{"_id":"xmr-pay","_rev":"30-bfe1fa238b1b8f2a3ef2202675b0ae50","name":"xmr-pay","dist-tags":{"beta":"0.4.0-beta.0","latest":"1.1.0"},"versions":{"0.1.2":{"name":"xmr-pay","version":"0.1.2","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.2","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"f497f30dc93b3704ae7a3122f24d6e776b25d90b","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.2.tgz","fileCount":17,"integrity":"sha512-b1ncZbbWDiZ9exsMVAuGHgOTBOzfzGWLC7GV8+BkmC/PIQjUVbFlhPzp8IAYpFs/30wBOwJ9CfiJquRKMkRHTw==","signatures":[{"sig":"MEYCIQDFh+Gn4AQHzJGulLsYTz906gZNEdFU8UVEHERvcjvLJAIhAJeK41o9/gUg3PMkBdUX/buoV/vbyoYdZtfKSHi++1cL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":169874},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js"},"gitHead":"4e0a3198deb33555da10bf09c56df012c3c43915","scripts":{"demo":"node examples/demo-server.js","test":"node test/config.test.js && node test/watch.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.2_1781201764619_0.9665300886225872","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"xmr-pay","version":"0.1.3","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.3","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"face7e2bccc7297d9d1e97c22afa94f320f39ee8","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.3.tgz","fileCount":17,"integrity":"sha512-0lfXL2yZojz7ggfPMNxI61hmixyEgbYxcF7S8z2bOSsW88Zg0CPlOy/5QRx2Vs3gsI4f2NzDpZdURlCuWXJTEA==","signatures":[{"sig":"MEUCIQDef5XUmzAWflAga8vNiudRMdPA3eSE1TTOo5pT34kb6gIgfmm25ZqB6Qt7V9Phkeeszi3rPTQ3FPKf2Xqd+8Je//0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":169903},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js"},"gitHead":"e571442f64edc6527f8ec7fda6b474843d527a03","scripts":{"demo":"node examples/demo-server.js","test":"node test/config.test.js && node test/watch.test.js && node test/webhook.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.3_1781202034184_0.04305616197255202","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"xmr-pay","version":"0.1.4","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.4","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"a815f3e56a2023c82766d8bde3db59b406606ff6","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.4.tgz","fileCount":17,"integrity":"sha512-9cJqD83nrh/s05J3W+lbKNYf4wVba31shF5N8/W2QodQbnX+rWkDfHyyLiMKgSQmyJGBh3iDlKFVJoXoRYbgAQ==","signatures":[{"sig":"MEYCIQDakbhGpDUKSHm0zScj7ztDuXPpcDTSsbda0xdRw6UE8gIhANZNHGmbhNNsO2H06YjcpJM3r6JBUJJPtDywzvkkn1j9","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":172239},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js"},"gitHead":"771ba15d4e24e2251a2274ea18d7bdd2a82255ac","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.4_1781216698531_0.3417039641290627","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"xmr-pay","version":"0.1.5","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.5","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"6decae928a70770912d2a531aff77a7dccb9ab33","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.5.tgz","fileCount":17,"integrity":"sha512-2P4XGD+rSvO5ddAiallYHdgwLiK0vGUj0VFBkDSoSURy9f3Xb4jP1Qd+kHkQ8OpObqnkGIkdNBvO18Hs9ExneA==","signatures":[{"sig":"MEQCICjCwQw3vwCuy7Zfji47JYg9qmE0HbStRXzOAE5KGJWlAiAJY5AMmzZpLqdi9HGj15wQlKlTXYwMSYE0uflwmbJa1Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":172747},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js"},"gitHead":"e7330b4f856ee5be52327187b4d9832a2faad652","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.5_1781216857296_0.8934076165817759","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"xmr-pay","version":"0.1.6","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.6","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"cf8662189e509d7ab53c164c04fec30570958a64","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.6.tgz","fileCount":18,"integrity":"sha512-95z1Eg81MLCIzQZ45FuivOv6OcAeDS9LlFuZL2RL1fLhqM4UIgQI81rAQKhyMHy/GnE2OZ1aZtstffN+WTBgmA==","signatures":[{"sig":"MEYCIQDEZ6GMYgTNudg0EZMX6044rYe8u91M5Zv+gqKi+P5xNgIhAJ2phxT6ATrXakMTKdCQFEUUxyHWRSNk0wGvw4DKwlwL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":177126},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js"},"gitHead":"a48215e7a658f26f56dff81a015e795ef41b5f25","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.6_1781235895505_0.5484688038515588","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"xmr-pay","version":"0.1.7","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.7","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"99239c4c564296c474cf80b3e4c9036f64f16534","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.7.tgz","fileCount":18,"integrity":"sha512-/IitE6IpM7tivL9XOf5tZfJNgOuIJTm3JpvhfFkD6GMQM5l5lmjmiikPT5UzA4QD55CDg+kMRbLxNv0t5xWigw==","signatures":[{"sig":"MEUCIQDyEzjgZYewvsK4zWRAvfh3X3Zmu1Qnk1qUCQAlUeNR4QIgYu/I+Fdr2CsYjLiuGXb9YR4ph2+/tuVk0MxzOyahuTQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":184647},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js"},"gitHead":"522ea9057230e9210e7bc3677ee1f608e14d4d7a","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.7_1781270827378_0.03912463524553944","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"xmr-pay","version":"0.1.8","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.8","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"33d69ccdd8cb23d2c25850e6b78dc8d540c92bb2","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.8.tgz","fileCount":18,"integrity":"sha512-sL4Zi1KeSJrcMYlPZQBdD8g0sL73PFJJau7TCbMpgvRbVkWNidZMHZBP+NnJrjldj6fqV4YRAZagqjcgqtJxXg==","signatures":[{"sig":"MEUCIBRrWyqxXziLFfHuTsH6vdAJE+FifTC50tD7ejTd8F/yAiEAgxl9AA7sQ9SIX+//XuthHgwZkTbAqMATwzNPoqHJ7MY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":185270},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"0231f866a85bbbe5626bcf649bcee10591e9e750","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{"qrcode-generator":"^1.4.4"},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.8_1781273886798_0.8753278305013352","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"xmr-pay","version":"0.1.9","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.9","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"8b749ccc55ba69d13ed1cc971a261a7b3a8769d0","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.9.tgz","fileCount":20,"integrity":"sha512-XkUkfYJqzmBXqLAAMUM/+T/ner0oMRyyfHCBtWtkklKTyeQAGTVltnMjWODXeo5PebuKgvRn9jk6IInmFmUk1Q==","signatures":[{"sig":"MEUCIQDORkIpYbk96Gs1EKGeQ0APG0mc5cUDCn3njQnOs07J1gIgSwtHEQJGvjNyk10ujxPWAZWkUBabme50FeMYcyv4E9o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":252521},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"351caf35ff1c736c61665eaaec15fc21417bd846","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.9_1781374473913_0.06092278795444783","host":"s3://npm-registry-packages-npm-production"}},"0.1.10":{"name":"xmr-pay","version":"0.1.10","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.1.10","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"8e17c161c8822de6f4bd1f419d77d73041980de4","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.1.10.tgz","fileCount":20,"integrity":"sha512-cRbUcz3XUErn7L8CkBxYo7URe78085zDGrD2NBCIJ2/WX3XcaFyEpTcofu/L3NVTbeqf78DomiTECcJdbVPRRQ==","signatures":[{"sig":"MEUCIEhFfKn6iehQGqmp1eb4MR6VKNOolJrgwDCTR05ESJnDAiEAlYAMidQdEB4J7R3cMHt2X9lV69NYItcdZIkM9iEB0Gg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":254012},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"faf99448d25f931866cf2ad307f12f8de85219f0","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.1.10_1781374834147_0.4215361689155783","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"xmr-pay","version":"0.2.0","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.2.0","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"2eb844ddd98e333c3d01b3795fb15da15813b8bf","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.2.0.tgz","fileCount":24,"integrity":"sha512-X3wAnQZX4Hw3TFfMJvXwt9xwe4orSUOme+977wwL39vz+TDoy12eazx813DX32nh6VaJ764NnxF0ZM3UYYByOQ==","signatures":[{"sig":"MEQCIFVfF3itQQnDZWxySU0u6Js9vOae1hyfh6HZmPmZ8ce0AiBySPapcxKxuppKvtunpEBkvs7PsHnapGPf43uWJNeeug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":298865},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"66453499dd30ffaf9c6dff3736fe559d6642af49","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.2.0_1781451821842_0.34029191455561936","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"xmr-pay","version":"0.2.1","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.2.1","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"61b51aec14adab098de26818bcad4bed9f67617d","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.2.1.tgz","fileCount":24,"integrity":"sha512-Uvh6rsiMg1VPhvubTaH3J2XVgsZ/vd63t5S1fDq9cYa15QJoQ6SeNGEx6VRd4YugNgQbvhejncoCRp5dc1frDA==","signatures":[{"sig":"MEYCIQDTz3bVaDNY3VEuw+jXqBGZ0SPMUQ7wAk/Arv60F/ffvgIhAPlHCzjur/60MSNU3OGSi+/bMUnCyGMJPyryY8D2mGfM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":300469},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"c05082214cee50eff8e447dc38f45eb5e9870ace","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.2.1_1781464421210_0.11228204555455923","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"xmr-pay","version":"0.2.2","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.2.2","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"f1df231244063f9f663e872f3badda31686f74ad","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.2.2.tgz","fileCount":24,"integrity":"sha512-dCXIbS2vrq2ZRLJPPT7IdNufxW1w5TxKR1IwTt4vNS44oFQdmujEfXMxGQk0rfkT2ffG4/FdYkebJw5dyhiZ8A==","signatures":[{"sig":"MEUCIQDgYDDm42jipXYjVLfQqAWjnHwQ9ydY2kEzzziWfW0K+wIgMA/UuF9rY8fRZ1kDovegWEsFjHcQhSUVKgrMpyZBsI0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":302919},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"5d12858e6518aefbba615052266c560e21eb1948","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.2.2_1781466536562_0.41972021509405555","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"xmr-pay","version":"0.2.3","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.2.3","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"0b556bf1182dc0fe5b78aa8f370d5e8612ad76c7","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.2.3.tgz","fileCount":24,"integrity":"sha512-q7ptYWZ0pF0ok5/DiJ4hylleeLB1OCt232o+fj2KG4YYm11CzZHln+UK3SJySvkRiwVS30/ZMB5p6mH0B+9IIQ==","signatures":[{"sig":"MEQCIC0NMYIz8DedUWUwiij5i5pKNNpKKp9JX2Z1EAFIwGAvAiAsl7hxERCR1TJNpnr4MlEntGRrqYYI7ZCwugeMPoyw8g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":306649},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"b5948aab03e7fed5d130c8096dd26fddae3ffc55","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.2.3_1781480055539_0.09175092542404317","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"xmr-pay","version":"0.2.4","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.2.4","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"c756dbf9881a4dfa0637580bb133b5c6c8dfa1a9","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.2.4.tgz","fileCount":24,"integrity":"sha512-a1f6xGJAuMa1zhG8iCQpfVkZcm2LfTaHwhkQsGQ6MlpIfgqEedOKNc7R101ijLq3UX8NXV1ZvX+pBE6EU1RB6g==","signatures":[{"sig":"MEUCIB/j6iz36WAKxik1dhz8X/Q/F/09tzF+w6vJl4sMGzvpAiEA3J/OBhH1i0hBO2nkjpMCM8ZPMj7Sbn2hMB+XAQsQ5H4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":308852},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"a107e3c542e9bac6f598bf7367dce456f2c3d790","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.2.4_1781523686433_0.6139374881855622","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"xmr-pay","version":"0.2.5","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.2.5","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"d1e72e475e47dcedd9e11c3658f8d059b581ad39","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.2.5.tgz","fileCount":25,"integrity":"sha512-2zS380GpkbJeRMp9qGTR7iWk7n2ZJMB42CrN1TtBX/HYHgA1FM3iqCnAGKTAI64RZoWu0TRtl5GrkRVBFVSQkQ==","signatures":[{"sig":"MEYCIQC3zuxFDxKS+ugJcGtX3ctqO0IPJcU7u5h9ocYqEC3GxAIhAL2YuiuNHoa/nNYw6d54xRBM2xyv+YBszkr3VVwhP6AX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":317558},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"e444a7a033ec80f5045fbd5c91974dad65db4409","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.2.5_1781527202846_0.9519834810112657","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"xmr-pay","version":"0.3.0","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.3.0","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"dist":{"shasum":"eb33b66b0401d2794ab29168ea6d63a62a762a54","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.3.0.tgz","fileCount":27,"integrity":"sha512-3Mohiu01hD2EjmRn+okznuaP6JUMtVUq2ddFqmaDSw+R2HJvA6l3DQWkJ7CVeHvH4X2/fN3PqPe9bwoH4EQhjw==","signatures":[{"sig":"MEUCIB9LXx0CH3ZqymRj7pqNn4kNgPwcc7s9TjhEUlY5gVCqAiEAxDxjbR8PewObq8/ckkf64cFWN1Yy5PNUqhr6vcQuWjE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":357898},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./receipt":"./src/receipt.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"ea50d7970acf626dc282cfa1de2427a0e7804428","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.3.0_1781541189747_0.9713370443090492","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"xmr-pay","version":"0.3.1","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.3.1","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"bin":{"xmr-pay":"bin/agent.js"},"dist":{"shasum":"9c18cc4a07a8d899f906d9088abe09d17ec6694a","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.3.1.tgz","fileCount":28,"integrity":"sha512-GQMWnSSBXA+uJZyCkSsV/aWwn1Zlu98LdrkVzf2dfDZxdlH3GGn93ReO9cCfFuWQBQgQIfiwjPhtVYEb2iU63w==","signatures":[{"sig":"MEYCIQDZv/vKgU5FeOoY4mPwDQUU3TvoXbsZ9uOC4t7pYo3oLQIhAKICUp9aWowJXmqcfYVotdnSFzYeWO1Niqz86KXbSlOG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":367573},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./receipt":"./src/receipt.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"f13f34f9fecc97f6fe93b971bde4428f17df60bd","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/agent-cli.test.js && node test/watch.test.js && node test/webhook.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"0.4.0-beta has payment-correctness fixes (false-paid, double-credit, double-spend gate, unlock_time) + durable webhooks + O(1) scale — please upgrade: npm i xmr-pay@beta","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.3.1_1781543479774_0.9059314018534235","host":"s3://npm-registry-packages-npm-production"}},"0.4.0-beta.0":{"name":"xmr-pay","version":"0.4.0-beta.0","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@0.4.0-beta.0","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"bin":{"xmr-pay":"bin/agent.js"},"dist":{"shasum":"a1c4f04d5f15cb5fe52da091801795af80cbf0c2","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-0.4.0-beta.0.tgz","fileCount":28,"integrity":"sha512-CGfR10k5Zq3DX5aX3fkVEkYRcgmJxwfxHez/L2S31tY756ymILOnKmoq0qrV1TDVhHkNSvqtADWSQkyK9WTa3A==","signatures":[{"sig":"MEUCIQDKhxubwTwx6IvESlBv8Nki+ArntErXexoar22tA+6E6QIgAzjyl49oSkWaBK3tipUftbN9n2iA0+5s8PQsZQpnoL0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":397653},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./receipt":"./src/receipt.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"aee49e3565ddcc7c25363a56ad969b12be30c834","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/agent-cli.test.js && node test/watch.test.js && node test/webhook.test.js && node test/webhook-redelivery.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/reorg.test.js && node test/expiry.test.js && node test/property.test.js && node test/rpc-fuzz.test.js && node test/false-paid.test.js && node test/webhook-storm.test.js && node test/break.test.js && node test/soak.test.js && node test/stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:mut":"node test/core.test.js && node test/watch.test.js && node test/property.test.js && node test/agent.test.js && node test/reorg.test.js && node test/scanner-birthday.test.js && node test/verify-gates.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/rpc-fuzz.test.js","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.11.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"25.8.1","_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"fast-check":"^4.8.0","@stryker-mutator/core":"^9.6.1"},"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_0.4.0-beta.0_1781645193310_0.8794459937400669","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"xmr-pay","version":"1.0.0","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@1.0.0","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"bin":{"xmr-pay":"bin/agent.js"},"dist":{"shasum":"9e5565486fb73ecb002eb75a8fe777fa080efb96","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-1.0.0.tgz","fileCount":33,"integrity":"sha512-Wrq5zcAGfsuPitPNbNCNdMbB5bpsoncCchb99LKhZSMqKwcacGCPJwNUwequicN8+V0Ako5xDbguH34etmpq/g==","signatures":[{"sig":"MEUCIHcpxm2CCg+7vzCgEiWjWEtDW7CeMvnHQYf5Jzz/kv7pAiEAh2VbXewzNsbhkI/tlckMCi++holVb7QdsHgRwWjiBjM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":459189},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./widget":"./widget/xmr-pay.js","./receipt":"./src/receipt.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"b6157fa6e18ac44b83bb55010b9471de0eba0402","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/quorum.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/agent-cli.test.js && node test/watch.test.js && node test/webhook.test.js && node test/webhook-redelivery.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/agent-sse.test.js && node test/verify-keyless.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/reorg.test.js && node test/expiry.test.js && node test/property.test.js && node test/rpc-fuzz.test.js && node test/false-paid.test.js && node test/webhook-storm.test.js && node test/break.test.js && node test/soak.test.js && node test/stress.test.js && node test/monero-parity.test.js && node test/adversarial-types.test.js && node test/adversarial-stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:mut":"node test/core.test.js && node test/watch.test.js && node test/property.test.js && node test/agent.test.js && node test/reorg.test.js && node test/scanner-birthday.test.js && node test/verify-gates.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/rpc-fuzz.test.js","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"deprecated":"order-dependence bug in settlement dedup; upgrade to >=1.0.1","repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.16.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"26.3.0","_hasShrinkwrap":false,"devDependencies":{"fast-check":"^4.8.0","@stryker-mutator/core":"^9.6.1"},"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_1.0.0_1781985995994_0.4603060793159566","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"xmr-pay","version":"1.0.1","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@1.0.1","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"bin":{"xmr-pay":"bin/agent.js"},"dist":{"shasum":"6a7e19485c5805d7d88300a9b34a64e1b50e7468","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-1.0.1.tgz","fileCount":33,"integrity":"sha512-j8eUMYfSU2twsraMXAGsSXVHLkGKjG9kBWYs3zxOosdjH9eEfLxurPcOvvoON2MBd9mHA3oXe9NY5tSIeoPmIg==","signatures":[{"sig":"MEQCIAWNB9xQ6OAvOeJNLlZ6PedPgE5vcAuScowDGc5NjfyEAiAd2EB83/vSRbu+Ij/HMcSj4DMmA/ztNqZTU3J5VcmKYQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":460251},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./widget":"./widget/xmr-pay.js","./receipt":"./src/receipt.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"98eb4aa1ad2fc4a99f0781d070e7aa853a830d1d","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/quorum.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/agent-cli.test.js && node test/watch.test.js && node test/webhook.test.js && node test/webhook-redelivery.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/agent-sse.test.js && node test/verify-keyless.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/reorg.test.js && node test/expiry.test.js && node test/property.test.js && node test/rpc-fuzz.test.js && node test/false-paid.test.js && node test/webhook-storm.test.js && node test/break.test.js && node test/soak.test.js && node test/stress.test.js && node test/monero-parity.test.js && node test/adversarial-types.test.js && node test/adversarial-stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:mut":"node test/core.test.js && node test/watch.test.js && node test/property.test.js && node test/agent.test.js && node test/reorg.test.js && node test/scanner-birthday.test.js && node test/verify-gates.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/rpc-fuzz.test.js","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.16.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"26.3.0","_hasShrinkwrap":false,"devDependencies":{"fast-check":"^4.8.0","@stryker-mutator/core":"^9.6.1"},"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_1.0.1_1781986646634_0.4985123675128458","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"xmr-pay","version":"1.0.2","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"author":{"name":"SlowBearDigger"},"license":"MIT","_id":"xmr-pay@1.0.2","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"bin":{"xmr-pay":"bin/agent.js"},"dist":{"shasum":"54974c5f69ae9b0914037a8bc40d1eb18696d8dd","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-1.0.2.tgz","fileCount":33,"integrity":"sha512-XNvO7HQGan9RbRcsWttS4K3idKhoT097jA91Wty8GLmpmG1Jqg2QqyYqVV6Bas5pJA19nfT3Yhkt4ieLd+i+yg==","signatures":[{"sig":"MEUCIFP3ppTh96cp65UvNO0IWiH/Zlbzc/G2kL4nvvUZaYDvAiEAxqRIn+Two4vqBZoia+u0gN0Jy5Zi9aO4t3FMC50WU8o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":461464},"main":"src/verify.js","exports":{".":"./src/verify.js","./core":"./src/core.js","./agent":"./src/agent.js","./watch":"./src/watch.js","./config":"./src/config.js","./verify":"./src/verify.js","./widget":"./widget/xmr-pay.js","./receipt":"./src/receipt.js","./scanner":"./src/scanner.js","./webhook":"./src/webhook.js","./package.json":"./package.json"},"gitHead":"38439f4b15c3ae83c818b770c49f2fbf6273972f","scripts":{"demo":"node examples/demo-server.js","test":"node test/verify-gates.test.js && node test/quorum.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/agent-cli.test.js && node test/watch.test.js && node test/webhook.test.js && node test/webhook-redelivery.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/agent-sse.test.js && node test/verify-keyless.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/reorg.test.js && node test/expiry.test.js && node test/property.test.js && node test/rpc-fuzz.test.js && node test/false-paid.test.js && node test/webhook-storm.test.js && node test/break.test.js && node test/soak.test.js && node test/stress.test.js && node test/monero-parity.test.js && node test/adversarial-types.test.js && node test/adversarial-stress.test.js","agent":"node examples/scanner-agent.js","build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test:mut":"node test/core.test.js && node test/watch.test.js && node test/property.test.js && node test/agent.test.js && node test/reorg.test.js && node test/scanner-birthday.test.js && node test/verify-gates.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/rpc-fuzz.test.js","test:live":"node test/live-stagenet.js","test:agent":"node test/live-agent.js","test:scanner":"node test/live-scanner.js","test:summing":"node test/live-summing.js","test:fastsync":"node test/scanner-fastsync.js"},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"repository":{"url":"git+https://github.com/SlowBearDigger/xmr-pay.git","type":"git"},"_npmVersion":"11.16.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","directories":{},"_nodeVersion":"26.3.0","_hasShrinkwrap":false,"devDependencies":{"fast-check":"^4.8.0","@stryker-mutator/core":"^9.6.1"},"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xmr-pay_1.0.2_1781995225253_0.5906491388251964","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"xmr-pay","version":"1.1.0","description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","main":"src/verify.js","exports":{".":"./src/verify.js","./verify":"./src/verify.js","./core":"./src/core.js","./config":"./src/config.js","./receipt":"./src/receipt.js","./watch":"./src/watch.js","./scanner":"./src/scanner.js","./agent":"./src/agent.js","./webhook":"./src/webhook.js","./state":"./src/state.js","./report":"./src/report.js","./refund":"./src/refund.js","./widget":"./widget/xmr-pay.js","./package.json":"./package.json"},"bin":{"xmr-pay":"bin/agent.js"},"license":"MIT","author":{"name":"SlowBearDigger"},"repository":{"type":"git","url":"git+https://github.com/SlowBearDigger/xmr-pay.git"},"homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"peerDependencies":{"monero-ts":">=0.11.0"},"peerDependenciesMeta":{"monero-ts":{"optional":true}},"scripts":{"build":"bash scripts/build-widget.sh","release":"bash scripts/release.sh","test":"node test/verify-gates.test.js && node test/quorum.test.js && node test/state.test.js && node test/report.test.js && node test/refund.test.js && node test/core.test.js && node test/config.test.js && node test/receipt.test.js && node test/agent-cli.test.js && node test/watch.test.js && node test/webhook.test.js && node test/webhook-redelivery.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/fuzz.test.js && node test/agent.test.js && node test/agent-sse.test.js && node test/verify-keyless.test.js && node test/config-pin.test.js && node test/scanner-birthday.test.js && node test/reorg.test.js && node test/expiry.test.js && node test/property.test.js && node test/rpc-fuzz.test.js && node test/false-paid.test.js && node test/webhook-storm.test.js && node test/break.test.js && node test/soak.test.js && node test/stress.test.js && node test/monero-parity.test.js && node test/adversarial-types.test.js && node test/adversarial-stress.test.js && node test/agent.load.test.js && node test/chaos-reorg.test.js && node test/invariant-stress.test.js","test:mut":"node test/core.test.js && node test/watch.test.js && node test/property.test.js && node test/agent.test.js && node test/reorg.test.js && node test/scanner-birthday.test.js && node test/verify-gates.test.js && node test/verify-rpc.test.js && node test/chaos.test.js && node test/rpc-fuzz.test.js","test:live":"node test/live-stagenet.js","test:scanner":"node test/live-scanner.js","test:fastsync":"node test/scanner-fastsync.js","test:summing":"node test/live-summing.js","test:agent":"node test/live-agent.js","agent":"node examples/scanner-agent.js","demo":"node examples/demo-server.js"},"devDependencies":{"@stryker-mutator/core":"^9.6.1","fast-check":"^4.8.0"},"gitHead":"a1bb1fba0d0b901995c9128b5c526b92ce2bbdc6","_id":"xmr-pay@1.1.0","_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-11IUtviIyEUk3wRCAHYlqv9UORPpELkSyKvPdaKk252QRjusIZICIwKFjAt01eVW0aY3cOxz8pw/KOvr5ZJkcw==","shasum":"62dc55a11145a34e6e893febaac222d7638f1cb9","tarball":"https://registry.npmjs.org/xmr-pay/-/xmr-pay-1.1.0.tgz","fileCount":40,"unpackedSize":597641,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDpmrRlSYEjbWsX4nmZZZcuLHExd3EufCsFTq5gaJI52wIhANaA1QU3bvIDys9IFNytt/ndS6GNl+7FnhCsP142HdQ/"}]},"_npmUser":{"name":"slowbeardigger","email":"slowbeardigger@proton.me"},"directories":{},"maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/xmr-pay_1.1.0_1782077937653_0.5462422385786725"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-11T18:14:36.321Z","modified":"2026-06-21T21:38:57.920Z","0.1.0":"2026-06-11T18:14:36.552Z","0.1.1":"2026-06-11T18:15:24.408Z","0.1.2":"2026-06-11T18:16:04.789Z","0.1.3":"2026-06-11T18:20:34.331Z","0.1.4":"2026-06-11T22:24:58.713Z","0.1.5":"2026-06-11T22:27:37.458Z","0.1.6":"2026-06-12T03:44:55.647Z","0.1.7":"2026-06-12T13:27:07.510Z","0.1.8":"2026-06-12T14:18:06.975Z","0.1.9":"2026-06-13T18:14:34.075Z","0.1.10":"2026-06-13T18:20:34.330Z","0.2.0":"2026-06-14T15:43:41.986Z","0.2.1":"2026-06-14T19:13:41.345Z","0.2.2":"2026-06-14T19:48:56.697Z","0.2.3":"2026-06-14T23:34:15.679Z","0.2.4":"2026-06-15T11:41:26.580Z","0.2.5":"2026-06-15T12:40:03.018Z","0.3.0":"2026-06-15T16:33:09.900Z","0.3.1":"2026-06-15T17:11:19.913Z","0.4.0-beta.0":"2026-06-16T21:26:33.478Z","1.0.0":"2026-06-20T20:06:36.171Z","1.0.1":"2026-06-20T20:17:26.831Z","1.0.2":"2026-06-20T22:40:25.413Z","1.1.0":"2026-06-21T21:38:57.821Z"},"bugs":{"url":"https://github.com/SlowBearDigger/xmr-pay/issues"},"author":{"name":"SlowBearDigger"},"license":"MIT","homepage":"https://github.com/SlowBearDigger/xmr-pay#readme","keywords":["monero","xmr","payments","checkout","tx-proof","non-custodial","serverless","widget"],"repository":{"type":"git","url":"git+https://github.com/SlowBearDigger/xmr-pay.git"},"description":"Sovereign Monero payments toolkit. Client-side payment links + QR (core), stateless on-chain proof verification (verify), signed fulfillment webhooks (webhook), and a zero-dependency checkout widget. No accounts, no API keys, no third parties in the payme","maintainers":[{"name":"slowbeardigger","email":"slowbeardigger@proton.me"}],"readme":"# xmr-pay\n\nAccept Monero on your own site. The money goes straight to your wallet. There is no\ncompany in the middle, no account to open, no fee paid to anyone, and nobody can\nfreeze, see, or hold your funds but you.\n\nxmr-pay is a small toolkit you run yourself: payment links and QR codes, an\nembeddable checkout widget, and trustless on-chain payment detection. It is code,\nnot a service.\n\n[npm](https://www.npmjs.com/package/xmr-pay) · MIT licensed · zero runtime dependencies · signed releases\n\n## Running a WooCommerce store?\n\nThere is a separate, standalone plugin built on this engine:\n\n> **[xmr-pay for WooCommerce](https://github.com/SlowBearDigger/xmr-pay-woocommerce)**\n\nIf you just want to accept Monero in a WordPress store with no code, start there.\nThat plugin stands on its own (install it, paste your address, done) and this README\nis about the library underneath it. The two projects are independent; each links the\nother.\n\n## See it live (stagenet, no real money)\n\n> [live.xmrpay.shop](https://live.xmrpay.shop) : configure it yourself and watch it verify a payment\n> [demo.xmrpay.shop](https://demo.xmrpay.shop) : a full demo store, pay with free test XMR\n> [xmrpay.shop/demo.html](https://xmrpay.shop/demo.html) : the checkout widget and the \"prove you paid\" flow\n\n## You do not need a dedicated server\n\nThis is worth being blunt about, because it is where most Monero tooling adds\nfriction: confirming a Monero payment is, underneath, just reading public blockchain\ndata and doing some math. So none of the ways to do it require a box that stays on\n24/7.\n\n> **Proof mode** is a stateless function that runs on demand. It can live in a\n> serverless function or one small route on the site you already have. Nothing is\n> always-on.\n> **Watch mode** runs wherever you already run code, against your own wallet-rpc or\n> a built-in view-only scanner that needs no daemon at all.\n> **Inside WordPress**, the plugin does both in pure PHP. No Node, no daemon, no\n> separate process. WordPress's own cron and the buyer's checkout page trigger the\n> check; the rest of the time nothing runs.\n\n### Why that is reasonably trustworthy (and where the limits honestly are)\n\n> **It can see, it cannot spend.** Detection only ever holds your *view* key. It can\n> read incoming payments; it can never move your money. The key that spends funds is\n> never asked for and never stored.\n> **The amount is proven, not claimed.** Monero commits the real amount of every\n> output on-chain. The verifier checks that commitment, so a forged or edited amount\n> is rejected. It cannot be talked into seeing money that is not there.\n> **It fails closed.** Several independent checks must all pass: the amount\n> commitment, enough confirmations, the funds are not time-locked, and no\n> transaction is counted twice. If anything is missing, or a node will not answer,\n> the order stays unpaid. It never guesses \"paid\".\n> **The honest caveat:** verification trusts the Monero node you point it at to tell\n> the truth. A public node is fine for most sites. For serious money, point it at\n> your own node, or require two nodes to agree. That one thing is on you, and the\n> setting is right there.\n\nThe verification math is cross-checked against the reference Monero library and the\nwhole money path is covered by an adversarial test suite, so \"no server\" does not\nmean \"cut corners\".\n\n## What you get\n\n> **Your money, directly.** Payments land in your wallet. xmr-pay never holds,\n> routes, or can touch a cent. There is no xmr-pay in the payment path.\n> **No accounts, no API keys, no monthly fee.** It is code you run, not a service\n> you subscribe to.\n> **Privacy by default.** Monero hides amounts and parties on-chain, and nothing in\n> the buyer's browser is trusted to settle an order.\n> **Underpaid, or paid in two goes?** Watch mode sums the payments, so the order\n> finishes itself once the total adds up, and the buyer can top up to the same\n> address.\n\n## The truths (please read before taking real money)\n\nWe would rather tell you the rough edges than have you find them with a customer.\n\n> **Monero is irreversible, and the sender is hidden, so there are no automatic\n> refunds.** If you need to refund someone you send them XMR back by hand. That is\n> the trade for having no chargebacks and no middleman.\n> **You are trusting a node to tell the truth.** A single public node could lie, be\n> slow, or go down. Fine for tips. For real revenue, run your own node or require two\n> nodes to agree (it then refuses to confirm rather than trust one source).\n> **Few confirmations is fast but reversible.** Accepting at zero confirmations is\n> instant, but a payment can still vanish in a chain reorg. Use more confirmations\n> for higher-value orders. This is your risk dial to set.\n> **A brand-new transaction can take a moment to verify on a public node.** If a\n> buyer submits a proof for a transaction still in the mempool, a public node may not\n> serve it yet and the check comes back \"try again\", never a false \"paid\". It clears\n> once the transaction is in a block. Your own node removes the wait.\n> **The browser is never trusted.** Anything shown in a buyer's browser can be faked\n> by that buyer. Goods are released only after your own server verified a real\n> payment on-chain. Same rule as every serious payment system.\n\n## Install\n\n```\nnpm i xmr-pay monero-ts        # monero-ts only needed for server-side detection\n```\n\nThe network is explicit at every entry point. Default is mainnet; use stagenet to\ntest with no real money:\n\n> **Widget:** the network follows the address you pass — a `4…` address is mainnet, `5…`/`7…` is stagenet (no separate attribute).\n> **Verify:** `verifyPayment({ networkType: 'stagenet', ... })`.\n> **Agent:** the `XMR_NETWORK=stagenet` env var (the `npx xmr-pay` wizard asks).\n\n**Run the agent in one command** (non-custodial; it holds only your view key):\n\n```\nnpx xmr-pay        # setup wizard (address + view key + node), then it runs\n```\n\nIt scans from the current block (no historical rescan), generates the token and\nwebhook secret, asks your settlement speed (`instant` 0-conf, `fast` 1 block,\n`secure` 10 blocks), persists its wallet and orders, and prints the exact values to\npaste into your store. `npx xmr-pay start` runs it again later.\n\n## How it works\n\n| Module | Runs | Purpose |\n|---|---|---|\n| `xmr-pay/core` | browser + server | payment URIs (links), QR as SVG, per-order amount nonces |\n| `xmr-pay` (verify) | your backend or serverless fn | re-verify a buyer's tx proof on-chain, trustless |\n| `xmr-pay/watch` | your backend | auto-detection through your own monero-wallet-rpc |\n| `xmr-pay/scanner` | your backend | view-only WASM scanner, auto-detection with NO wallet-rpc daemon |\n| `xmr-pay/agent` | your backend | long-running order manager: per-order subaddress, summing, signed paid webhook |\n| `xmr-pay/config` | offline + browser | signed merchant configs, tamper-evident addresses |\n| `xmr-pay/webhook` | your backend | signed fulfillment webhooks to YOUR systems |\n| `widget/xmr-pay.js` | browser | full checkout UI, one self-hosted file, zero dependencies |\n\nTwo detection modes, freely combined:\n\n| | Proof mode (default) | Watch mode |\n|---|---|---|\n| Infra (yours) | a stateless verify endpoint, on demand | a long-running process you host |\n| Buyer effort | pastes txid + proof | none, just pays |\n| View key | not needed | yours, in-process (view-only) |\n| Partial / top-up auto-complete | manual (single-tx proofs) | automatic, sums transfers |\n| Best for | tips, a single product, lowest infra | a real store, installments, hands-off |\n\n```\nproof mode (no always-on process; your verify endpoint runs on demand):\n  buyer's browser:  pays > wallet makes a tx proof > widget POSTs {txid, proof}\n  YOUR server:      > verify endpoint > verifyPayment re-checks on YOUR nodes > paid\n\nwatch mode (the agent; no monero-wallet-rpc needed):\n  order > fresh subaddress > buyer pays > your agent scans and SUMS transfers\n        > paid (handles partial / split / top-up payments) > signed order.paid webhook\n```\n\nThey share the same exact-math core, so a payment counts identically either way.\nMany shops run watch mode and keep proof as a dispute path. Watch mode is documented\nin full in [docs/AGENT.md](docs/AGENT.md).\n\n## Checkout widget\n\nOne self-hosted file (`widget/xmr-pay.js`, ~98 KB, bundles its own QR encoder, no\nexternal requests ever). Drop it in and you have a Monero checkout.\n\n```html\n<script src=\"/xmr-pay.js\"></script>\n\n<!-- tips / donations, nothing else needed -->\n<xmr-pay address=\"4YOUR_ADDRESS…\" label=\"Buy me a coffee\"></xmr-pay>\n\n<!-- store checkout, detection against YOUR endpoint -->\n<xmr-pay\n  address=\"4YOUR_ADDRESS…\"\n  amount=\"0.050000004821\"\n  order=\"ord_123\"\n  verify-url=\"/api/verify-payment\"\n  theme=\"light\" lang=\"en\"></xmr-pay>\n```\n\n<details>\n<summary><b>Attributes, events, skins, error feedback</b></summary>\n\nWhat the buyer gets: amount + QR (generated locally, with the exact `tx_amount`\nprefilled so wallets can't be sent the wrong amount), click-to-copy address with a\nhighlighted fingerprint, \"open in wallet\" deep link, an always-there trust panel,\nand a \"paid? prove it\" panel that submits txid + tx proof to your endpoint.\n\n**Attributes:** `address` (required unless `config` is set), `amount`, `label`,\n`order`, `verify-url`, `redirect-url`, `lang` (`en`/`es`), `theme` (`light`),\n`skin` (`brutal`), `config` (base64 signed envelope), `fingerprint`/`pubkey` (pin\nthe signer).\n**Events:** `xmr-pay:paid`, `xmr-pay:result` (CustomEvent, verify result in `detail`).\n\n**Buyer-error feedback (built in).** Bad txid gives *\"that transaction ID should be\n64 characters\"*; not a proof gives *\"paste the tx key or the proof block from your\nwallet\"*, caught instantly before any server round-trip. **Underpaid** gives\n*\"Detected 0.1 XMR, send 0.2 more to complete\"* plus a fresh QR for exactly the\nmissing amount (piconero-exact, no float drift). The proof box also smart-pastes a\nwhole Feather block and picks out the txid + proof itself.\n\n**Skins.** Default is a neutral, universal look (system sans, rounded, soft\nshadows). `skin=\"brutal\"` is the GOXMR brand look (monospace, square, hard shadow).\nBoth are driven by `--xp-*` CSS variables, so any brand can retheme without forking.\n\n</details>\n\n## Payment links\n\nA payment link is just a URL. Host [examples/pay-link.html](examples/pay-link.html)\nanywhere static and share:\n\n```\nhttps://your-site.com/pay-link.html#address=4…&amount=0.05&label=Invoice%2042\n```\n\n<details>\n<summary><b>monero: URIs, wallet compatibility, short links</b></summary>\n\n`core.makePaymentURI()` builds the `monero:` URI (also what the widget's QR and\n\"open in wallet\" use). The URIs are round-trip tested against the official wallet2\nparser (what GUI, CLI and Feather run internally), including 12-decimal nonce\namounts and unicode descriptions, so they prefill cleanly across Feather, GUI, CLI,\nCake, Monerujo and Stack (mobile + desktop, Win/Mac/Linux).\n\nPrefer the `#fragment` form for shared links; fragments never reach server logs or\nproxies. Truly short URLs (`/p/x7k2`) need a lookup, so add a redirect route on your\nown server rather than a third-party shortener that would track your buyers.\n\nBuyer-side wallet instructions (Feather/GUI/Cake/CLI menu names, restored-seed\ncaveat): [docs/WALLETS.md](docs/WALLETS.md).\n\n</details>\n\n## Order creation (amount-nonce)\n\n```js\nconst { makeAmountNonce } = require('xmr-pay/core');\nconst amount = makeAmountNonce('0.05');   // '0.050000004821', unique per order\n// store { order_id, amount } in YOUR db; render the widget with that amount\n```\n\nThe random piconero tail makes each order's on-chain amount unique, so a proof\nstructurally fits only its own order: a secondary anti-replay guard on top of your\ntxid dedup. The added value is dust (default ≤ 0.000001 XMR).\n\n## Proof mode\n\nThe only server piece, and it is yours: stateless, runs on demand.\n\n```js\nconst { verifyPayment } = require('xmr-pay');\n\nconst r = await verifyPayment({\n  txid, proof,                       // what the buyer pasted (tx key or tx proof, auto-detected)\n  address: order.address,\n  amount: order.amount_xmr,          // string keeps 12-decimal nonces exact\n  nodes: ['https://your-node:18081', 'https://fallback:18081'],\n  minConfirmations: 1,               // 0 accepts mempool, your risk, your call\n  quorum: 1,                         // 2+ means independent nodes must agree\n  alreadyUsed: (txid) => db.txidSeen(txid),\n});\n// { paid, status, reason, receivedXmr, expectedXmr, shortfallXmr, confirmations,\n//   txid, nodesAgreed, overpaid }   txid comes back normalized (lowercase)\n```\n\nFull endpoint with anti-spam gates: [examples/serverless.js](examples/serverless.js).\nDrop it in Vercel/Netlify/Express; stateless, your orders table is the only state\nand it is already yours. One-click deploy template: [docs/DEPLOY.md](docs/DEPLOY.md).\n\nA freshly broadcast (mempool) transaction may not be retrievable from a public node\nyet, so verification returns `node-error` (retryable, never a false `paid`) until the\ntx is in a block. Run your own node to remove the wait.\n\n<details>\n<summary><b>No <code>monero-ts</code>? Verify through your wallet-rpc</b></summary>\n\nIf you already run `monero-wallet-rpc`, `verifyPaymentViaRpc` checks the same proofs\nthrough it: same gates, same result shape, no WASM peer to install (so none of\n`monero-ts`'s transitive advisories; see SECURITY.md):\n\n```js\nconst { verifyPaymentViaRpc } = require('xmr-pay/watch');\nconst r = await verifyPaymentViaRpc({\n  url: 'http://127.0.0.1:18083',     // your monero-wallet-rpc\n  txid, proof, address: order.address, amount: order.amount_xmr,\n  nodes: ['https://your-node:18081'], // for the time-lock gate if the wallet has no record of the tx\n});\n```\n\n</details>\n\n## Watch mode\n\nAutomatic detection: a fresh subaddress per order, payments summed (so partial\npayments and top-ups auto-complete), the buyer submits nothing. Two transports: your\nown `monero-wallet-rpc`, or a view-only WASM scanner with no daemon at all.\n\n```js\n// no daemon: a view-only wallet from (address + view key), the agent does the rest\nconst { createScanner } = require('xmr-pay/scanner');\nconst { createPaymentAgent } = require('xmr-pay/agent');\n\nconst scanner = await createScanner({ primaryAddress, privateViewKey, networkType, nodes });\nconst agent = createPaymentAgent({ scanner, minConfirmations: 1, onPaid: (o) => fulfil(o) });\nagent.start();\n\nconst order = await agent.createOrder({ id: 'ord_42', amount: '0.05' });  // returns { address, … }\nconst r = await agent.check('ord_42');   // { paid, status, receivedXmr, shortfallXmr, … }\n```\n\nEach order gets its own subaddress, and a second order can never bind a subaddress\nalready in use, so two orders can't credit the same payment. Full guide, the runnable\nHTTP service, config, and the trust model: [docs/AGENT.md](docs/AGENT.md).\n\n<details>\n<summary><b>Or through your own monero-wallet-rpc</b></summary>\n\n```js\nconst { createWatcher } = require('xmr-pay/watch');\nconst watcher = createWatcher({ url: 'http://127.0.0.1:18083' });\nconst { address, index } = await watcher.newSubaddress('order ord_123');\nconst r = await watcher.checkOrder({ subaddressIndex: index, amount: order.amount_xmr });\n// { paid, status: paid|partial|mempool|locked|pending, receivedXmr, shortfallXmr, txids }\n```\n\nPer-order subaddresses replace the amount-nonce here (the address identifies the\norder). Time-locked outputs never count as paid. Keep wallet-rpc on localhost.\n\n</details>\n\n## Webhooks\n\nThere is no xmr-pay server to call you. Your detection IS the webhook moment: when a\npayment settles, notify whatever needs to know (shop platform, shipping, Discord,\nZapier), signed with your own secret:\n\n```js\nconst { sendWebhook, verifySignature } = require('xmr-pay/webhook');\n\nif (r.paid) {\n  await sendWebhook(process.env.FULFILL_WEBHOOK_URL, {\n    event: 'order.paid', order_id, txid: r.txid, confirmations: r.confirmations,\n  }, { secret: process.env.FULFILL_WEBHOOK_SECRET });   // X-XMR-Pay-Signature: sha256=…\n}\n// receiver: verifySignature(rawBody, secret, req.headers['x-xmr-pay-signature'])\n```\n\nRetries with backoff built in. (The agent fires this for you, once, on settle.) The\nsigned body carries an `event_ts` (unix ms): after verifying the signature, reject a\ndelivery whose `event_ts` is stale, and stay idempotent on `order_id`, so a replayed\nwebhook can't trigger a second fulfillment. The browser also gets an `xmr-pay:paid`\nDOM event; treat it as UX only (a thank-you, a redirect), never the signal to release\ngoods.\n\n## Security and trust\n\n**The browser decides nothing. Fulfill on your server.** A buyer can fake the\n`xmr-pay:paid` event in devtools or point the widget at a fake server; it only fools\ntheir own screen, and your server never verified a real payment.\n\n**Node trust.** Verification is only as honest as the nodes you query. The default\n`quorum` is `1` (fast, single node); set `quorum: 2`–`3` for serious volume so\nindependent nodes must agree (it fails closed on disagreement, so availability then\nrides on your nodes). For the highest confidence run your own `monerod` and use RPC\nmode (`verifyPaymentViaRpc` against your own `monero-wallet-rpc`), which sidesteps the\nbundled WASM wallet and its transitive dependencies entirely.\n\n<details>\n<summary><b>Threat model</b></summary>\n\n| Attack | Outcome |\n|---|---|\n| Buyer claims \"I paid\" with no proof | nothing to verify, rejected |\n| Buyer fakes \"paid\" in devtools (forge the event, edit DOM, point `verify-url` at a fake server) | cosmetic, only their screen; your order stays unpaid. Fulfill server-side |\n| Forged or tampered proof | fails cryptographic verification on-chain |\n| Proof for a payment to someone else | proofs are address-bound, rejected |\n| Reusing a real proof on another order | amount-nonce + `alreadyUsed`, returns `replay`/`underpaid` |\n| Off by 1 piconero | integer-piconero compare, returns `underpaid` |\n| Amount above Monero's max supply (uint64) | rejected; `xmrToPico`/`atomicToPico` enforce the on-chain ceiling, parity with monerod's `parse_amount` |\n| Time-locked payment (`unlock_time` set, confirms but frozen) | raw tx fetched from the daemon; `unlock_time ≠ 0` returns `locked`. Fails closed if no node returns the tx |\n| A node lies | `quorum: 2+` returns `node-disagreement` |\n| A node or wallet-rpc is down, slow, or times out | `node-error`, transient and retryable, never a false `paid`. Distinct from `invalid` so you can tell \"retry\" from \"reject\"; the example endpoint answers `503` |\n| Endpoint spam | gate on \"order exists and pending\" before any RPC |\n| Double-submit race (same txid, concurrent) | claim the txid atomically with a `UNIQUE` constraint on `tx_hash` |\n\n</details>\n\n<details>\n<summary><b>Hardening checklist (the part that stays on you)</b></summary>\n\n> **Fulfill server-side, never from the browser.** Release goods only after your\n> server returned `paid` and wrote it to your order record. Same rule as Stripe.\n> **`UNIQUE` constraint on `tx_hash`** in your orders table closes the replay race\n> the `alreadyUsed` callback only narrows.\n> **Use `makeAmountNonce` for every order** (proof mode), so a proof can't fit\n> another order.\n> **Scale `minConfirmations` with value**: 1 for small carts, 10 for high-value\n> (reorg safety). `minConfirmations: 0` (mempool) is opt-in risk.\n> **`quorum: 2` for high-value orders**, so two independent nodes must agree.\n> **Never take `address`/`amount` from the request body**; always your own order\n> record (the examples do this).\n> **Your page is the trust root.** If it is compromised the address can be swapped,\n> so use a signed config + published fingerprint (below) for real-money stores.\n\n</details>\n\n<details>\n<summary><b>Signed config (tamper-evident address)</b></summary>\n\nSigning moves address integrity onto a key the merchant keeps off the web server, so\na breach can serve the real signed config or a broken one, but cannot mint a new one\nfor the attacker's address.\n\n```js\nconst { generateSigningKey, signConfig } = require('xmr-pay/config');\nconst key = generateSigningKey();                 // keep privateKey offline\nconst env = signConfig({ address, amount: '0.05', networkType: 'mainnet' }, key.privateKey);\n// env.fingerprint e.g. \"2847-789f-a55a-bd90-1234-5678\", publish where buyers can check\n```\n\n```html\n<xmr-pay config=\"<base64 envelope>\" verify-url=\"/api/verify-payment\"></xmr-pay>\n```\n\nThe widget verifies the Ed25519 signature (WebCrypto, no extra dependency), uses the\nsigned address, and shows `Signed · <fingerprint>`. A \"signed\" config that fails\nverification shows a red warning and no payable address. Pin a known signer with\n`pubkey=\"…\"` or `fingerprint=\"…\"`. With the fingerprint known out of band a buyer\ncatches an address swap even on a fully compromised page.\n\n</details>\n\n<details>\n<summary><b>Privacy: what a node sees</b></summary>\n\nVerifying a payment asks one node for one transaction by its txid. The node learns\nthe txid and your IP/timing, not the amount or address (derived locally). That is\nless than a normal wallet exposes. Close the exposure at the connection level: run\nyour own node (list it first in `nodes`), or egress over Tor / point at an `.onion`\nnode. `nodes` takes any URL, configuration not code.\n\n</details>\n\n## Demo\n\nA complete, deployable demo lives in [`demo/`](demo/): a stagenet store checkout that\nverifies a real payment on-chain, plus a mainnet tip widget with no backend.\n\n```\ncd demo && npm install && npm start    # http://localhost:8780, click \"Try it\"\n```\n\n## Validated\n\n187 offline checks plus a 92,006-case math fuzz, plus live stagenet validation.\n\n> Offline: input gates 40, core (links/QR/nonce) 22, signed configs 10, watch summing\n> 14, webhooks 8, wallet-rpc verify 20, adversarial \"chaos\" 27, agent lifecycle 17,\n> monerod amount parity 29, node-quorum 13, plus order-independence and\n> byzantine-duplicate stress. The fuzz hammers the piconero math (shortfall, summing,\n> round-trips) so paying the displayed difference always completes an order to the\n> exact piconero, including the float traps (`0.1 + 0.2 = 0.3`). The parity suite\n> mirrors monerod's own `parse_amount` (overflow ceiling, 13th-decimal, signs) so we\n> never accept an amount the chain rejects.\n> Live on stagenet: proof verify through a 13-case adversarial matrix (exact,\n> underpaid/overpaid to the piconero, replay, address-bound rejection, malformed\n> returns `invalid`, dead node returns `node-error`, 2-node quorum, at 0-conf and\n> 1-conf), all through the unlock_time gate; the view-only scanner detecting a real\n> payment via the view key alone; two real payments summed on one subaddress to\n> complete an order; the agent end to end (per-order subaddress, settle, one-time\n> signed webhook). Spot-checked against a real mainnet transaction key.\n\n## Donate\n\nIf xmr-pay saved you a payment processor's cut, a little Monero back is welcome,\nnever required:\n\n```\n45sEohkyWYxAfHy8ekP7B34Bd3qhgrupcQfUQAHvfUWkfgqJhCA4QYLigrBg8G8TE4WggtMGpmjXrbmvepkWLec58KKLkm9\n```\n\n## Releases\n\n<details>\n<summary><b>Build the widget yourself and verify a download</b></summary>\n\nThe widget is a plain concatenation of `widget/xmr-pay.part.js` and the vendored\n`qrcode-generator` (`src/vendor/`): no minifier, no timestamps, no npm install:\n\n```\nnpm run build\nshasum -a 256 widget/xmr-pay.js     # must match SHA256SUMS in the release\n```\n\nEach release ships `SHA256SUMS` plus a minisign signature. Public key (also\n`minisign.pub` in this repo): `RWSA/E4ogu5/1mQf2r66pkWK9fYBEeFdf2cvrjkhiALoXCWT3woSSRtH`\n\n```\nminisign -Vm SHA256SUMS -P RWSA/E4ogu5/1mQf2r66pkWK9fYBEeFdf2cvrjkhiALoXCWT3woSSRtH\nshasum -a 256 -c SHA256SUMS\n```\n\nFrom npm the package is published with provenance (`npm view xmr-pay --json | grep\nprovenance`). If a signature or hash does not match, do not use the file, and report\nit.\n\n</details>\n\n## Docs\n\n> [docs/AGENT.md](docs/AGENT.md) : watch mode and the merchant agent (what it solves, API, trust model)\n> [docs/DEPLOY.md](docs/DEPLOY.md) : one-click deploy of the verify endpoint\n> [docs/WALLETS.md](docs/WALLETS.md) : buyer-side wallet instructions per wallet\n> [docs/SUITE.md](docs/SUITE.md) : how the pieces fit together\n> [CHANGELOG.md](CHANGELOG.md) : release notes\n> [SECURITY.md](SECURITY.md) : reporting, dependency advisories, \"try to break it\"\n\n## Acknowledgements\n\nWe stand on excellent open-source work. Give them a star:\n\n> [monero-project](https://www.getmonero.org/): the protocol; our money-math parity suite mirrors `parse_amount`'s own unit tests.\n> [monero-integrations / monerophp](https://github.com/monero-integrations/monerophp) (MIT): the pure-PHP ed25519, key-derivation and base58 primitives the WordPress-native verifier is vendored on. The breakthrough that made \"verify in PHP\" possible.\n> [kornrunner/php-keccak](https://github.com/kornrunner/php-keccak) (MIT): Keccak-256 with Monero's padding, in pure PHP.\n> [monero-ts](https://github.com/woodser/monero-ts) (woodser, MIT): the WASM Monero library powering the watch/proof paths, and our ground-truth reference for cross-checking the PHP verifier.\n> [qrcode-generator](https://github.com/kazuhikoarase/qrcode-generator) (MIT): the checkout widget's self-contained QR encoder.\n> Inspiration: [BTCPay Server](https://btcpayserver.org/)'s Monero plugin, [MoneroPay](https://gitlab.com/moneropay/moneropay), and [AcceptXMR](https://github.com/busyboredom/acceptxmr). We studied all three to match (and, on reorg-safety, double-spend and arithmetic, exceed) their detection model.\n\n## License\n\nMIT, including the vendored [qrcode-generator](https://github.com/kazuhikoarase/qrcode-generator)\n(c) Kazuhiko Arase, bundled so the widget makes zero external requests.\n\nA [GoXMR](https://goxmr.click) project, also available for [WordPress / WooCommerce](https://github.com/SlowBearDigger/xmr-pay-woocommerce).\n","readmeFilename":"README.md"}