verify request body once in /tmp/verify-body.json and reuse it for both the initial challenge request and the signed retry, ensuring consistency.

  • Updated helper script documentation: Clarified in embedded-wallet-sign.js that encrypt-otp outputs {encappedPublic, ciphertext} JSON text that must be passed as a string value, with example jq usage.

Implementation Details

  • The encryptedOtpBundle field was causing {"code":"INVALID_INPUT","reason":"Invalid wallet request."} errors when sent as a nested object; wrapping with jq -n --arg b "$ENC_BUNDLE" '{type: "EMAIL_OTP", encryptedOtpBundle: $b}' resolves this.
  • The retry logic handles the asynchronous nature of the wallet provider's login completion by polling until status is no longer "PROCESSING".
  • Both verification requests now use -d @/tmp/verify-body.json for consistency and to avoid shell escaping issues.

https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk

The README verify example spliced the encrypt-otp output into the request
body as a nested JSON object, but the spec defines encryptedOtpBundle as a
string holding that JSON text. The raw-object form fails with
INVALID_INPUT "Invalid wallet request".

- Build the verify body once with jq (--arg string-encodes the bundle) and
  reuse the saved file for both legs so the signed retry is byte-identical
- Loop the signed retry while the response is {"status":"PROCESSING"}
- Note in the helper's usage comment that encrypt-otp output is the string
  value, not a nested object

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk
@greptile-apps

greptile-apps Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This PR does not match any of the 3 configured review trigger rules.

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

3 Skipped Deployments
Project Deployment Actions Updated
grid-cards-demo Ignored Ignored Preview Oct 8, 2026 11:05pm UTC
grid-flow-builder Ignored Ignored Preview Oct 8, 2026 11:05pm UTC
grid-wallet-demo Ignored Ignored Preview Oct 8, 2026 11:05pm UTC

Request Review

claude added 2 commits October 8, 2026 23:03
Show the saved request body, label each verify leg, and replace the
until-loop with a plain while-loop so the PROCESSING retry reads clearly.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk
encrypt-otp already prints a JSON string literal, so splicing it into the
body yields the string field the API expects. Drop the jq --arg wrapper,
which double-encoded the bundle, and say so in the README. Keep the
labeled verify steps, the body example, and the PROCESSING retry loop.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KeZ4QUyBQZVLZFceifFnYk
@shreyav

shreyav commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

this is not needed

@shreyav shreyav closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants