Repository navigation
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
|
The latest updates on your projects. Learn more about Vercel for GitHub. 3 Skipped Deployments
|
Contributor
|
Preview deployment for your docs. Learn more about Mintlify Previews.
|
Contributor
|
This PR does not match any of the 3 configured review trigger rules. |
Contributor
|
Move device-code status and redemption inputs into JSON request bodies, distinguish terminal device-code states, and document agent route feature-gate errors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
Add /agents/me/cards (list, issue purchase card), /agents/me/cards/{cardId}
(get, tighten or freeze, close purchase card) and its reveal, the
MANAGE_CARDS permission, the ISSUE_PURCHASE_CARD action with its
CARD_ISSUANCE_FAILED and APPROVAL_EXPIRED failure reasons, and allowedMccs,
blockedMccs and agentId on cards.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
The passkey challenge response gains an optional payloadToSign: the exact canonical JSON of the Turnkey session request whose lowercase-hex SHA-256 is the challenge. A client can now parse and check what the passkey authorizes (activity type, its own clientPublicKey) and recompute the digest before calling navigator.credentials.get(). Additive: existing clients that only read challenge are unaffected, and Grid still forwards the stored request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
POST /agents/me/quotes takes AgentQuoteRequest, whose destination is either another embedded wallet (ACCOUNT) or CHAIN_ADDRESS: network (BASE, ETHEREUM, SOLANA, POLYGON, ARBITRUM, TRON), currency (USDC or USDT; TRON is USDT only, BASE is USDC only) and address. Grid records the address as an external account of the customer, reused when one exists for the same network, currency and address, and screens it before quoting. A CHAIN_ADDRESS quote sends USDB with lockedCurrencySide SENDING and commits to the USDB amount, the destination and a minimumReceivingAmount. Grid prices the conversion again when the quote executes, after any approval, and fails the action with the new PRICE_MOVED failure reason rather than send for less. The create and get responses, and AgentAction.quote, are AgentQuote: Quote plus minimumReceivingAmount. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
Grid's default agent merchant-category blocks stay on top of blockedMccs and are lifted only by the platform on a standard agent card (defaultMccBlocksLifted); an agent's blockedMccs must cover the card's effective blocks. Purchase-card currency is an enum of USD, allowedMccs has at least one code, closing a card that is not an open purchase card is a 409 like reveal, spending limits on a purchase card are a 400, and reusing an Idempotency-Key with a different body is a 400. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
AgentCard carries the Card as `card` beside the agent fields instead of merging them with allOf, which kept generated clients from reading the card's nullable limits. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019XW8sx8DuMs7wsDg5hHJck
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Amends the experimental Agents API so an agent can operate a customer's embedded wallet with Grid enforcing its policy.
Grid-Wallet-Signature; Grid signs with the agent's delegated key (403 when the agent has none).DelegatedKeyCreateRequesttakes exactly one ofcardIdoragentId(both or neither is a 400). Card requests are unchanged.AgentActiongainsfailureReason(QUOTE_EXPIRED,POLICY_DENIED, ...) andexpiresAt; a pending action expires with its quote and is never re-quoted on approval.AgentActionWebhookaddsPENDING_APPROVAL,APPROVED,REJECTED,FAILED.AgentPermissionaddsRECEIVE_FUNDS,MANAGE_IDENTITY,MANAGE_CARDS./agents/me/customer,/agents/me/verifications,/agents/me/kyc-link,/agents/me/deposits./agents/me/cards(list; issue aSINGLE_USEorMERCHANT_LOCKEDpurchase card, 201 or 202 pending approval),/agents/me/cards/{cardId}(get; tighten-only PATCH and freeze; close a purchase card) and/agents/me/cards/{cardId}/reveal. Each response is anAgentCard: the platform'sCardnested undercard, besideagentId,agentCardKind,spendLimit,reservedAmount,effectiveBlockedMccsandexpiresAt.AgentActionadds theISSUE_PURCHASE_CARDtype withpurchaseCard/cardfields and theCARD_ISSUANCE_FAILEDandAPPROVAL_EXPIREDfailure reasons.allowedMccsandblockedMccs(create, update, read),agentId(issue a standard card for an agent) anddefaultMccBlocksLifted(the platform may lift Grid's default agent merchant-category blocks on a standard agent card only; an agent'sblockedMccsmust cover the card's effective blocks).PasskeyAuthChallengegains optionalpayloadToSign: the exact canonical JSON of the Turnkey session request whose lowercase-hex SHA-256 ischallenge, so a client can check what a passkey authorizes before signing. Additive; existing clients are unaffected.POST /agents/me/quotestakesAgentQuoteRequest, whose destination isACCOUNT(another embedded wallet) orCHAIN_ADDRESS(network,currencyUSDC/USDT,address). A chain quote sends USDB withlockedCurrencySideSENDINGand commits to aminimumReceivingAmount; Grid re-prices at execution and fails the action with the newPRICE_MOVEDreason rather than send for less. Create/get responses andAgentAction.quoteareAgentQuote(Quote plusminimumReceivingAmount).Validation:
make build,make lint(0 errors; no new warnings),npm run validatepass.