Skip to content

Document AgentCard checkout origin - #276

Open
hiroTamada wants to merge 1 commit into
mainfrom
hypeship/agentcard-checkout-origin
Open

hiroTamada wants to merge 1 commit into
mainfrom
hypeship/agentcard-checkout-origin

Conversation

@hiroTamada

@hiroTamada hiroTamada commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add optional checkout_origin to the AgentCard card spec shown in CLI help.
  • Document the canonical origin format, autopilot matching behavior, approval fallback, and browser-origin validation limitation.
  • Clarify that prepared checkout uses preparation.merchant_origin and that this field does not guarantee payment success.
  • Keep raw spec forwarding unchanged and cover the field in forwarding/help tests.

Checks

  • go test ./cmd
  • make build
  • make test (includes go vet ./... and go test ./...)
  • git diff main...HEAD --check

Note

Low Risk
Documentation and test-only updates; card spec JSON is still forwarded unchanged with no new client validation.

Overview
Documents optional checkout_origin on AgentCard card specs in the README AgentCard checkout example, vaults cards CLI help (AgentCardCardSpec), and related prose.

The new field is described as a canonical merchant HTTPS origin (with localhost HTTP for tests) that Kernel forwards to AgentCard for non-prepared autopilot rule matching, with explicit limits: no browser-side validation, autopilot/approval may still apply, no payment guarantee, and prepared checkout should use preparation.merchant_origin instead.

Tests add a raw-spec forwarding case for checkout_origin and assert the help text includes the field and autopilot/approval guidance.

Reviewed by Cursor Bugbot for commit 75292ab. Bugbot is set up for automated code reviews on this repo. Configure here.

@hiroTamada
hiroTamada marked this pull request as ready for review September 30, 2026 19:34

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 75292ab. Configure here.

Comment thread cmd/vaults_help.go
amount: number; // integer minor units; 1..9007199254740991
currency: string; // three letters
card_id?: string; // vc_...; otherwise chosen at approval
checkout_origin?: string; // canonical HTTPS origin; localhost HTTP allowed for tests

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checkout origin dropped from JSON

Low Severity

Documented public checkout_origin is still absent from the display-safe spec allowlist, so create/get -o json silently drops the stored origin after the request is forwarded.

Fix in Cursor Fix in Web

Triggered by learned rule: Filter vault secrets; print action URLs in full

Reviewed by Cursor Bugbot for commit 75292ab. Configure here.

@AnnaXWang AnnaXWang left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cmd/vaults_help.go:73 — please retain main’s newer warning that card updates replace the whole spec, so omitting checkout_origin from an update removes its existing value.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants