0.5.0
All three packages move to 0.5.0 together: @wasit-dev/core, @wasit-dev/cli and @wasit-dev/server.
Two reporting fixes found by running Wasit against code it did not write, and one addition that brings the MCP server level with the CLI. No check was added or removed.
Results can change on upgrade
Only in two situations:
- A target that issues an x402 v1 challenge. See the first fix below.
- An MPP channel target that refuses a replay with a status other than 402 or 2xx. The verdict is still FAIL, but it no longer calls the refusal a double-spend.
Against a conformant v2 target nothing changes: Wasit's own x402 fixture passes 7/7 with this build, as it did with 0.4.0.
Fixed: x402 v1 challenges are read, and payment checks no longer fail when nothing was paid
Run with its operator's written authorization against a service that speaks x402 v1, 0.4.0 reported X402-02 FAIL, skipped X402-03–05, and reported X402-06 and X402-07 as FAIL although no payment was ever built or sent. X402-07 therefore read as a corrupted signature that was not rejected. docs/CHECKS.md already said a challenge that cannot be read has no verdict.
Now:
X402-02still fails, because theexactscheme on Stellar is defined for v2 only. The failure now says an x402 v1 challenge was found in the response body.X402-03–05inspect that body instead of being skipped.X402-04applies the v1 field names, andX402-05reports whether the network is a CAIP-2 identifier.X402-06andX402-07are skipped with the reason, for a v1 challenge or any challenge the payment client cannot read. Nothing is sent.
Seven new offline tests, each mutation-checked.
Fixed: MPP-12 and MPP-14 no longer call a refused replay a double-spend
Both reported any non-402 response as "accepted twice … This is a double-spend." The official MPP SDK's channel server on its main branch refuses replays with HTTP 500 (stellar/stellar-mpp-sdk#82), so Wasit claimed a double-spend while the server had in fact refused. The verdict stays FAIL, since the required status is 402, but the double-spend wording now appears only for a 2xx.
Added: wasit_x402_test accepts method, body and headers
The CLI has had --method, --body and --header since 0.1.0, but the MCP tool could only send a GET, so an agent could not test a paid POST endpoint. The same request shape now applies to every probe, including X402-06 and X402-07. A body sent with GET or HEAD is refused as a configuration error. Header values appear in the agent's transcript, so never pass a credential as a header; use the CLI for an endpoint that needs one.
Install
npx -y @wasit-dev/cli@0.5.0 --version
claude mcp add wasit -- npx -y @wasit-dev/server@0.5.0Testnet only. A passing result means the service behaved as the spec requires for the published checks; it is not a security audit.
Verified before publishing
- 120 offline tests pass;
npm run typecheckis clean. npm run verify:clean-install: the three tarballs install into an empty project,wasit-mcpcompletes an MCP handshake, and reports 0.5.0.- Full x402 suite against Wasit's own v2 fixture: 7/7.
Still planned
On-chain verification for X402-06, a signature-only corruption for X402-07, and exit code 2 from wasit wallet status --role on an unreadable key are now planned for 0.6.0. See the changelog.
Full changelog: v0.4.0...v0.5.0