{"_id":"@droplinked_inc/payment-hub","_rev":"3-6921f3ae07704e72190ef90f07b87a60","name":"@droplinked_inc/payment-hub","dist-tags":{"latest":"1.0.0"},"versions":{"0.1.0":{"name":"@droplinked_inc/payment-hub","version":"0.1.0","license":"MIT","_id":"@droplinked_inc/payment-hub@0.1.0","maintainers":[{"name":"droplinked_inc","email":"ali@droplinked.com"}],"homepage":"https://github.com/droplinked/droplink-packages#readme","bugs":{"url":"https://github.com/droplinked/droplink-packages/issues"},"dist":{"shasum":"375078e2e5ba45e26b6e2e2ded0125f3c4a4324d","tarball":"https://registry.npmjs.org/@droplinked_inc/payment-hub/-/payment-hub-0.1.0.tgz","fileCount":64,"integrity":"sha512-wsrL8HYcd/Myo7SdTQnktaQbiEKSH3SBT5E9jSG95NfpMySgkbUj93e/5o8ZojIgE3FMFLE9260z9XefBeLJ/A==","signatures":[{"sig":"MEYCIQCEH2qEG5YLkb2lmMluAZREXP3D4DQ7Sdt73T1N0mmfowIhAOoEgpP2ZfsRVt8qRuUW8GXYkFQ+ctIsn6cWjkSXmlJV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":138070},"main":"./dist/index.js","type":"module","_from":"file:droplinked_inc-payment-hub-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src --max-warnings=0","test":"jest","build":"tsc -p tsconfig.json","typecheck":"tsc --noEmit -p tsconfig.json","test:coverage":"jest --coverage"},"_npmUser":{"name":"droplinked_inc","email":"ali@droplinked.com"},"_resolved":"/tmp/ec0fcf88bd653d5cc3b8f86987359bc9/droplinked_inc-payment-hub-0.1.0.tgz","_integrity":"sha512-wsrL8HYcd/Myo7SdTQnktaQbiEKSH3SBT5E9jSG95NfpMySgkbUj93e/5o8ZojIgE3FMFLE9260z9XefBeLJ/A==","repository":{"url":"git+https://github.com/droplinked/droplink-packages.git","type":"git","directory":"packages/payment-hub"},"_npmVersion":"10.9.7","description":"PSP-aggregator orchestration for droplinked: routes payment-intent creation and webhook verification across Stripe, PayPal, Bonum, PayMob, Telr, Coinbase Commerce, x402, and XION. Hardened recover+rewrite of droplinked-payment-hub@0.2.37.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"zod":"^3.23.8"},"publishConfig":{"access":"public","provenance":false},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/payment-hub_0.1.0_1779168343607_0.7936828132484566","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@droplinked_inc/payment-hub","version":"0.2.0","license":"MIT","_id":"@droplinked_inc/payment-hub@0.2.0","maintainers":[{"name":"droplinked_inc","email":"ali@droplinked.com"}],"homepage":"https://github.com/droplinked/droplink-packages#readme","bugs":{"url":"https://github.com/droplinked/droplink-packages/issues"},"dist":{"shasum":"ced525590093eb159a88d27da9b9aa0530a29605","tarball":"https://registry.npmjs.org/@droplinked_inc/payment-hub/-/payment-hub-0.2.0.tgz","fileCount":56,"integrity":"sha512-iH/edOv3MpPhUd1xWWc8bw1l1WOXfBrlkFihRvUoommhzFDBO7rzSaxoxpXs09ib10RGMmbFepOev5oXwfam1g==","signatures":[{"sig":"MEYCIQDwR3KGfqJzhiqe6sUQajLc/OHC0M7OflnolqFG1gAufgIhAKSqnPp0tixWL3x28oAoByT/4QVj78BOUPW+lQITzuDw","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108384},"main":"./dist/index.js","type":"module","_from":"file:droplinked_inc-payment-hub-0.2.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src --max-warnings=0","test":"jest","build":"tsc -p tsconfig.json","typecheck":"tsc --noEmit -p tsconfig.json","test:coverage":"jest --coverage"},"_npmUser":{"name":"droplinked_inc","email":"ali@droplinked.com"},"_resolved":"/tmp/1e427849d1de797d415c5d7c42b266ae/droplinked_inc-payment-hub-0.2.0.tgz","_integrity":"sha512-iH/edOv3MpPhUd1xWWc8bw1l1WOXfBrlkFihRvUoommhzFDBO7rzSaxoxpXs09ib10RGMmbFepOev5oXwfam1g==","repository":{"url":"git+https://github.com/droplinked/droplink-packages.git","type":"git","directory":"packages/payment-hub"},"_npmVersion":"10.9.7","description":"PSP-aggregator orchestration for droplinked: routes payment-intent creation and webhook verification across Stripe, PayPal, Bonum, PayMob, Telr, Coinbase Commerce, x402, and XION. Hardened recover+rewrite of droplinked-payment-hub@0.2.37.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"zod":"^3.23.8"},"publishConfig":{"access":"public","provenance":false},"_hasShrinkwrap":false,"devDependencies":{"react":"^19.0.0","@types/react":"^19.0.0","@droplinked_inc/payment-intent-react":"0.2.0"},"peerDependencies":{"react":">=18.0.0","@droplinked_inc/payment-intent-react":">=0.2.0"},"peerDependenciesMeta":{"react":{"optional":true},"@droplinked_inc/payment-intent-react":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payment-hub_0.2.0_1779333846191_0.10713534199411834","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@droplinked_inc/payment-hub","version":"1.0.0","description":"PSP-aggregator orchestration for droplinked: routes payment-intent creation and webhook verification across Stripe, PayPal, Bonum, PayMob, Telr, Coinbase Commerce, x402, and XION. Hardened recover+rewrite of droplinked-payment-hub@0.2.37.","license":"MIT","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","sideEffects":false,"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"dependencies":{"zod":"^3.23.8"},"peerDependencies":{"@droplinked_inc/payment-intent-react":">=0.4.1","react":">=18.0.0"},"peerDependenciesMeta":{"@droplinked_inc/payment-intent-react":{"optional":true},"react":{"optional":true}},"devDependencies":{"@types/react":"^19.0.0","react":"^19.0.0","@droplinked_inc/payment-intent-react":"0.4.1"},"publishConfig":{"provenance":false,"access":"public"},"repository":{"type":"git","url":"git+https://github.com/droplinked/droplink-packages.git","directory":"packages/payment-hub"},"engines":{"node":">=22.0.0"},"scripts":{"build":"tsc -p tsconfig.json","test":"jest","test:coverage":"jest --coverage","lint":"eslint src --max-warnings=0","typecheck":"tsc --noEmit -p tsconfig.json"},"_id":"@droplinked_inc/payment-hub@1.0.0","bugs":{"url":"https://github.com/droplinked/droplink-packages/issues"},"homepage":"https://github.com/droplinked/droplink-packages#readme","_integrity":"sha512-hdOscEvAaHqeZ1GOpy5N1PnKV7A5CRv+BGiDynuYyZtQUgiwMrOdVNOGoe8IqMXTHukPStPcwiHwcCBBuBUUiw==","_resolved":"/tmp/0cf9eec4fd7e9ef531acffc82aa8ba52/droplinked_inc-payment-hub-1.0.0.tgz","_from":"file:droplinked_inc-payment-hub-1.0.0.tgz","_nodeVersion":"22.23.1","_npmVersion":"11.19.0","dist":{"integrity":"sha512-hdOscEvAaHqeZ1GOpy5N1PnKV7A5CRv+BGiDynuYyZtQUgiwMrOdVNOGoe8IqMXTHukPStPcwiHwcCBBuBUUiw==","shasum":"d72c933d20334c2809255e50afa560249b4e209d","tarball":"https://registry.npmjs.org/@droplinked_inc/payment-hub/-/payment-hub-1.0.0.tgz","fileCount":56,"unpackedSize":108485,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAKKnZdnJ6nATZiTdaAsUsHN3Q1ij9sI0tDaLDcIW8EIAiAIP5vF6ysrx+wYlaSJyKl0Dgt707oqS2SohGW7EVx8lw=="}]},"_npmUser":{"name":"droplinked_inc","email":"ali@droplinked.com"},"directories":{},"maintainers":[{"name":"droplinked_inc","email":"ali@droplinked.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/payment-hub_1.0.0_1786016229144_0.7870644291106588"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T05:25:43.489Z","modified":"2026-08-06T11:37:09.435Z","0.1.0":"2026-05-19T05:25:43.763Z","0.2.0":"2026-05-21T03:24:06.377Z","1.0.0":"2026-08-06T11:37:09.291Z"},"bugs":{"url":"https://github.com/droplinked/droplink-packages/issues"},"license":"MIT","homepage":"https://github.com/droplinked/droplink-packages#readme","repository":{"type":"git","url":"git+https://github.com/droplinked/droplink-packages.git","directory":"packages/payment-hub"},"description":"PSP-aggregator orchestration for droplinked: routes payment-intent creation and webhook verification across Stripe, PayPal, Bonum, PayMob, Telr, Coinbase Commerce, x402, and XION. Hardened recover+rewrite of droplinked-payment-hub@0.2.37.","maintainers":[{"name":"droplinked_inc","email":"ali@droplinked.com"}],"readme":"# @droplinked_inc/payment-hub\n\n> Replaces `droplinked-payment-hub`. See [MIGRATION.md](../../docs/MIGRATION.md) for the swap path.\n\nPSP-aggregator orchestration for droplinked. Routes payment-intent\ncreation to the droplinked backend and verifies inbound webhooks against\nregistered, dependency-injected adapters. Hardened recover+rewrite of\n`droplinked-payment-hub@0.2.37` (last hostile-published by\n`droplinked-component`).\n\nSee [`THREAT_MODEL.md`](./THREAT_MODEL.md) for the five hardening\ncommitments and the tests that prove each one.\n\n## Install\n\n```bash\npnpm add @droplinked_inc/payment-hub\n```\n\n`zod` is a runtime dependency. PSP SDKs (`@stripe/stripe-js`, etc.) are\nNOT bundled — wire them as adapters at composition time.\n\n## Quick start\n\n```ts\nimport {\n  PaymentHub,\n  createStripeAdapter,\n  createPaypalAdapter,\n  createBonumAdapter,\n} from '@droplinked_inc/payment-hub';\nimport Stripe from 'stripe';\nimport { createHmac } from 'node:crypto';\n\nconst stripe = new Stripe(process.env.STRIPE_SECRET_KEY!);\n\nconst hub = new PaymentHub({\n  apiBaseUrl: 'https://apiv3.droplinked.com/',\n  apiTestnetBaseUrl: 'https://apiv3dev.droplinked.com/',\n  getAuthToken: () => session.accessToken,\n  maxRetries: 2,\n  requestTimeoutMs: 15_000,\n  adapters: {\n    stripe: createStripeAdapter({\n      verify: ({ rawBody, headers, secret }) => {\n        const sig = String(headers['stripe-signature'] ?? '');\n        stripe.webhooks.constructEvent(Buffer.from(rawBody), sig, secret);\n        return true;\n      },\n    }),\n    paypal: createPaypalAdapter({\n      verify: async ({ rawBody, headers, secret }) => {\n        // delegate to PayPal SDK webhook-id verification\n        return verifyPaypalWebhook(rawBody, headers, secret);\n      },\n    }),\n    bonum: createBonumAdapter({\n      computeHmac: (raw, secret) =>\n        createHmac('sha256', secret).update(raw).digest('hex'),\n    }),\n  },\n});\n\n// Create a payment intent (Stripe).\nconst intent = await hub.createPaymentIntent({\n  orderId: 'ord_123',\n  paymentMethod: 'stripe',\n  isTestnet: false,\n});\nconsole.log(intent.clientSecret);\n\n// PayPal convenience.\nconst url = await hub.getPaypalCheckoutUrl({\n  orderId: 'ord_123',\n  returnUrl: 'https://shop.example.com/success',\n  cancelUrl: 'https://shop.example.com/cancel',\n});\n\n// Inbound webhook verification.\nconst ok = await hub.verifyWebhook({\n  provider: 'stripe',\n  rawBody: req.rawBody,\n  headers: req.headers,\n  secret: process.env.STRIPE_WEBHOOK_SECRET!,\n});\n```\n\n## Public API\n\n| Symbol | Kind | Notes |\n|---|---|---|\n| `PaymentHub` | class | Orchestrator — `createPaymentIntent`, `getPaypalCheckoutUrl`, `verifyWebhook`, `registerAdapter`, `hasAdapter`, `baseUrl` |\n| `PspAdapter` | interface | `{ provider, verifyWebhook, getStatus? }` |\n| `PaymentProvider` | type | `stripe \\| paypal \\| bonum \\| paymob \\| telr \\| coinbase-commerce \\| x402 \\| xion \\| web3` |\n| `PaymentProviderSchema` | zod | Validates incoming provider strings |\n| `CreatePaymentIntentOptionsSchema` | zod | Validates intent creation input |\n| `PaymentIntentResultSchema` | zod | Validates backend responses |\n| `createStripeAdapter`, `createPaypalAdapter`, `createBonumAdapter`, `createPaymobAdapter`, `createTelrAdapter`, `createCoinbaseCommerceAdapter`, `createX402Adapter` | factories | DI-style — never bundle the upstream SDK |\n| `createAdapter`, `createHmacAdapter` | factories | Build a custom adapter |\n| `MemoryIdempotencyCache` | class | Bounded FIFO + TTL, swap via `idempotencyCache` option |\n| `deriveIdempotencyKey`, `timingSafeEqual` | helpers | Exposed for adapter authors |\n| `redactSecrets` | helper | Pre-publish error scrubbing |\n| `PaymentError`, `PaymentConfigError`, `PaymentNetworkError`, `PaymentValidationError`, `PaymentProviderMismatchError`, `PaymentWebhookError`, `PaymentIdempotencyConflictError`, `PaymentTimeoutError`, `PaymentAbortError` | errors | All extend `Error`, all scrub credentials |\n\n## Compatibility notes\n\n- The legacy `createPaymentIntent(orderId, method, isTestnet, returnUrl, cancelUrl)`\n  positional signature is replaced by a single-object form on\n  `PaymentHub.createPaymentIntent({ ... })`. Consumers should update\n  call sites; a thin positional shim can be added later if the rollout\n  pace demands it.\n- `DroplinkedPaymentIntent` (React) and `useXionWallet` (React hook) from\n  the legacy package are intentionally NOT shipped here. The React UI\n  surface is a separate concern and will live in a UI package (most\n  likely `@droplinked_inc/ui-kit`) once the underlying transports\n  (Stripe Elements, AbstraxionProvider) are wired through DI as well.\n\n## Development\n\n```bash\npnpm --filter @droplinked_inc/payment-hub typecheck\npnpm --filter @droplinked_inc/payment-hub test:coverage\npnpm --filter @droplinked_inc/payment-hub build\npnpm --filter @droplinked_inc/payment-hub lint\n```\n","readmeFilename":"README.md"}