Document AgentCard checkout origin - #276
hiroTamada wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 75292ab. Configure here.
| amount: number; // integer minor units; 1..9007199254740991 | ||
| currency: string; // three letters | ||
| card_id?: string; // vc_...; otherwise chosen at approval | ||
| checkout_origin?: string; // canonical HTTPS origin; localhost HTTP allowed for tests |
There was a problem hiding this comment.
Checkout origin dropped from JSON
Low Severity
Documented public checkout_origin is still absent from the display-safe spec allowlist, so create/get -o json silently drops the stored origin after the request is forwarded.
Triggered by learned rule: Filter vault secrets; print action URLs in full
Reviewed by Cursor Bugbot for commit 75292ab. Configure here.
AnnaXWang
left a comment
There was a problem hiding this comment.
cmd/vaults_help.go:73 — please retain main’s newer warning that card updates replace the whole spec, so omitting checkout_origin from an update removes its existing value.


Summary
checkout_originto the AgentCard card spec shown in CLI help.preparation.merchant_originand that this field does not guarantee payment success.Checks
go test ./cmdmake buildmake test(includesgo vet ./...andgo test ./...)git diff main...HEAD --checkNote
Low Risk
Documentation and test-only updates; card spec JSON is still forwarded unchanged with no new client validation.
Overview
Documents optional
checkout_originon AgentCard card specs in the README AgentCard checkout example,vaults cardsCLI help (AgentCardCardSpec), and related prose.The new field is described as a canonical merchant HTTPS origin (with localhost HTTP for tests) that Kernel forwards to AgentCard for non-prepared autopilot rule matching, with explicit limits: no browser-side validation, autopilot/approval may still apply, no payment guarantee, and prepared checkout should use
preparation.merchant_origininstead.Tests add a raw-spec forwarding case for
checkout_originand assert the help text includes the field and autopilot/approval guidance.Reviewed by Cursor Bugbot for commit 75292ab. Bugbot is set up for automated code reviews on this repo. Configure here.