Repository navigation
All three packages move to 0.6.0 together: @wasit-dev/core, @wasit-dev/cli and @wasit-dev/server.
The two x402 payment checks now prove what their names say: X402-06 verifies the settlement on-chain, and X402-07 forges only the signature. MPP-01 reads the newer form of the transfer event and stops blaming a target for a slow RPC. Node.js 22 is supported. No check was added or removed.
Results can change on upgrade
X402-06fails a target that serves without settling, reports a transaction that is not its settlement, or answers without aPAYMENT-RESPONSEheader.X402-07fails a target that decodes a payment without verifying its signature, or accepts a forged one with 201 or 204.MPP-01passes a payment to a muxed (M...) recipient that it used to miss, and gives no verdict instead of a FAIL when RPC stops advancing.
Against Stellar's official reference paywall (stellar/x402-stellar), this build passes 7/7, with X402-06 verified on-chain. If a run goes red on upgrade, the check got stronger, not the service worse.
Changed: X402-06 verifies settlement on-chain
It passed on any 2xx, which established that the target served the resource, not that the payment landed. It now reads the settlement from the PAYMENT-RESPONSE header and holds the reported transaction to the advertised terms on Stellar RPC, as MPP-01 does: one transfer from this run's payer to payTo, for amount of asset. Against a server built to serve without settling, and one that reports someone else's transaction, 0.5.0 passed and 0.6.0 fails both. A settlement_pending response is reconciled on chain, as the spec directs.
wasit test gains --rpc-url, and the MCP tool wasit_x402_test gains rpcUrl.
Fixed: X402-07 corrupts only the signature
It overwrote the tail of the base64 envelope, which broke XDR decoding, so a target that decoded the envelope and never verified the signature still refused it and passed. It now flips one byte of the client's Soroban authorization-entry signature and leaves the rest of the transaction intact. Against a server that decodes but never verifies, 0.5.0 passed and 0.6.0 fails. Acceptance is now any 2xx, not only 200.
Fixed: MPP-01 reads CAP-67 transfer events
Since CAP-67, a SEP-41 transfer to a muxed address emits its data as a map { amount, to_muxed_id } instead of a bare i128. MPP-01 read only the bare form, so a settlement to a muxed recipient would have been reported as no transfer at all. It now reads both and matches an advertised muxed recipient on the base account and the id. Checking this end to end showed the official @stellar/mpp charge server has the same gap: stellar/stellar-mpp-sdk#89.
Fixed: MPP-01 no longer blames the target for a slow RPC
The wait for the settled transaction is now measured in ledgers: it is reported missing only once RPC has closed ten more ledgers without it, and an RPC that stops advancing gives ERROR (harness) instead of a FAIL. When a target refuses the payment, the FAIL no longer says it "paid".
Changed: Node.js 22 is supported
All three packages declare "node": ">=22" instead of >=24. CI tests them on Node 22 and 24.
Fixed: wasit wallet status --role <role> exits 2 when it could not check that role
wasit wallet status --role x402 && deploy used to go ahead on a key that was never checked. With --role it now exits 2 whenever the role could not be checked; an unfunded account is an answer and exits 0.
Install
npx -y @wasit-dev/cli@0.6.0 --version
claude mcp add wasit -- npx -y @wasit-dev/server@0.6.0Testnet only. A passing result means the service behaved as the spec requires for the published checks; it is not a security audit.