Mirror gateway Wave 1 docs onto the public companion - #24
Conversation
Align the installable gateway skill, CLI deposit help, OpenCode plugin README, and agent-skills index with the merged gateway surface: live terms instead of retired floors, three-word @bitplan.dev paymail, x402 v2 PAYMENT-SIGNATURE, and evaluate on the MCP tool list. Co-authored-by: Satchmo <rohenaz@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Biome quote/style pass on the skill script. Agent-pages checks the gateway skill with a string match instead of a nested regex. Co-authored-by: Satchmo <rohenaz@users.noreply.github.com>
rohenaz
left a comment
There was a problem hiding this comment.
GPT-6 Sol @ xhigh review of PR #24 (Codex subscription CLI)
Verdict: DON'T MERGE — the advertised public gateway skill references payment scripts that are absent from its published directory.
Model: gpt-6-sol · effort: xhigh · CLI: Codex 0.156.1 · tip: a9482a139f8c9dde9189a767d2ef16a8ab479c40 · base: master (draft companion after gateway #2+#3)
Session: 01a0cef7-a49d-7381-be6a-7ca3c86ed752 · tokens: ~135,793
Command: codex exec -m gpt-6-sol -c 'model_reasoning_effort="xhigh"' -c 'sandbox_mode="read-only"' -C ~/code/worktrees/bitplan-dev-pr24-a9482a1-sol -o /tmp/sol-reviews/bitplan-dev-pr24-a9482a1-sol.md -
Local review md: /tmp/sol-reviews/bitplan-dev-pr24-a9482a1-sol.md
Authorship: Luke Rohenaz / rohenaz · Do NOT undraft/merge from this review.
Confirmed behaviors
- The live gateway discovery lists the documented batch and evaluate endpoints,
PAYMENT-SIGNATURE, legacyX402-Proof, thebitplan.devpaymail domain, and live fee fields. Models exposesrouting_feeandbyok_fee_bps; the rate response exposesmin_deposit_sats. The CLI help at packages/cli/src/index.ts:82 no longer claims a 0.5 BSV minimum. - The canonical and published gateway
SKILL.mdfiles are byte identical, and the index digest matches. The agent-pages test checks both. - pay.ts:160 emits a base64 x402 v2 payload with
--x402; its default remains the legacy base64url proof. The OpenCode README now describes thePAYMENT-SIGNATUREbehavior implemented by the plugin.
Findings
- Medium — Published skill is missing its runnable WIF scripts. The public skill instructs readers to run
$SKILL_DIR/scripts/token.tsand, at line 182,pay.ts. Its published directory contains onlySKILL.md; the scripts and package manifest exist only inskills/gateway/scripts/. A user fetching the advertised public skill cannot follow those WIF steps. Publish those files with the skill or point readers to an obtainable script installation. - Low —
--x402challenge-only input builds an incomplete payment requirement. pay.ts:13 advertises challenge-only input, but the fallback at lines 91–110 creates anacceptedobject withoutmaxTimeoutSeconds. x402 v2 requires that field; the full-body path preserves the offered object. Require the full 402 requirements for--x402and retain challenge-only input for the legacy proof. Gateway rejection was not tested. - Low — BYOK settlement wording retains a zero-fee assumption. SKILL.md:481–489 correctly makes
byok_fee_bpslive, then says calls settle to “add-ons only” after naming router, search, and evaluate charges. Name the own-key fee in that settlement sentence when it is nonzero. The live fee was 0 at review time, so this is a conditional wording issue.
Money-path / regression check
master...HEAD changes no wallet, application envelope, settlement, hold, or on-chain files. The CLI deposit change is help text and its test; gatewayDepositCommand is untouched. The standalone pay.ts payment helper does change, but its transaction construction is unchanged apart from formatting; the functional addition is header serialization.
Luke / Kayle notes
Both PR commits are authored by Luke Rohenaz (rohenaz@users.noreply.github.com). Keep the PR draft until the public skill packaging and x402 fallback are addressed and reviewed. On a CLEAN result, Kayle can undraft and merge to master; this review does neither.
CI / tests
bun test apps/web/src/lib/agent-pages.test.ts: 8 passed, 0 failed.git diff --check master...HEAD: passed.- The CLI and OpenCode focused suites could not load
@bsv/sdkbecause dependencies are absent in this checkout. Kayle’s reported 639/0 run was not independently reproduced. - Tip checks: Vercel and Vercel Preview Comments passed; verify failed at
bun run lint:root. The visible diagnostics include unchanged template files andskills/gateway/scripts/token.ts, consistent with the reported inherited master lint failure. No PR-introduced lint failure was established. - Live discovery confirms endpoint presence and fee fields; it does not independently establish the documented 500-request inline batch shape, MCP tool list, or a paid retry.
MERGABLE
no — for Tina’s undraft gate.
Ship token.ts, pay.ts, and package.json next to the public SKILL.md so agents that install from .well-known get working $SKILL_DIR/scripts. --x402 now requires the full 402 accepts[0] (including maxTimeoutSeconds); challenge-only stays on the legacy proof. BYOK settlement names the own-key fee only while byok_fee_bps is above 0. Co-authored-by: Satchmo <rohenaz@users.noreply.github.com>
rohenaz
left a comment
There was a problem hiding this comment.
GPT-6 Sol @ xhigh review of PR #24 (Codex subscription CLI)
Verdict: CLEAN / MERGABLE=yes — prior MED closed; residual issues are LOW only.
Model: gpt-6-sol · effort: xhigh · CLI: Codex 0.156.1 · tip: 9f075ab305da3dd19113463c1913ad4dde30eaef · base: master (still draft)
Session: 01a0cf0b-8717-7f20-aa4f-c05440ce3933 · tokens: ~78,426
Command: codex exec -m gpt-6-sol -c 'model_reasoning_effort="xhigh"' -c 'sandbox_mode="read-only"' -C ~/code/worktrees/bitplan-dev-pr24-9f075ab-sol -o /tmp/sol-reviews/bitplan-dev-pr24-9f075ab-sol.md -
Local review md: /tmp/sol-reviews/bitplan-dev-pr24-9f075ab-sol.md
Authorship: Luke Rohenaz / rohenaz · Do NOT undraft/merge from this review (Tina undrafts on CLEAN; Kayle merges).
Prior MED — CLOSED
Published apps/web/public/.well-known/agent-skills/gateway/scripts/{token,pay}.ts and package.json exist and are byte-identical to skills/gateway/scripts/. Discovery index lists the skill; SKILL.md:132 uses sibling script paths; agent-pages.test.ts:103 asserts discovery, digest, and file equality.
Prior LOWs
- pay.ts
--x402/maxTimeoutSeconds: PARTIAL — pay.ts:91acceptedOfnow requiresmaxTimeoutSeconds, but still accepts anaccepts[0]missing other required v2 fields and emits it unchanged. Follow-up: validate the complete v2 requirements against the challenge before fetching UTXOs and signing. - BYOK settlement wording (
byok_fee_bps=0): CLOSED — SKILL.md:481 says the gateway adds nothing for the model while the fee is zero and distinguishes billable add-ons. (Gateway server settlement code is outside this repo.)
SKILL.md identity
Canonical ↔ published: identical (SHA-256 7160993f41ca13161c3eeecb21d0d85daf700658bd4b3cc54e2699f1af2a53b0).
Money-path / wallet / envelope
No changed production wallet or envelope logic, and no normal-flow regression found. Residual LOW is the incomplete accepts[0] validation in pay.ts above.
NEW findings
- Low — deposit example uses unset
$N. SKILL.md:178 — copying without definingNsends invalid{"sats":}on both requests, so no payment challenge is obtained. Prefer-d '{}'for the documented default floor, or assignNfrom/v1/rate.
CI / tests (spot-check)
bun test apps/web/src/lib/agent-pages.test.ts: 8 passed, 0 failed. Byte comparisons andgit diff --checkpassed in the Sol checkout.- Tip CI: Vercel + Vercel Preview Comments pass;
verifyfail onlint:root(run 35886808154) — consistent with inherited master lint noise; not treated as a new PR blocker. - Commits on tip authored by Luke Rohenaz (
rohenaz@users.noreply.github.com); PR authorrohenaz. Review posted as rohenaz. Full-suite 639/0 and typecheck/build not re-run independently (read-only checkout missing@bsv/sdkfor CLI gateway tests).
MERGABLE
yes — for Tina’s undraft gate. MED closed; remaining issues are LOW and nonblocking. This review does not undraft or merge.
Summary
Mirror the gateway Wave 1 docs/surface updates that merged on
opldotdev/gateway.bitplan.dev#3(tipfdbaf6b, mergec5ca668) into this public companion.skills/gateway: missing endpoints + batch details (inline OpenRouter shape, up to 500,GET /v1/batches), three-word paymail@bitplan.dev, router fee and own-key fee from live terms (routing_fee/byok_fee_bps, nothing while 0),evaluateon the MCP tool list,scripts/pay.ts --x402printsPAYMENT-SIGNATURE. No stale 30% / 0.5 BSV / always-zero BYOK lines.packages/cli/src/index.ts: retired "minimum 0.5 BSV" replaced with a pointer at live terms (GET /v1/rate,/.well-known/x402-info).PAYMENT-SIGNATUREinstead ofX402-Proof./.well-known/agent-skills/gateway/.Sol@xhigh review (tip
a9482a1, MERGABLE no)Addressed on this tip (
9f075ab) without undrafting:$SKILL_DIR/scripts/{token,pay}.ts(andpackage.json) next to the publicSKILL.mdatapps/web/public/.well-known/agent-skills/gateway/scripts/as byte copies ofskills/gateway/scripts/. Discovery and the installed skill now match. Agent-pages tests assert the published scripts equal the canonical ones.pay.ts --x402no longer synthesizes an incompleteacceptedobject. It requires the full 402accepts[0]includingmaxTimeoutSeconds; challenge-only stays on the legacyX402-Proof.byok_fee_bpsis above 0, and stays truthful that live fee is 0 / the gateway adds nothing for the model while 0.Money-path / gateway API payment code is unchanged. No new product numbers were invented.
Verification
bun run lint—biome checkof the changed CLI/skill scripts is clean; repo-widebun run lintstill reports pre-existing template/token format noise on master (lint:root).apps/weblint of the touched test is clean (published.tscopies are ignored so they stay byte-identical).bun run typecheckbun test— 639 pass, 0 failbun run buildCompatibility and safety
Docs, skill packaging, and CLI help text only. Envelope, wallet, rendering, and on-chain behavior are unchanged.
bitplan gateway depositstill pays whatever the live 402 asks; only the commander description no longer states a retired 0.5 BSV floor. The skill script's default output remains the legacyX402-Proof;--x402printsPAYMENT-SIGNATUREand now requires the offered 402 accepts object.