{"_id":"@agent-cards/checkout","_rev":"20-dd1d433342384f5e6a27648d58995ebf","name":"@agent-cards/checkout","dist-tags":{"latest":"0.15.1"},"versions":{"0.1.0":{"name":"@agent-cards/checkout","version":"0.1.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.1.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"27c36079958e64a36d7184bbfd39e30da94379f7","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.1.0.tgz","fileCount":10,"integrity":"sha512-nzYoCMwgcwjz7OLJiKIE4CP/Dqpeag4j32z7tyow935UVsfB1A2UBQcpbQWp3pX1KruG5p7fT7xNpqXqy46g9w==","signatures":[{"sig":"MEQCIEpAbNrGS4Og3qn8P0bs2ALBBqtE4ekDl7X23cXslIN/AiBza9Lm3NHD54BTyME71MjvyR2rXBemSQOE+Wh+0xfPYg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":26848},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"fa361e499291c0b16b4631e49bf41d9be9d58df3","scripts":{"test":"node test.mjs","build":"npx -y -p typescript@5.9.3 tsc","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.1.0_1787723400683_0.7347451042536597","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agent-cards/checkout","version":"0.2.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.2.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"9bd4215d0cea7d47a1261003a5d14714e91a2f5b","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.2.0.tgz","fileCount":14,"integrity":"sha512-gyt55XomLW9nQEwsf3HxVipf1zfdiVdQdfdzKkcSXG2kckxovOTxLohihamqEGqxFjMEoObS47DHLpzeqttQ9Q==","signatures":[{"sig":"MEQCIHOm8qHDXKJfRmsY9XqY6dd8xTnrVyt27pHfx/pDHtz1AiAwuzC+vY32yhWfQF0uolF8Qp8y6eMlWofBwrmLuphw9Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":122384},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"1142369c3c3f52fd25c4dfd96ce487fd1f106e23","scripts":{"test":"node test.mjs","build":"npx -y -p typescript@5.9.3 tsc","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.2.0_1788393292775_0.4721801524964995","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@agent-cards/checkout","version":"0.2.1","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.2.1","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"a5103b67aaf4f0642205d60000f6b54830e5f985","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.2.1.tgz","fileCount":14,"integrity":"sha512-PjBorLzza6nORAKFPs0rGo32NZpUOnvYgMm0bE9V0PV+HCbhBngrHA6wZ/VrjRpQIT8k4kYL+JPlxDXKT4f4mQ==","signatures":[{"sig":"MEUCIDRhFgfSHg+sgC8HQVqzEfnxzFVnL1hJUEs3eufGN4xLAiEAtfZTrzzerjqw0tRcUd79Z0gX6ehpkwoWnbFPpBu18Zw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDcg6MAViYcL543xIgejhTQWERS5vd9XIvAJsVdjtcHigIgPbugT8+m8g/BNGwX9fXLDk3T3NYd2a8SIXGNjAZ5lBU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":135028},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"123b75289cf8cd5546559272eeed81b4ec14a446","scripts":{"test":"node test.mjs","build":"npx -y -p typescript@5.9.3 tsc","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.2.1_1788458399134_0.3900659142931111","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agent-cards/checkout","version":"0.3.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.3.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"69d49f3fe81c083f8e7b827d6533e81aafa158e2","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.3.0.tgz","fileCount":18,"integrity":"sha512-NqIMzrDLoy7uY++3ozJq1hZ7491vAxD6q3QKYHJhuDrECR/PDIUwud2CIXOtdxltadO7RCCH2D/Xfay0zvBAdw==","signatures":[{"sig":"MEUCIGSy4H+6UrGY2oIqljRSUDTCDxnoPF0f/UhEmzlDQ7EQAiEA4fcT8xh/Punxalv0lDx075UbZZ319sQ84wD+rsro6O8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDi6xH+gfGVzGVxaJaHOyKp0rgVb+eY8fK9hHz995gZUQIgNWN1HRRMuLtTe9PBLoY1Q1dkkTezDpnAXmM0rlpHkjA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":177333},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"8b768d5f7720e7c846eaaa48827541a81762441d","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.3.0_1788724234929_0.4755186207281774","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@agent-cards/checkout","version":"0.3.1","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.3.1","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"3d26f22d1d55a334b9ce7b4d23c01334ec473b18","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.3.1.tgz","fileCount":18,"integrity":"sha512-L1ZKoMhTmbHeg3eK4+XFuYY0I6oCfVohA+w9Gzae7kkA+oOIJWwGtUScItmF315QmSolW+l1KR+VlxvN6bOHtw==","signatures":[{"sig":"MEUCIGBkXMU2jcDAN2YoUy817nPyhS0OTM9BFfdq075d2O7UAiEAhT7i6D38/uRNkw0edlh5Nb9rlz88oGAWecszDCGh9EU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCD++l8+g0YeOh7sdSXJNNGnnyTeC5ly1LONm+ymzcx0AIhAN76w9y41hC51h9TXA4Zu+drKYle4MhAMgNpH+QaBXqt","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":188556},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"90bc1db6f0c9c18f0ba34f824ccd99611ff6f15a","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.3.1_1788734057373_0.6248064815673964","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@agent-cards/checkout","version":"0.4.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.4.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"38f6aec7fe84346f38af692c6767b9e4cde0e1c2","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.4.0.tgz","fileCount":20,"integrity":"sha512-5+rmm1h8QPbbWDc4XzHuFRo3ymZQjFpzMoBLMkSisnboAayAxPFhwiIVqbpBkNoAgwwzszUIkR2zQP0MSsFluA==","signatures":[{"sig":"MEUCIQCl0iWqVOW82N52/nnUXCsIEVHl+JbL6rl8r3NOJwy6oQIgR9i8IHo5WswTTvjStIS/5uuZXyEXwNzXqR4UqJxMLG4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDoBb6iM+6Ko/N5eW6ny4OlFcshF8WLDqf0EQZZM7i6NAIhAIUXVsndMqqpJKsHxIsY1E9o+l+pOlGCYMm+y0Hd2B2g","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":219100},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"bd2bc29048adcd980c2d2adb0a0320c791172aae","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.4.0_1788759613959_0.9223328497896313","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@agent-cards/checkout","version":"0.4.1","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.4.1","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"564fa47b66c8c6eddd63d2bb73a2a28a3b8a4c64","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.4.1.tgz","fileCount":20,"integrity":"sha512-Uc+/1o+EP3auTlAqNDXSxlTo7vcuW4OXXkBmieINXDOq/OZrgLoQMpgvog8KiYYJs4YoA4/xnoVeD624QHdlsg==","signatures":[{"sig":"MEUCIQCsDMUKCvVfpG60vlNLW0NhoHKoI3Z9lRe+P8kzM4BpTgIgYUEZuC9HRQhyD0pC3CF8730eI2N7HkzHsLfZc8/x9jE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCFUZyaPGOe6LsfzwHLQK3kjKNwLNKtNuKPnbtjK+hgSQIhAJIbRxO+NEvQ+4WHcHhYYxSA6DlT4sBuS9sQYccBvCdO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":222969},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"2b4f4f8a0081f4d1210134f34a5a07a13e5d9c25","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.4.1_1788901181444_0.004825812649346561","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agent-cards/checkout","version":"0.5.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.5.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"d14100bff5f3ec68b5eb5801ba4edbb741fdde93","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.5.0.tgz","fileCount":24,"integrity":"sha512-goCdkoUCWlQPsmwpsU9Tm82F3HQNwpPq6vDRYwTs9vS72Ovf99Xf2MNR96vCw4gxOk5nIzl11ebde8wcvMKKSw==","signatures":[{"sig":"MEUCIDvDJTGm1PwoJSRAk2pRcVNxeBOzwv+6tEQCs/toQV90AiEAw2QG+iKvZwNBc4WsVpi7TrnPKVgPJtnCvutxZN0V99k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQC8v+FnBiyWPvUOELJpkvLaHSGQkM0uAhrqJUF455yEcwIhAIxkRliIekQLZSiTCOtY7ir+NzAeHCvfIxvbke3oHI9E","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":239884},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"8135a545b4a721d3dc3578c94f11625eb495906a","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs minimum-delay.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.5.0_1788988508248_0.4185930382932683","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@agent-cards/checkout","version":"0.6.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.6.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"b3204789d1f442b17af9b796833b9537c36bb65d","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.6.0.tgz","fileCount":26,"integrity":"sha512-onrUPw0jH3eKo5Tj+e6D8bFe5ZffyPqsf13SssMKif6nUsQD3+S9BhTXJxFhV8VIruDVS69VHR2n38Ao8K+7MA==","signatures":[{"sig":"MEUCIQCZf/ue1logipPiYexX1ZzCmh2CkDjVfYNI+mRyAQ7/qwIgAVOB4HNIDS+oHptTAPx3k4rjQ9+Hm8bnwfByGqB6N1c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIACHb/x95PunNqRtGMBxut9Lp7tMCooOa1m6msIYULK+AiEAjsgPGz11TwwZdKpkOaYlz/ySTyQG0e65dLI2CSk0m9g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":257945},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"b43f5a7425dacbfa24c8d6c662c6439f6506fde3","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.6.0_1789007596835_0.5375260688778583","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@agent-cards/checkout","version":"0.7.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.7.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"f5bbe15e3aa3322d1bd9a3d90a65f8cbc8e8c101","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.7.0.tgz","fileCount":26,"integrity":"sha512-hMN5dl8v0CGRwlBel5+ZsXuwYx5wfyTA/5LRAok4Q18gIn9yHSqcqIbJ7EZQ4KNTks3Pm2y80K+2G0icciKDRg==","signatures":[{"sig":"MEQCIAZzWQEhY0ES15FIcKchRDN2XRF/a4mLMg01/ITHj1y5AiA7gTYDwpRdianJsCvnpso7P25k/vSzo8IS+CPAPZQ1Bw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGOxANaCUsyjWidD4zIpa1Sso+bkxrqzPQWnVOwan8FxAiBUpEBsRRs20NEUgMNpgFiI6vhV0AjVqFB2x2xA+CC3xw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":272456},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"a7ee26caaa3489d36bd3e79aa4b72209414fbe12","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs","build":"npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs","_comment_build":"TypeScript is fetched rather than declared as a devDependency ON PURPOSE. This package ships zero dependencies, which is why pnpm writes no importer for it in the workspace lockfile; adding any dep here creates one, and an importer the lockfile has not been regenerated for fails every Vercel build with ERR_PNPM_OUTDATED_LOCKFILE. Pinned so the published output is reproducible.","prepublishOnly":"pnpm build"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.7.0_1789079102719_0.7357840263192601","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@agent-cards/checkout","version":"0.8.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.8.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"8c0a206662acba538c64b1791fc73f2a6dd8ad3f","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.8.0.tgz","fileCount":34,"integrity":"sha512-lKHLw6DkjOa1s2vYwWgsfjSLlHl3sxYwNmnJ7AXfTh5CZYRv412Zgvih6xVTiylRI084/ltYNu0pYW9cZDnjlw==","signatures":[{"sig":"MEYCIQCzWqgCaIYt2Ql6mgazURttjVgak7pd9koc3KPeXnLT4QIhANbbfS73W5CjUJ1lV3Q4PVE3IuFM7BeLkhaGsr07k7i2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGyhgSnzBeCsD+cH3OnJI4Hs7Q9U4e56yzXpgb9djolmAiBYn47KeQww/TmDgy9KdbmzxWCgZKgLhEeqL+nMQZjckg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":287242},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./playwright":"./dist/cdp.js"},"gitHead":"82bcfd7f7e630f39ad12978ece8066601fda4d1f","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","check:payment-core":"node scripts/generate-payment-core.mjs --check"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.8.0_1789148158417_0.1848951352680468","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@agent-cards/checkout","version":"0.9.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.9.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"0fbd550d253aebb4705ef46fb2943a8fd17dbd55","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.9.0.tgz","fileCount":56,"integrity":"sha512-1lO2T4Nz63qPXolGxuUpWdUOBV732dYZ/xYyiR9O1m6CsVg+z2dhsCtNUR4+fDFKlG7o0b9x/Vi+rdxg9WVk3g==","signatures":[{"sig":"MEUCIGRIJ31h84wolpqnur/Rg26QxaJRs2bSNjsg3MbNRffMAiEAsNF87m6shGGNigFpEBVEbg+nl1Lwwqk3QMJ2RmHh1NY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIBXg4vpWp1so0QJBBvSlx/G2rqZr3zaY5najwKXmcU1KAiBCi8iT6meubF+wf5PsOy9KR1PWbWbWeSc4f7j1HJB9sQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":800362},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"94aab03b915bb7d4ee1ec690139378e2667ae394","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.9.0_1789165417945_0.11304582744979053","host":"s3://npm-registry-packages-npm-production"}},"0.9.1":{"name":"@agent-cards/checkout","version":"0.9.1","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.9.1","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"99335e531d296aa4ff7c68a91425b71595354a34","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.9.1.tgz","fileCount":60,"integrity":"sha512-8VGGbMXMr/yLzUUCYQvS+ydnc7n6Dznns4VMM/wsy2nD6Xp2Zg8DmbBnTDRlnOqriuhB+z5Z/mNJYfubsxM63A==","signatures":[{"sig":"MEQCIGnJiYFxZvgcD4tr3QLvQfwUh8524DCEjRR6JdqK0Us9AiABOzamW21Pke+vDku1XOgiswbqgdVTnAysHRXznZKcUg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCN8Izm1TlMI6LreCq7zHlr7bFsCqD2YywVR/JlF8pQSAIgDtSW5/tAvMTWVtOuTs8W8PlqCuTMPDnLKKTIADWB6TA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":834340},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"417e34b775d56945e676a174dc4a4adffc7cc606","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.9.1_1789172662823_0.45792662845680643","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@agent-cards/checkout","version":"0.10.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.10.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"2b064eb3e1a0f4b4addaf5ad896d5d2819671a39","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.10.0.tgz","fileCount":68,"integrity":"sha512-XmI1GT5JPTh4/7zJ3lotNv2PyJaWlb2q2K+0h4sOt/VDupXIilnAGjPPNvOb045X8P/sGoE4YWFEhAzuZaoPkQ==","signatures":[{"sig":"MEQCIENPFiFC+/j2LT/K3+WR8pGth8jfUMz9UcJa41+KNkTFAiANxs+Htn6mVnR4N1hdEnEyCQ2OIUmd+HsIVQx/2a6lhw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIE1cXqBU9p68e9PRg1WSZzWKIAnB/jB83bHtG488jwDUAiEA2YOr2xlxFmT3P61hjOl80hBloDimJbOLT+Zw2sxoLUA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":939556},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"7613a1a0f7031c11b768ea56c4628ede58ddfd70","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.10.0_1789342117898_0.7424533419379535","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@agent-cards/checkout","version":"0.11.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.11.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"deff63c607ea20945772ec1be79e43a27847fa47","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.11.0.tgz","fileCount":70,"integrity":"sha512-4/Ua4o1CvCU4mumgEMWUg2IiUnPPHM6QJgCML6xaz8nSt8H08XpkZY8jggt/9sABDYKV7GBMNLa8wFQKxf5QEQ==","signatures":[{"sig":"MEYCIQCAOdzXkjs5IP+Z3tl6omCrcDQv9ePq38rdEjWbzcqbugIhAOBJWhgPVvnB24WFiSe6pkNNeb3qdckfjMaonH1EmTSn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDl4oiI3Zb3NXEM5kgiNZr3LkcMX+RrziHM6tT1CZy2uQIhAIl1VbHmWldz9Dh4QNEintDJKRivSCPdY6DMfOKw88tJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":957944},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"54f7ea3f284bae4f3c624096a0901aa46d1dfcb5","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.11.0_1789414857409_0.5209103244257907","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@agent-cards/checkout","version":"0.12.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.12.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"c9df61119fa4b7ce8c344f9bbf2fbd1ef61c4fff","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.12.0.tgz","fileCount":70,"integrity":"sha512-j3s2EEow29+10n1UXWb9HU8k+Dmmv+hinjKJAK+2t85P9E9ZtHUBgnBRDJERlq3GZr5CWE9jV7IOCYa1AjzsFw==","signatures":[{"sig":"MEYCIQDfU0HK8Ysrr0pz8AtYBg2Eu5x1pAWXk9Rj0KddO9VMygIhAMuo9dXX003qT4rbpWOTk5yyMSUysmboMoZNLaAWEe99","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQChum7De7uJ9rwDZ46hWxCVGnrgATt99NTeduPTdxKJ7AIhAJMNfOpQSkilkY2vlQRtcOuxfHLnEGwWvdXZbu99hDfE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":968069},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"2d09acb327254ae71f1d6a819458907a7ce8e24b","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs && node --test ../vault/scripts/recurly-validation/watch-duty-sdk-result.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.8","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.12.0_1789432245933_0.5956428368310351","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@agent-cards/checkout","version":"0.13.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.13.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"c220bae15f95a2c73c3052700e0ad1e67f35bc76","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.13.0.tgz","fileCount":70,"integrity":"sha512-aKxEgORUOZMs93CsZUtJCU/hIvfgriSbTOKGZvmAv9+GXUyCzbVaKPo4HGWxk+R4+SpwiQEZuLyGzsEuwfk8JQ==","signatures":[{"sig":"MEYCIQCUTN90e1vboI8l8xzV8xWAzMtHp7eAo4hL8nhliUWhBgIhAKeZB1D0Op98fdDm0sSR2nNfA4JnXJE2+w6VW9wpmr7o","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIH6ogYnJiprZ6lr66Wmyv1uBZTp+6s10sOGnRk6t8WAZAiEAzF74Yv00pI6GF11H2odrClaIoevqI9d7L/SxwAeFG94=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1010747},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"2cf3cb02403192014c071e711bc7ee29a4fdcdbf","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs && node --test ../vault/scripts/recurly-validation/watch-duty-sdk-result.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.4","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.13.0_1789527287555_0.3578056509807115","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"@agent-cards/checkout","version":"0.14.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.14.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"44708a20eda7b39234a464406dba994f76c039b8","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.14.0.tgz","fileCount":72,"integrity":"sha512-CqTc2QUdHy6y9kiejYRRbS02+hWz/5mIVlxwW7qecPgNv3RyHXUS96fjiu+H73Sp9CAQzLpG/7SUNWaKsnzRXA==","signatures":[{"sig":"MEQCIAuk75wInaD3TJ1+r/OEne2TR8zYU9h4oIsv/2MU/di5AiBKWWdIfCv1pENrOMdw4N4SRks+QykUjgsnuHiz7NHKQQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFVRfWAeLOMDlXKo7Y3NwGd2HRX4fh8duk/MeRybN+CZAiEAhthXqNelMUf1QQHSMtIhq2bC+z5sSEe6QPMBMyL7/1c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1046158},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"9503e0e84e4548854bdf1c0a13f9a1abdeb658a4","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs && node --test ../vault/scripts/recurly-validation/watch-duty-sdk-result.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs && node spreedly-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.4","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.14.0_1789621548151_0.5634311559266276","host":"s3://npm-registry-packages-npm-production"}},"0.15.0":{"name":"@agent-cards/checkout","version":"0.15.0","keywords":["payments","agents","browser-automation","pci","checkout"],"license":"UNLICENSED","_id":"@agent-cards/checkout@0.15.0","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"dist":{"shasum":"9fcaa128c007addcfac7148eb6497f18453ecdec","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.15.0.tgz","fileCount":74,"integrity":"sha512-9SZNaVAvOAIVwcnrjK/FF3JE5d0qJz5VDNabIKH9nGqJ0dxINjYYP/tr2ain5XDcJ6EZbv55Cu6LreBQ4DVubQ==","signatures":[{"sig":"MEYCIQD6Wf9q4XYGJcmoc5NEARj6xxS9VzfXTdCI+KZpp9xe+wIhAOUqXftuWt5+xcLYp1m0DvHmCMRefonrW6SIWV0jz2hJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIDLIpnr7nCNTNhbmR81KLekZpKP5N4kCIM1IHfVe09VIAiEAzgtSJxzYLMT5GPXUbFLODandeuZlaNegROTTllqoay4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1055874},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"f3babfe255ee8eb14a89dae06387e17460dd8905","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs && node --test ../vault/scripts/recurly-validation/watch-duty-sdk-result.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs && node spreedly-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"_npmVersion":"10.9.4","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/checkout_0.15.0_1789660599439_0.7783305155831246","host":"s3://npm-registry-packages-npm-production"}},"0.15.1":{"_id":"@agent-cards/checkout@0.15.1","dist":{"shasum":"4f4fa0e02f7cc3059e4d34bb780d14ff000ba7fa","tarball":"https://registry.npmjs.org/@agent-cards/checkout/-/checkout-0.15.1.tgz","fileCount":74,"integrity":"sha512-TnJl1ovctm5817/f/qQ7uaSu47qaGsOBCY+1gqRHQsRqZF2syp98xWk8IjPIBLRMjILy+I5DEmuCyN/hY66vlA==","signatures":[{"sig":"MEUCIHmyUE7BpvoGm0ZXVsGmx7CLFSivR/SnHdCaPqL6fyC/AiEA4rjZnU9lacaS+gKrSAsHYh9TKrarRiPfqDOa5MlfspA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHy4XnJ5b2PeFqXb/mMavAgqvpFnF3EoSFuNIJABVIiPAiBWbBUHGO0oQH/cTwk4jdqGWsxOKy5EfyxI35baK67hvg=="}],"unpackedSize":1057971},"main":"dist/index.js","name":"@agent-cards/checkout","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"exports":{".":"./dist/index.js","./cdp":"./dist/cdp.js","./preflight":"./dist/preflight.js","./playwright":"./dist/playwright.js","./preflight/catalog.json":"./dist/preflight-catalog.json","./preflight/schemas.json":"./dist/preflight-schemas.json"},"gitHead":"f4922a2f1ad93ae1569d829be84050b15ba18878","license":"UNLICENSED","scripts":{"test":"node test.mjs && node --test lifecycle.test.mjs merchant-abort.test.mjs preparation.test.mjs braintree.test.mjs autopilot.test.mjs stripe-checkout.test.mjs payment-core.test.mjs prepared-processor.test.mjs minimum-delay.test.mjs paysafe.test.mjs attachment.test.mjs mercado-checkout.test.mjs mercado-polling.test.mjs && node --test preflight-package.test.mjs preflight-collector.test.mjs && node --test kernel-native-qualification.test.mjs && node --test ../vault/scripts/recurly-validation/watch-duty-sdk-result.test.mjs","build":"node ../payment-core/scripts/build.mjs && node scripts/generate-payment-core.mjs && npx -y -p typescript@5.9.3 tsc && node scripts/generate-preflight-contract.mjs","pack:preview":"node scripts/pack-preflight-preview.mjs","test:browser":"node browser.test.mjs && node stripe-browser.test.mjs && node preparation-browser.test.mjs && node owned-shop-browser.test.mjs && node spreedly-browser.test.mjs","_comment_build":"The public SDK keeps zero runtime dependencies. Its build vendors deterministic metadata and substitution artifacts from the internal payment core; TypeScript remains pinned.","prepublishOnly":"pnpm build","test:preflight":"node --test preflight-package.test.mjs preflight-collector.test.mjs kernel-native-qualification.test.mjs","check:payment-core":"node scripts/generate-payment-core.mjs --check","check:kernel-native":"node examples/preflight/kernel-native/qualification.mjs inventory --check","test:preflight:browser":"node preflight-browser.test.mjs","test:preflight:schemas":"node --test preflight-schemas.test.mjs"},"version":"0.15.1","_npmUser":{"name":"pipeabello","email":"f@kasegu.llc"},"keywords":["payments","agents","browser-automation","pci","checkout"],"_npmVersion":"10.9.4","description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","directories":{},"maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/checkout_0.15.1_1789663416344_0.44443872082108604"}}},"time":{"created":"2026-08-26T05:50:00.589Z","modified":"2026-09-17T16:43:36.657Z","0.1.0":"2026-08-26T05:50:00.863Z","0.2.0":"2026-09-02T23:54:52.930Z","0.2.1":"2026-09-03T17:59:59.217Z","0.3.0":"2026-09-06T19:50:35.027Z","0.3.1":"2026-09-06T22:34:17.477Z","0.4.0":"2026-09-07T05:40:14.047Z","0.4.1":"2026-09-08T20:59:41.524Z","0.5.0":"2026-09-09T21:15:08.370Z","0.6.0":"2026-09-10T02:33:16.918Z","0.7.0":"2026-09-10T22:25:02.808Z","0.8.0":"2026-09-11T17:35:58.510Z","0.9.0":"2026-09-11T22:23:38.050Z","0.9.1":"2026-09-12T00:24:22.938Z","0.10.0":"2026-09-13T23:28:37.995Z","0.11.0":"2026-09-14T19:40:57.759Z","0.12.0":"2026-09-15T00:30:46.028Z","0.13.0":"2026-09-16T02:54:47.649Z","0.14.0":"2026-09-17T05:05:48.281Z","0.15.0":"2026-09-17T15:56:39.551Z","0.15.1":"2026-09-17T16:43:36.478Z"},"license":"UNLICENSED","keywords":["payments","agents","browser-automation","pci","checkout"],"description":"Let browser agents pay with the user's own card, without your infrastructure ever touching card data.","maintainers":[{"name":"pipeabello","email":"f@kasegu.llc"}],"readme":"# @agent-cards/checkout\n\nLet your browser agents pay with **the user's own card**, without your\ninfrastructure ever touching card data.\n\nYour agent drives checkout normally. When the page tries to tokenize a card, we\npause that one request, ask the cardholder to approve on their device, and their\ndevice supplies the card and calls the merchant. You get back the response to\nreplay. A real card never enters your process, your logs, or your network.\n\n```\nyour agent ──drives──> merchant checkout\n                            │ tokenization request\n                            ▼\n                    [ paused by this SDK ]\n                            │  template only, dummy card\n                            ▼\n                  Agentcard ──notify──> cardholder's device\n                                             │ decrypts card locally\n                                             ▼\n                                     merchant's card vault\n                            ┌────────token────────┘\n                            ▼\n                    [ request resumed ]  ──> order completes\n```\n\n## Install\n\n```bash\nnpm i @agent-cards/checkout\n```\n\nUpgrading from 0.2.x? Read the [migration notes](./CHANGELOG.md), especially\nthe unknown-outcome, cancellation and browser-context requirements.\n\nTo inspect a checkout before card entry with SDK `0.9.0` or later, read [Check checkout support](./PREFLIGHT.md).\nThe read-only helper detects all 23 registered PSPs and reports processor support separately\nfrom an identified checkout flow. Kernel native coverage requires its own capability profile.\n\n## Use it\n\nTwo lines against a CDP session you already have:\n\n```ts\nimport { VaultClient, attachToCdp } from '@agent-cards/checkout';\n\nconst vault = new VaultClient({\n  clientId: process.env.AGENTCARD_CLIENT_ID!,\n  clientSecret: process.env.AGENTCARD_CLIENT_SECRET!,\n});\n\n// Pull the current processor list. attachToCdp arms the browser from it, so\n// without this you only intercept the processors built into your installed\n// version. Safe to call on every run: a failed fetch keeps the built-ins.\nawait vault.syncRegistry();\n\nawait attachToCdp(cdp, pageSessionId, {\n  vault,\n  user: 'usr_123',                 // whose card should pay\n  merchant: 'vanman.shop',\n  amount: 583,                     // your hint, an integer in the currency's smallest unit (or a decimal string: '5.83')\n  currency: 'usd',                 // \"$5.83\" is derived for the approval screen\n  onApprovalUrl: (url) => sendToUser(url),   // SMS, push, email, iMessage: your call\n});\n```\n\n`amount` is your hint: an integer in the currency's smallest unit (583 for\n$5.83), or a decimal string in normal units ('5.83'), with `currency`. The\nprocessor's own amount is the higher authority: Agentcard reads it from the\npaused request where the processor puts it there, or from the Stripe intent\nthe request names, right before the cardholder's device replays, and the\ncompany's caps are judged on it. A hint lets a bad purchase be refused the\nmoment it opens; a hint more than one smallest unit away from the processor's\namount is refused with nothing charged (`AmountMismatchError`), and after the\nreplay the charge is reconciled against the approval\n(`ReplayResponse.amountVerified`, `chargedAmount`, and `chargedKind`:\n`captured` for a succeeded intent's `amount_received`, `authorized` for a\nmanual-capture intent's `amount_capturable`, `none` when nothing is collected\nyet; plus the `checkout_authorization.amount_mismatch` webhook to your server\nwhen the charge disagreed). Every result carries `amountAuthority`:\n`processor`, `agent`, `page`, or `none`. A display string is never sent;\nAgentcard derives it.\n\nThen let your agent click \"Pay\" like it always does. `attachToCdp` pauses the\nrequest for approval and resumes it only while the merchant request remains\nlive. Merchant timeouts still apply: Square's observed tokenization deadline\nis about 10 seconds, Braintree's native request timeout is 60 seconds, and Adyen Web's own request timeout abandons its Sessions payment call 60 seconds after Pay (observed on Adyen Web 6.41 and 6.44), each including approval and handoff. These are the processors' limits, not ones the SDK enforces: the SDK's own authorization wait stays 15 minutes. For human approval, use\n`controller.prepare()` before the first Pay action as shown below. For Adyen, `prepare()` moves the approval before Pay, so only the device-side encryption runs inside Adyen Web's minute.\n\nPlaywright:\n\n```ts\nimport { attachToPlaywright } from '@agent-cards/checkout/playwright';\nawait attachToPlaywright(page, { vault, user, merchant, amount });\n```\n\n## Credentials\n\nUse your **OAuth client credentials**, not an `sk_` API key — those are retired,\nand the checkout endpoints reject them (`client_credentials_required`) because an\nauthorization is bound to the confidential client that created it. The SDK does\nthe `client_credentials` exchange for you, caches the token, and refreshes it\nonce on a 401. Create a client from the dashboard Credentials page or with\n`agent-cards-admin oauth-clients create`.\n\n## Why you need the SDK and not just `Fetch.enable`\n\nCard fields render in **cross-origin iframes**, which are separate CDP targets.\nEnabling `Fetch` on the page session never sees the tokenization request. You\nneed recursive `Target.setAutoAttach({ flatten: true })` on every nested target,\nthen `Fetch.enable` on each, then `Runtime.runIfWaitingForDebugger` to unpause\nthem. That, plus which headers a merchant requires you to replay verbatim, is\nwhat this package encapsulates.\n\n## What runs where\n\n| | Sees the real card |\n|---|---|\n| Your agent / browser | **no** — only a dummy PAN and a token |\n| Agentcard servers | **no** — a request template and a token |\n| Cardholder's device | yes — decrypts locally, calls the merchant directly |\n\nBecause your process only ever handles a dummy card and an opaque token, this\nintegration is designed to keep you out of PCI scope. Get your own QSA's read\nbefore you put that in writing.\n\n## Supported processors\n\nCoverage is specific to the processor request format, merchant setup, browser transport and follow-up flow. A recognized endpoint is not proof that every store using that processor completes checkout.\n\n| Processor | Status |\n|---|---|\n| Shopify | supported, verified end to end |\n| Stripe | tokenization replay and direct card-bearing PaymentIntent confirms are implemented; direct confirms read the intent's amount back from Stripe; a hint sent as `amount` + `currency` must agree with it. Browser token-to-intent continuation is unsupported and held. Validate the exact merchant flow before pilot use |\n| Braintree card tokenization | Prepared checkout supported; one live Haymarket Books ebook purchase with SDK `0.5.0` confirmed merchant fulfillment and SDK `completed` using a merchant receipt resolver. Independent processor capture/settlement, live 3DS and PayPal wallet flows remain unverified. |\n| Checkout.com | supported |\n| Mercado Pago | Card tokenization and prepared checkout are implemented. Guest Checkout Pro in Mexico also corrects the issuer for one native card association when the selected card has the same brand and type. One live MXN 40 Lotería Chida purchase with published SDK 0.10.0 completed automatically through Pay; the merchant confirmed paid status and PDF fulfillment. The historical SDK result remains unknown because the private receipt adapter rejected a relative download URL; a separate read with the corrected adapter confirms that same paid receipt. Independent processor capture/settlement and other country or integration paths remain unverified. |\n| VGS Collect (Very Good Security; Wolt) | not supported: VGS's proxy aliases only submissions from its own iframe, so a replay from the cardholder's device is refused by the merchant (verified on Wolt, 2026-09-03). Not recognized, so the agent's browser is not paused there |\n| Adyen | supported (mode `cse`): the vault encrypts the card for Adyen on the cardholder's device and your browser sends it. Sessions flow only: the paused request is `/checkoutshopper/v1/sessions/{id}/payments` on Adyen's own hosts; a merchant that posts the encrypted fields to its own server is not recognized, so nothing pauses there. Without a preparation, approval starts at Pay and must land before Adyen Web's own request timeout (observed at 60 seconds on Adyen Web 6.41 and 6.44; not enforced by the SDK); `prepare({ psp: 'adyen' })` moves the approval before Pay |\n| Tranzila | supported (mode `hosted_form`): the cardholder finishes on Tranzila's own page; the paused form navigation resolves to a synthetic page, and you poll the merchant's order state |\n\nThe recognizer list is fetched from the API at runtime (`vault.syncRegistry()`),\nso new processors work without you shipping a release. `attachToCdp` derives the\n`Fetch.enable` url patterns from that same list rather than a constant, which is\nwhy the sync call belongs before the attach. `vault.cardUrlPatterns()` returns\nthose patterns if you arm a CDP connection yourself. Call\n`GET /v2/checkout/recognizers?modes=token,cse,hosted_form` for the list that is\nlive right now.\n\n## Modes\n\nEach recognizer carries a `mode` (absent means `token`), and every authorization\ncarries the mode it was handled in. The adapters do the right thing for all\nthree; the difference matters if you drive `authorize()` yourself.\n`ReplayResponse` is a union, so branch on `mode`.\n\n- **`token`** (every processor but Adyen). The cardholder's device calls the\n  processor and reports its answer; `authorize()` resolves with `status`,\n  `headers` and `body` to fulfill the paused request with. The browser checks\n  a fulfilled answer exactly as it checks a real one, so when the page called\n  the processor cross-origin (Stripe always does: Checkout on\n  `checkout.stripe.com` and Elements in the `js.stripe.com` frame both fetch\n  `api.stripe.com`) the answer must carry `access-control-allow-origin` for\n  the request's own `Origin`, or the page's fetch rejects and the checkout\n  reports a connection error even though the cardholder approved. The\n  adapters add those headers (`corsHeadersFor` + `withCorsHeaders`, exported\n  for a runtime that fulfills by hand, and `corsDecision` when you also want\n  the reason) and report the decision on the `authorized` event as `cors`:\n  `echoed`, `same_origin`, or `none` (no usable Origin on the request, so\n  the page could not read the answer). Only what a browser serializes is\n  echoed: one canonical http(s) origin, or the opaque `null`. Shopify's\n  card iframe posts to its own origin, so it never needed them.\n- **`cse`** (Adyen). Adyen's own page SDK encrypts the card before the request\n  leaves the browser, so the paused body carries ciphertext. The cardholder's\n  device produces the same ciphertext under the merchant's Adyen public key\n  (fetched by Agentcard from Adyen's host when the request is parked) and\n  `authorize()` resolves with `substitutions: { encoding: 'json', at, fields,\n  remove }`. Write them into the paused body with\n  `substituteEncryptedFields(body, substitutions)` and CONTINUE the request\n  from the same browser (`Fetch.continueRequest` with the rewritten\n  `postData`, or Playwright's `route.continue({ postData })`): its session\n  data, risk data and cookies must stay its own. Only the four encrypted\n  fields change, and the siblings named in `remove` are dropped (Adyen's\n  `brand`, which adyen-web derived from the dummy digits the agent typed:\n  left in place it names the wrong card and Adyen refuses the mismatch;\n  absent, Adyen reads the brand off the card it decrypts). A body that lacks\n  the fields throws `SubstitutionError`, which is not terminal. Adyen answers the browser,\n  so `charged_kind` is null on the approval and the merchant's order state is\n  the outcome to poll.\n- **`hosted_form`** (Tranzila). The processor's hosted card form submits the\n  card as a TOP-LEVEL form post, so the paused request is a page navigation\n  (the adapters arm `Fetch.enable` with no resource-type filter and attach the\n  processor's iframe, which is how a Document request on `direct.tranzila.com`\n  gets paused at all). The cardholder's device rebuilds that form with the\n  real card and submits it itself; the processor answers the device, and\n  `authorize()` resolves with `{ mode: 'hosted_form', kind:\n  'submitted_on_device', outcome: 'unverified', submittedAt }` once the\n  device reports the form left. **This is not an approved payment.** The\n  stamp is the cardholder's device attesting that the form left it;\n  Agentcard holds no processor evidence on this mode and cannot obtain any,\n  so the API finishes the authorization as `submitted_on_device` (never\n  `approved`) and sends your server `checkout_authorization.submitted`\n  (never `.approved`). Treat it as \"the person paid, or tried to, on their\n  own device\" and confirm the order with the merchant before you count it.\n  There is no response to replay: FULFIL the paused navigation with\n  `hostedFormSubmittedPage({ authorizationId, merchant, submittedAt })` (200,\n  `text/html`, `x-agentcard-checkout: submitted_on_device`, a `<meta\n  name=\"agentcard-checkout\">` and an inert JSON block saying \"submitted on\n  the cardholder's device, payment unverified, do not resubmit\"), the way\n  the adapters do. Do not abort it: an aborted navigation renders nothing,\n  the iframe silently keeps its dummy-card form, and the agent's next move is\n  to click Pay again. Do not fake the processor's result page either: this\n  SDK does not know the outcome. The adapters emit `submitted_on_device` (not\n  `authorized`), refuse a byte-identical re-post of the same form for 15\n  minutes (`hostedFormRepeatQuietMs`), and the API answers a regenerated one\n  with `409 duplicate_submission`, which the adapters quiet the way they quiet\n  a decline (`approvalCooldownMs`): the page's immediate re-posts are refused\n  without a round trip, and once the prior authorization is declined or\n  expired the same form is a new question. Confirm the order with the\n  merchant, which learns the outcome from the processor.\n\n`syncRegistry()` asks the API for `SUPPORTED_MODES` only\n(`token,cse,hosted_form`), so a processor whose flow this build cannot finish\nis never paused; the API serves `hosted_form` entries only to callers that ask.\nA registry mode this SDK cannot finish throws `UnsupportedModeError` before\ncreation. An approval returned in an unexpected mode has an unknown outcome\nand holds the attachment for reconciliation. The `authorized` event's detail names\nthe `mode`, the `authorizationId` and, for `cse`, the `fields` that were\nsubstituted; it never carries ciphertext. The `submitted_on_device` event's\ndetail names the `authorizationId`, `submittedAt` and `outcome:\n'unverified'`; it is not an `authorized` event and must not be counted as\none. `amountAuthority` on every replay is `stripe_payment_intent`,\n`hosted_form_sum` (the form's own amount) or `display_only`.\n\n## Errors worth handling\n\n- `ApprovalTimeoutError` — the server confirms the authorization expired without a replay attempt. A local deadline is different: `PaymentOutcomeUnknownError` means the approval link may still be valid, so reconcile the merchant order before another attempt.\n- `ApprovalDeclinedError` — the user said no.\n- `AmountMismatchError`: the processor's amount did not match the amount the\n  user was (or would have been) asked to approve. Nothing was charged. An\n  `ApprovalDeclinedError` with `expectedCents`, `actualCents`, `currency`,\n  `code: 'amount_mismatch'` and `stage`: `'pre_replay'` (checked right before\n  the device would have sent the card; `authorizationId` names the declined\n  authorization) or `'create'` (the intent already disagreed when the request\n  was parked; no authorization exists, `authorizationId` is null). Per\n  request, not per page: a merchant can still update an intent's amount\n  until it is confirmed, so the adapters quiet the page's immediate retry\n  and judge the next request afresh instead of latching.\n- `IntentNotConfirmableError`: the PaymentIntent was already charged, is\n  processing, or is authorized and on hold (or canceled), so Agentcard\n  refused to replay a confirm at it. An `ApprovalDeclinedError` with\n  `code: 'intent_not_confirmable'`. Deliberately not \"nothing was charged\":\n  check the intent at Stripe before retrying.\n- `ProcessorRefusedError`: the cardholder's device reported a processor\n  request rejection. `pspErrorCode` carries the processor's code; optional\n  `processorError` carries bounded Razorpay reason, source, step and payment/order\n  identifiers when the API has them. A generic code such as `BAD_REQUEST_ERROR`\n  does not establish an issuer decline or prove no money moved. Reconcile the\n  merchant payment before retrying. This remains an `ApprovalDeclinedError`\n  with `code: 'processor_refused'` for compatibility.\n  The attachment records `status: 'declined', reason: 'processor_refused'`\n  and holds further card requests. After confirming merchant failure, call\n  `retryAfterMerchantFailure({ status: 'failed' })` to permit a deliberate new\n  attempt immediately, without waiting for the user-decline cooldown. Do not\n  automatically create a new attachment after this error;\n  the guard applies only within the existing attachment.\n- `CheckoutApiError` with `code === 'amount_unverifiable'`: Stripe could not\n  be asked (502; the SDK retries twice, 500ms then 1500ms, before throwing)\n  or the paused request lacked its client secret or publishable key (400).\n  `code === 'intent_not_confirmable'` at create (409) means the intent was\n  already used; the adapters stop intercepting for that page.\n  `code === 'cse_key_unavailable'` (502) means Adyen did not answer the\n  public-key fetch and is retried the same way; `cse_client_key_unknown`\n  (400) means Adyen does not know the merchant's `clientKey`, and\n  `cse_template_unsupported` (400) means the paused body carries no\n  encrypted card fields to fill (a stored card, a wallet, a single-blob\n  `encryptedCard`); both are terminal for that page.\n  `hosted_form_template_incomplete` (400) means the paused form lacks a\n  field the device fills or the processor requires, `hosted_form_gated`\n  (400) means it carries a live captcha token the device could never\n  re-submit, and `hosted_form_field_refused` (400, with `field` and a\n  `reason` of `stored_credential`, `not_a_sale` or `callback_host`) means\n  the form asks the processor for something other than one plain sale\n  reporting to the merchant you named (a reusable token in or out, a sale\n  mode that is not a sale, a callback URL off the merchant's host: name the\n  merchant by its hostname when the form carries callback URLs); all three\n  are terminal for that page. `duplicate_submission` (409,\n  with `prior_authorization_id` and `prior_status`) means this exact\n  submission already has, or already had, its prompt: the adapters quiet the\n  page's re-posts for `approvalCooldownMs` (no second notification for one\n  payment) and judge the next request afresh, since the prior authorization\n  declines or expires and the same form is then a new question.\n- `CardEncryptedError`: this processor encrypts the card in-page and its\n  registry entry does not (yet) say the vault can produce that ciphertext;\n  route the purchase to an Agentcard-issued card instead.\n- `UnsupportedModeError`: the registry requests a mode this SDK cannot finish\n  before an authorization exists. Upgrade. An unexpected approved mode instead\n  raises `PaymentOutcomeUnknownError` and requires reconciliation.\n- `SubstitutionError`: a `cse` approval could not be written into the paused\n  body (the four encrypted fields were not there). The request is failed and\n  the next one is judged afresh.\n\n## Building this package\n\nIt declares **no dependencies**, matching `packages/vault`, so the workspace\nlockfile needs no importer entry for it (a new package with its own deps cannot\nbe installed here without regenerating the lockfile, and a full regen drifts\nunrelated transitive versions). Build it with the workspace TypeScript:\n\n```bash\ncd packages/checkout && pnpm build && pnpm test\n```\n\n\n## Browser integration and merchant outcomes\n\n`attachToPlaywright` works with an existing Chromium page reached through\n`chromium.connectOverCDP`. Browserbase supplies `session.connectUrl`; Kernel\nsupplies `browser.cdp_ws_url`; a custom browser must expose a compatible CDP\nendpoint. This is Agentcard's **direct SDK** path. Kernel's native Vault alias\nintegration is a separate provider adapter with its own coverage and lifecycle;\ndo not install both interceptors on the same checkout without validating how\nthose routes interact.\n\nThe local browser suite validates Chromium and nested cross-origin frames over\nboth Playwright routing and a raw, session-aware CDP connection. It does not\nestablish live Browserbase, Kernel, 3DS or merchant coverage. A raw page-scoped\nPlaywright `CDPSession` is not the `CdpLike` interface. Raw CDP must preserve the\n`sessionId` on every command/event and allow recursive target attachment.\nInitial arming errors reject `attachToCdp`; a child that cannot be armed remains\npaused and reports `browser_interception_unavailable` for operator recovery.\n\nAwait attachment before clicking Pay. Both adapters stop waiting for browser\nsetup after 30 seconds and throw `CheckoutAttachmentError` with\n`code: 'checkout_attachment_failed'` and `reason: 'timeout'`, `'closed'` or\n`'unavailable'`. Use `attachmentTimeoutMs` to choose a setup deadline from 1 to\n300000 milliseconds, separately from the approval's `timeoutMs`.\nClose the failed checkout page and create a fresh browser context before\ntrying again. A late setup response cannot reopen the failed attachment or\nrequest approval; intercepted card requests remain blocked. A setup failure\ndoes not establish the status of any earlier purchase.\n\nUse a checkout context created with `serviceWorkers: 'block'`. Playwright cannot\nroute requests intercepted by a service worker. The SDK rejects already active\nservice workers, but that check cannot prevent a site from registering one\nlater in an existing context configured to allow them. Attach before entering\ncard fields; keep the existing checkout tab. Separate popup tabs need their own\nattachment. A page route does not cover a popup's first navigation; a popup\nwhich submits payment on that navigation requires a separately validated\ncontext/browser-level integration. Existing `page.route` handlers must call\n`route.fallback()` when they do not handle a request; later routes have priority.\n\nBoth adapters now return a controller; existing code that ignores the return\nvalue continues to work. Choose `requireMerchantResult: true` for a pilot:\n\n```ts\nconst checkout = await attachToPlaywright(page, {\n  vault, user, merchant, amount, currency,\n  requireMerchantResult: true,\n  onStateChange: state => recordState(state),\n  onUserAction: action => deliverPrivatelyToUser(action),\n  resolveMerchantResult: async state => readMerchantOrder(state),\n  paymentEndpoints: [\n    { origin: 'https://payments.example.com', pathname: '/submit', methods: ['POST'] },\n  ],\n});\n\n// Your existing agent dispatches checkout. Later, once the paused request resumes:\nconst state = await checkout.reconcile();\nif (state.status === 'completed') await finishAgentTask(state);\n```\n\n`resolveMerchantResult` must verify the merchant's result for the original\npayment attempt. It returns one of:\n\n- `{ status: 'completed', orderId }`: merchant-confirmed success with a genuine order or receipt ID. Existing integrations keep this form.\n- `{ status: 'completed', confirmation: { kind: 'merchant_payment', authorizationId } }`: merchant-confirmed payment when no order or receipt ID is available. The ID must match the current checkout authorization.\n- `{ status: 'failed' }`: merchant confirmed the attempt failed; no successful payment/order exists.\n- `{ status: 'pending' }` or `{ status: 'unknown' }`: keep waiting or reconcile; never click Pay again.\n- `{ status: 'requires_user_action', reason: '3ds' | 'redirect' | 'other' }`: deliver your own browser live view or supported challenge UI to the user.\n\nFor a merchant that confirms payment without returning an order ID, your\nresolver can return the explicit payment confirmation:\n\n```ts\nconst checkout = await attachToPlaywright(page, {\n  vault, user, merchant, amount, currency,\n  requireMerchantResult: true,\n  resolveMerchantResult: async state => {\n    const payment = await readOriginalMerchantPayment(state);\n    if (!payment.confirmed || !state.authorizationId) return { status: 'unknown' };\n    return {\n      status: 'completed',\n      confirmation: {\n        kind: 'merchant_payment',\n        authorizationId: state.authorizationId,\n      },\n    };\n  },\n});\n```\n\n`readOriginalMerchantPayment` is your merchant-specific check. The check must\nmatch the original payment request, amount, currency and selected card, and\nverify authoritative merchant success for that attempt. HTTP 200 alone, a card\ntoken, a success URL or text that anyone can open does not establish payment.\nCopying `state.authorizationId` without checking the payment is insufficient.\nThe SDK checks the authorization binding; it does not independently authenticate\nthe merchant evidence supplied by your resolver.\n\nReturn one completion form at a time. The payment-confirmation form leaves\n`state.orderId` absent and exposes `state.confirmation` with the exported\n`MerchantPaymentConfirmation` type. Your consumer should finish on\n`state.status === 'completed'` and treat `orderId` as optional. A missing or\nmismatched authorization, or `{ status: 'completed' }` without either completion\nform, leaves the outcome unknown. Confirmed completion clears stale failure or\nauthentication reasons and continues to block further payment submissions.\nNever invent an order ID from a token or authorization ID.\n\nThe SDK does not infer order success from `authorized` or a tokenization reply,\nand does not claim to detect or solve arbitrary 3DS challenges. Your merchant\nresolver (or `checkout.requestUserAction('3ds')` when your browser observes it)\ndrives that hook. Deliver `onUserAction` approval URLs privately: they are\ncapabilities and never belong in general telemetry. Observer exceptions are\nisolated from the payment handoff.\n\nNative Stripe Checkout emits `checkout_blocked` before the existing `blocked`\nevent when its local preparation rejects a request. Its\n`StripeCheckoutBlockedDetail` contains only fixed codes: `version: 1`,\n`processor: 'stripe'`, endpoint family, phase, stage, reason, optional validation code, gate state, and\ndisposition. It contains no URLs, identifiers, request-derived field names or values, or exception text.\n\n| Field | Values |\n| --- | --- |\n| `endpoint_family` | `payment_methods`, `payment_page_confirm`, `other` |\n| `phase` | `tokenization`, `final`, `unknown` |\n| `stage` | `request_read`, `classification`, `claim`, `readiness`, `document`, `stub_response` |\n| `validation_code` | Shared-core `StripeCheckoutValidationCode`; present only for `request_validation_failed` |\n| `gate_state` | `fresh`, `stubbed`, `submitted`, `stopped` |\n| `disposition` | `active_claim_preserved`, `checkout_stopped` |\n\n`reason` is the exported `StripeCheckoutBlockReason` union. It identifies SDK\nclaim and readiness failures, such as `duplicate_confirmation`, `document_changed`,\nor `attachment_not_ready`. A shared-core rejection reports\n`request_validation_failed` and a fixed `validation_code` identifying the failed\ncheck, or `unclassified` when no recognized code is available. Initial request\nclassification uses phase `unknown`; a billing capture rejection uses\n`tokenization`, and a billing attachment rejection uses `final`.\nFor example, `form_field_unknown` identifies an allowlist rejection without\nrevealing the field name or value. Identifying that field requires a separate\nreviewed synthetic fixture; the code alone does not establish or fix a processor\nschema mismatch. `gate_state` records the state before the adapter handles\nthe failure, though document validation may already have stopped the gate.\n\n`active_claim_preserved` means a valid duplicate was refused without invalidating\nthe original request's claim. Do not cancel that checkout in response to the duplicate.\n`checkout_stopped` means the local preparation was retired; reconcile any existing\nauthorization before another attempt. Neither disposition proves a payment outcome.\n\nWith `requireMerchantResult`, subsequent card requests stay blocked after\nhandoff. Stripe `/v1/payment_methods` and `/v1/tokens` handoffs always hold further\nrecognized card requests, even when that option is false. A tokenization approval has no\nauthoritative binding to a specific PaymentIntent, amount or currency. The first\nobserved confirm cannot supply that binding. The SDK therefore blocks every\nfollow-up confirm on that attachment, including the same token, an unrelated\nintent, changed amounts and retries. It reports `awaiting_merchant` with reason\n`stripe_tokenization_unbound`, while ordinary browser traffic stays available.\nThere is no automatic token-to-intent continuation or merchant-continuation hook.\nUnrecognized merchant-server endpoints remain outside this guard unless listed\nin `paymentEndpoints`; this is not a guarantee against a merchant charging a\nsaved token on its own server.\nA direct card-bearing PaymentIntent confirm remains supported with the backend's\nexisting amount verification when `amount` and `currency` are supplied.\n\nHosted-form submissions also always stay blocked because their payment outcome\nis unverified. `reconcile()` calls the resolver once, coalescing concurrent calls.\nAfter an explicit merchant-confirmed failure, the application may call\n`checkout.retryAfterMerchantFailure({ status: 'failed' })` to permit another\nattempt where the attachment permits recovery. This is an assertion from your\nmerchant integration, not a timeout or a best guess. Completed orders, cancelled\nattachments and attachments that issued an unbound Stripe token cannot reset\nthis way, including when the token's browser delivery acknowledgement was lost.\nReconcile the merchant outcome and use a separately validated checkout flow;\ndo not reuse that token in a new attachment as a workaround. Configuration and\nunsupported-mode failures require fixing the integration. Bank flows requiring\nanother confirmation and other stored-token chains remain unverified.\n\nWorldpay, Bambora and Mercado Pago preparation requires SDK 0.6.0 or later and the matching API and Vault release.\n\nPrepare a Square, Braintree, Worldpay, Bambora or Mercado Pago checkout before the first Pay action so the cardholder can approve before the native card request starts. The API and Vault deployments must support the selected processor:\n\n```ts\nconst checkout = await attachToPlaywright(page, {\n  vault, user: 'your-user-id', merchant: 'Example merchant',\n  amount: 100, currency: 'USD',\n  onApprovalUrl: deliverPrivatelyToCardholder,\n});\nconst preparation = await checkout.prepare({\n  psp: 'braintree',\n  environment: 'production', // Square, Braintree and Worldpay: production or sandbox\n});\n// The cardholder has consented and unlocked the same approval document.\n// No processor request or payment has started.\nawait page.getByRole('button', { name: 'Pay', exact: true }).click();\n```\n\n`prepare()` is available on both Playwright and raw CDP controllers. It requires `amount` and `currency`, must precede the first recognized card request, and returns only when the cardholder's device is ready. It delivers the preparation URL through `onApprovalUrl` and `onUserAction`; binding the subsequent authorization sends no second approval link or SMS. The approval page on the cardholder's device must stay open. Its selected card, merchant origin, declared merchant, amount, currency, processor and environment bind one fresh request. The amount's authority is `agent`; a card token does not enforce the merchant's eventual charge amount.\n\n| Processor | `environment` | Fresh native request |\n| --- | --- | --- |\n| Square | `production` or `sandbox` | Matching Square `/v2/card-nonce` host |\n| Braintree | `production` or `sandbox` | Matching Braintree GraphQL host and guest `TokenizeCreditCard` mutation |\n| Worldpay | `production` or `sandbox` | Matching Access Worldpay host and `/sessions/card` |\n| Bambora | `shared` | `/scripts/tokenization/tokens` on `api.bam.shift4api.net` or `api.na.bambora.com` |\n| Mercado Pago | `shared` | `api.mercadopago.com/v1/card_tokens` with a fresh card body |\n| Recurly | `shared` | Form-encoded POST to `/js/v1/token` on `api.recurly.com` or `api.eu.recurly.com` |\n| Spreedly | `shared` | Native iframe JSON POST to `/v1/payment_methods/restricted.json` on `core.spreedly.com` |\n| Adyen | `production` or `sandbox` | The Sessions `/checkoutshopper/v1/sessions/{id}/payments` POST on the matching Adyen host family (`sandbox` is `checkoutshopper-test.adyen.com` with a `test_` client key; `production` is the live hosts with a `live_` key), carrying a fresh card's four encrypted fields |\n\nUse `environment: 'shared'` for Bambora, Mercado Pago, Recurly and Spreedly because the same endpoint serves test and live requests. Agentcard cannot establish the processor's test mode from that URL or a credential prefix. Configure test mode through the merchant's processor account when testing. Agentcard's own `sandbox` flag remains separate. Prepared Worldpay, Bambora, Mercado Pago and Recurly requests reject saved-card and recurring request bodies; a refused request retires the local preparation. Reconcile any existing merchant attempt before creating a new attachment.\n\nPrepare an Adyen Sessions checkout before the agent clicks Pay:\n\n```ts\nawait controller.prepare({ psp: 'adyen', environment: 'production' }); // 'sandbox' for Adyen's test host\n```\n\nAfter approval, click Pay once. adyen-web encrypts the agent's placeholder digits and posts its Sessions `/payments` request; the SDK pauses it and binds it to the approval, the cardholder's device (still on the approval page) encrypts the approved card under the merchant's Adyen key, and the request continues from your browser with only the four encrypted fields swapped and `brand` dropped. Adyen answers your browser, so the merchant's order state is the outcome to poll. The bound request must be a fresh `scheme` card on the approved host family with a client key of that environment; a stored-card, single-blob or store-the-card request never uses the approval. Adyen Web's own 60-second request timeout then covers only the pause, the bind and the device's encryption.\n\nPrepare a Spreedly checkout before submitting the merchant's card form:\n\n```ts\nawait controller.prepare({ psp: 'spreedly', environment: 'shared' });\n```\n\nAfter approval, submit the form once. The Vault replaces the card fields on your device and sends the native request through an encrypted connection to Spreedly. The merchant's environment and signed session stay unchanged. The API, Vault, relay and preparation migration must support Spreedly before you use this flow; the API refuses preparations while its relay rollout flag is disabled.\n\nInitial coverage includes the hosted iframe's new-card request. Saved-card CVV updates, Express, wallets, bank accounts and gateway purchase APIs require separate support. A returned card token does not confirm payment; wait for the merchant's result before reporting success. Autopilot is unavailable for Spreedly.\n\nPrepare Recurly before clicking the merchant's payment button:\n\n```ts\nawait controller.prepare({ psp: 'recurly', environment: 'shared' });\n```\n\nAfter approval, submit the merchant's form once. Recurly's native request timer starts with that submission. The SDK preserves the captured US or EU endpoint and accepts a new-card form only. Legacy JSONP, saved tokens, bank accounts, alternative payments and proactive authentication requests require separate support. Prepared requests also refuse nonempty Worldpay or Cybersource risk results because those sessions can depend on the original card. A nonempty co-badged network preference is also refused until the selected card’s supported networks can be checked. A card token does not confirm a donation, subscription or purchase; confirm the merchant's result before reporting payment success.\n\n### Use Checkout Pro in Mexico\n\nAttach the SDK before entering card fields on `www.mercadopago.com.mx`, then prepare the guest card checkout:\n\n```ts\nawait controller.prepare({ psp: 'mercado_pago', environment: 'shared' });\n```\n\nThe Vault checks the selected card's issuer using the merchant's current checkout configuration. Your browser receives the processor's original card-token response, and the SDK replaces the issuer in one native card association. The card number, security code and eight-digit prefix stay out of your SDK process. The encrypted relay carries the configuration lookup between the approval device and Mercado Pago.\n\nThe selected card must have the same brand and card type as the native form. Missing or ambiguous configuration, changed checkout details, and a repeated card association stop continuation. Start a fresh checkout and approval after resolving the mismatch. Final Pay and merchant confirmation still follow your existing checkout integration.\n\nUse the matching SDK, API, Vault and relay releases together. The issuer correction covers the observed guest Checkout Pro flow in Mexico. CardForm or Bricks on merchant websites, other countries, installment changes and Autopilot need separate validation. Successful tokenization and issuer association do not establish a paid order; keep `requireMerchantResult` and a merchant receipt resolver when validating a purchase.\n\nBraintree's native `ClientConfiguration` GraphQL query can run before, during or after preparation without using the approval. Only a single `TokenizeCreditCard` mutation can consume the prepared Braintree checkout. Prepared requests require guest card tokenization with explicit `options.validate: false`; omitted validation options, saved-card fields and `validate: true` are refused. Other GraphQL operations, batches and compound mutations are blocked. Braintree's legacy REST fallback cannot consume a prepared authorization.\n\nReadiness lasts up to 30 seconds (`preparation.expiresAt`) and appears as `ready_to_submit`, with `paymentStatus: 'not_started'`. Trigger the caller-owned Pay action immediately after the promise resolves. Expiry, navigation, cancellation, an early request or a changed checkout fails closed. A preparation and its attachment are single use; reconcile any bound authorization before creating a new attachment. The SDK never clicks Pay, reuses a stale request, changes native request deadlines, or automatically retries a failed prepared checkout.\n\nAfter Pay, the processor's native deadline still covers fresh authorization binding, device replay and token handoff. A disconnected or backgrounded cardholder device, or a slow transport, can still miss it. A subsequent SCA challenge has its own lifetime after token handoff. If the merchant request aborts or its frame closes, the attachment blocks further requests and tries to retire the pre-replay authorization; a started replay or unconfirmed cancellation remains unknown. Without `prepare()`, approval loading and human interaction still share the native deadline, so delayed approval cannot finish that request.\n\nLost authorization polling, local approval timeouts, or interrupted browser\nhandoffs produce `outcome_unknown` and block automatic retry. The thrown\n`PaymentOutcomeUnknownError` carries `authorizationId` when creation was\nacknowledged. `checkout.cancel()` stops the local attachment and polling; it\ndoes not revoke a pending approval link or undo a processor payment. Cancellation\nafter an attempt starts is therefore unknown until reconciled. A cancelled\nattachment cannot restart.\n\n### Unsupported endpoints\n\n`paymentEndpoints` is an explicit list supplied by the integrator after observing\nthe site's payment requests. Each guard uses a canonical origin, exact path and\nmutation methods; it never examines or logs card bodies. If a guarded endpoint\nis not recognized, the SDK aborts it and reports `unsupported_checkout` /\n`unsupported` without creating an approval. Preflights and ordinary page traffic\ncontinue. There is no wildcard or intercept-all fallback, and no automatic\nconversion to an issued card. Unknown endpoints absent from these guards remain\nuntouched; the SDK cannot identify every payment request from its URL.\n\n### Runnable integration and local verification\n\n`examples/existing-browser.mjs` runs against an existing provider session, using\nan application-owned driver module for the agent's actions, user communication\nand merchant-result resolver. Set `CHECKOUT_DRIVER` to that module's absolute\npath and `CHECKOUT_CDP_URL` to the provider connection URL; optionally select the\nexisting tab with `CHECKOUT_PAGE_INDEX`. The module must export\n`prepareCheckout(page)`, `submitCheckout(page)`, `resolveMerchantResult({page,\nstate})`, `onUserAction(action, {page})`, and `finishAfterPayment({page, orderId})`.\n`prepareCheckout` returns the checkout options above. `submitCheckout` dispatches\nthe existing agent's approved purchase and returns without waiting for approval.\nInstall `playwright-core` in the example's host project. The SDK itself keeps no\nruntime dependencies. The example is integration scaffolding, not a universal\nmerchant driver and not evidence of a live provider checkout.\n\n```sh\npnpm build\npnpm test\n# Uses installed playwright-core, falling back to the monorepo backend dependency.\n# Set CHECKOUT_CHROME_PATH if Chromium is not installed in Playwright's cache.\npnpm test:browser\n```\n\nThe browser fixtures never contact a payment service. The general suite uses\n`psp.invalid`; the Stripe continuation suite forces `api.stripe.com` through an\nallowlisted loopback proxy and a temporary self-signed TLS stub (requires the\n`openssl` CLI). All other proxy destinations are rejected. These suites use an\nin-process Agentcard API fixture and loopback merchant pages. The preparation\nfixture denies all external traffic and waits beyond each modeled request deadline before any card request: eleven seconds for Square, sixty-one seconds for Braintree, and six and a half seconds for Worldpay, Bambora and Mercado Pago. Each fixture then checks one fresh request with an unchanged abort timer. The five-second timer matches the inspected Worldpay and Bambora source; the Mercado Pago timer is a test boundary, not a measured native deadline. The fixture exercises SDK ordering with native-shaped request bodies and synthetic responses, not processor acceptance. It proves nested-frame pause/resume, agent control during approval,\npost-payment tasks in the same page, decline/expiry/cancel, unknown-outcome retry\nblocking, explicit unsupported endpoint behavior, and blocking an immediate real-browser\nStripe token-to-intent fetch chain, including unrelated first intents, changed\namounts/currencies and delayed CDP acknowledgement. It does not test card\ncryptography, real bank authorization or a cloud-provider deployment.\n\nProvider/API references checked for this integration:\n[Playwright CDP](https://playwright.dev/docs/api/class-browsertype#browser-type-connect-over-cdp),\n[Playwright routing limitations](https://playwright.dev/docs/api/class-page#page-route),\n[Browserbase Playwright quickstart](https://docs.browserbase.com/welcome/quickstarts/playwright),\n[Kernel native Agentcard integration](https://www.kernel.sh/docs/integrations/payments/agentcard).\n\n\nThe authenticated `GET /v2/checkout/coverage` endpoint describes direct-SDK\nprocessor modes, limitations and verification levels. Use\n`POST /v2/checkout/coverage/assess` with up to 1,000 uniquely identified cases:\n`{ cases: [{ id, request_url, method: \"POST\", scenario: \"one_time\", weight: 1,\nrequires_3ds: false }] }`. Scenarios also include `save_card`,\n`subscription_initial` and `subscription_renewal`. The endpoint assesses request\nrecognition, not purchases: `recognized`, `unsupported` and `unverified` are\ncoverage classifications, `recognized_traffic_share` is traffic-weighted, and\n`purchase_success_rate` stays null without observed merchant outcomes. Do not\nsubstitute the assessor for a browser/merchant validation run or use native\nKernel adapter coverage as evidence for this SDK's coverage.\n### Autopilot execution metadata\n\nWhen the cardholder has enabled an eligible spending rule in their vault, the same authorization can run through autopilot. The SDK keeps polling the existing authorization and returns optional `executionMode: 'autopilot' | 'user_approval'` and `grantId` metadata. Older API responses remain supported.\n\n`authorize()` accepts optional `executionMode` and `grantId` routing hints, sent as `execution_mode` and `grant_id`. These never establish permission to spend; the protected payment service checks the cardholder's signed rule. Autopilot suppresses `onApprovalUrl` while it is executing. A definite fallback to user approval delivers the existing authorization's URL once. A lost outcome remains `PaymentOutcomeUnknownError`; it does not create or submit a second payment.\n\nUse `executionMode: 'user_approval'` to require the existing confirmation flow. Without a selected card or grant, the backend can use exactly one eligible rule; ambiguous card selection keeps confirmation. A `grantId` restricts selection to that rule. The initial executor supports only the configured controlled Stripe test flow, and production remains disabled.\n\nFor controlled hosted Stripe Checkout, both attachment functions accept `stripeCheckout: { sessionId, publishableKey, environment? }`. The default is TEST, requiring `cs_test_` and `pk_test_`. LIVE requires explicit `environment: 'production'`, a `cs_live_` Session and its `pk_live_` key. Both modes require `executionMode: 'autopilot'`, an explicit `grantId`, and a positive numeric USD `amount` in cents. The top-level document must be that exact Session on `https://checkout.stripe.com`, at `/c/pay/{sessionId}`, `/pay/{sessionId}`, `/g/pay/{sessionId}`, or `/f/pay/{sessionId}`. The SDK validates the existing URL without rewriting or navigating it. Direct `authorize()` calls use `stripeCheckoutEnvironment: 'production'` for the same explicit LIVE opt-in; the attachment functions pass it automatically.\n\nThe SDK answers dummy-card tokenization locally, then sends the browser's final native confirmation through the shared core and enclave. The local response is preparation only: it creates no authorization and makes no processor request. The final result includes `checkoutSessionId` only after the selected grant, restricted terminal response, and captured amount have been checked. Continue to confirm the merchant order through the checkout controller.\n\nWhen Agentcard reports `autopilot_status: action_required` for the same authorization and grant, the SDK stops waiting and calls `onUserAction` with `reason: 'other'` and the authorization ID. The checkout controller records `requires_user_action` and holds further card requests. A direct `VaultClient.authorize()` call rejects with `PaymentOutcomeUnknownError` and reason `autopilot_action_required`. The existing authorization and reservation remain held; the SDK does not cancel or create another payment, return a processor payload, or infer a 3DS challenge. Your application's `resolveMerchantResult` can report the authoritative outcome of this same payment through `reconcile()`. Challenge execution and automatic continuation are not provided by this status report.\n\nThe shared core carries a validated billing email from that tokenization request into the final confirmation before authorization. The email stays bound to the same Session and local PaymentMethod reference. Missing email stays missing; duplicate or conflicting values are refused. The SDK does not fill an email from the Agentcard account or invent one for the merchant.\n\nThis integration requires matching backend and measured executor releases. TEST and LIVE have separate admission controls. LIVE also requires a newly authorized production grant on the selected real card, a fixed merchant account/profile with exactly one complete fixed-price USD line item and an independently reviewed operation qualification reference; the SDK option supplies none of these. LIVE deployment remains unqualified and disabled until that evidence exists. Exact observed totals do not establish atomic amount enforcement by Stripe. Subscriptions, saved-card flows and authentication continuations remain excluded. An unavailable preparation or uncertain result is declined or held for reconciliation; it cannot switch to a competing human-approval payment.\n\nThe adapters also send the observed top-level HTTPS `merchantOrigin`, such as `https://shop.example`, without a path, query or trailing slash. Direct `authorize()` callers can supply that origin explicitly. It is a routing hint; the protected adapter independently verifies the processor account, payee and amount. If a browser cannot provide its top-level URL, an explicit `merchantOrigin` option can supply the hint; otherwise the regular approval path remains available.\n","readmeFilename":"README.md"}