Replies: 4 comments
|
This is close to the testing problem you describe, with a narrower scope. Pulse has an offline 80-case corpus for the AP2 Payment Mandate to x402 exact/EIP-3009 boundary, including amount, nonce, signature, and cross-artifact mismatch cases. It is community work, not an official AP2 suite, and it does not cover the full IntentMandate/CartMandate chain or provide a public sandbox. We are seeking two implementations outside Prime Beat to reproduce it independently. The unpaid target is frozen at commit Any language is fine. The implementation must derive all 80 decisions and failure codes without calling the reference verifier or using Because you are already building a third-party verifier, your work may overlap if this narrower boundary is useful. Issue #16 is the only place for participation or qualification questions so the evidence stays in one thread. |
|
Thank you for sharing the initiative and for defining the reproduction scope so clearly. |
|
I have a test hop: agent signed intent → normal Stripe test charge. 20 minutes. |
|
Different layer from a mandate-chain conformance suite, but related to the "no public sandbox" pain: For the crypto draft / human-wallet-sign side (not Intent/Cart/Payment Mandate verification), we keep a public testnet demo so callers can create a draft and sign without needing a private sandbox or spend keys on the agent. send21 prepares payment drafts and pay links. Agents create drafts with scoped keys that cannot spend. Humans sign in their own wallet. send21 never holds keys, never signs, never broadcasts. It is not an AP2 mandate verifier and does not ship official AP2 conformance vectors. If the gap you are filling is mandate-chain attack cases, community corpora like the Pulse Payment Mandate ↔ x402 set are the right class of tool. If you also need a live human-sign rail to exercise after a mandate would have ACCEPTed, the testnet demo is open: https://send21.io/demo |
Uh oh!
There was an error while loading. Please reload this page.
Hi everyone. We're building a third party risk screening service that verifies the full AP2 mandate chain (IntentMandate, CartMandate, PaymentMandate), including SD JWT VC verification per draft ietf oauth sd jwt vc and JWT signed CartMandates.
Since there's no callable public sandbox for AP2 (Stripe gives you one for ACP, this doesn't have an equivalent), we've been generating our own spec compliant test chains locally with our own test keys and checking them against a handful of attack scenarios we came up with ourselves: tampered amounts, replayed authorizations, wrong nonce, forged keys, cart/payment mismatch.
Is there an official or community maintained set of conformance tests or reference vectors for AP2 that third party verifiers should be running against? I'd rather test against something the maintainers already validated than assume our homegrown scenarios cover everything.
All reactions