Skip to content

[Advanced] Minimal Rust client for the x402 pay flow (Stellar) #40

Description

@Eras256

Difficulty: Advanced (senior · 8/10). ~16–24h. Rust + Stellar transaction signing + x402. Parallel to #32 (Go) — another language surface for the toolkit.

Context

Same gap as #32, different language: no Rust client exists for paying an x402-protected Stellar endpoint, even though Rust is the native language of the Soroban ecosystem this SDK targets.

Goal

A small, self-contained Rust crate/example under examples/rust-x402/ that pays an x402-protected Stellar endpoint end-to-end.

Scope / Deliverables

  1. Given a URL + a Stellar secret key, perform the full 402 flow: parse the payment requirements from the payment-required header, build and sign the Stellar auth entry, retry with the PAYMENT-SIGNATURE payment credential.
  2. Signing via official Stellar Rust crates (stellar-xdr, stellar-strkey, or equivalent) — no hand-rolled XDR.
  3. Config via env; the secret key is never logged — Debug/Display impls must not leak it.
  4. A clear README and a runnable example binary.
  5. Tests: challenge-header parsing + payment-credential construction against a mock server (cargo test).

Acceptance criteria

  • Pays a real x402 endpoint on testnet end-to-end — include a tx hash that resolves on stellar.expert in the PR.
  • cargo test passes and cargo clippy is clean; no secrets committed; no unwrap() on the happy path that a malformed server response could trigger.

Pointers

  • x402 v2, scheme exact; USDC SAC (testnet) CBIELTK6YBZJU5UP2WWQEUCYKLPU6AUNZ2BQ4WWFEIE3USCIHMXQDAMA; facilitator https://channels.openzeppelin.com/x402/testnet.
  • The header the client must send after a 402 (and read back from the retry) is PAYMENT-SIGNATURE — not X-PAYMENT, which is x402 v1. Every prior community submission on this repo that assumed the wrong header failed silently against the real facilitator; check the TS SDK's client if unsure.

Test target (live, verified)

Pay against Nirium's own live testnet x402 endpoint — confirmed responding today:

GET https://nirium-agent.fly.dev/api/v1/premium/signals

Returns a real 402 with a payment-required header (x402 v2, stellar:testnet, 0.02 USDC, fees sponsored). No API key needed. This is the same endpoint referenced in the SDK's own README examples.

Out of scope

  • Publishing to crates.io (welcome as a bonus, not required).
  • MPP support — x402 only for this issue.

References

Reward

Eligibility is subject to GrantFox review under this campaign. Rewards are decided by GrantFox based on quality and available budget and are not guaranteed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions