fix(payments): use Coinflow session keys on web and mobile - #14615
Merged
Merged
Conversation
|
raymondjacobson
added a commit
that referenced
this pull request
Sep 29, 2026
Coinflow is retiring wallet/blockchain-only authentication. Add `POST /coinflow/session-key` to identity service so authenticated clients can obtain a session using a server-side merchant API key. The endpoint requires a fresh Ed25519 proof of ownership of the root Solana wallet, bound to the authenticated identity and environment. The public `spl_wallet` is a user bank, so it cannot be used to identify the Coinflow wallet. Responses are non-cacheable; timeouts, malformed upstream responses, and upstream errors fail closed without exposing credentials. **Rollout:** deploy this PR first with `coinflowApiKey` and `coinflowEnvironment`. The API key must match the clients' merchant (`audius` in sandbox, `tikilabs` in production). [Client PR #14615](#14615) must follow this configured deployment. Deployment instructions and sandbox/device checks are in the identity-service README. No database migration is needed. **Validation:** 8 isolated backend tests pass, covering wallet/identity/signature tampering, stale/future proofs, environment mismatch, missing configuration, upstream response validation, and credential-safe errors. Targeted lint passes with dependency-resolution checks disabled in the isolated environment; `git diff --check` passes. Full `npm run verify` could not start because this checkout has no project dependencies (`turbo: command not found`). Live Coinflow and full identity-service integration tests have not been run.
Base automatically changed from
codex/coinflow-session-auth-backend
to
main
September 29, 2026 01:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Coinflow purchase and withdrawal now wait for a session key before rendering on web and mobile. A shared hook signs a root-wallet ownership proof, requests the key from identity service, keeps it in memory, refreshes it after 25 minutes, and stops using it before expiry. Loading and retry UI covers authentication failures.
Keys are scoped to identity, wallet, account, and environment; stale adapter initialization and late responses cannot carry a previous account's credentials into the new account. All four components retain their transaction-signing adapters. The pinned SDKs already forward session keys, so no SDK upgrade is required. Correct the common Vitest source alias so the new hook tests resolve their mocked modules.
Rollout: this PR is stacked on the backend session endpoint PR #14614. Merge and deploy that endpoint with the matching Coinflow API key/environment before merging this PR. Release the mobile update as well as web, then test purchase/withdrawal in sandbox on web, iOS, and Android, including guest checkout, expiry/retry, and account switching. Confirm completion with Coinflow only after production rollout and verification.
Validation: 6 hook tests pass with React 19 and the pinned TanStack Query version in an isolated dependency environment. They cover the signing proof, closed-modal gating, refresh failure/expiry/retry, account/logout isolation, late wallet responses, stale adapters, and expired credentials. Scoped hook typechecking and prop compatibility checks against web SDK 5.9.1 / native SDK 4.5.2 pass. Targeted lint passes with dependency-resolution checks disabled;
git diff --checkpasses. Fullnpm run verifycould not start (turbo: command not found); full application typechecks, live checkout, and iOS/Android device tests remain unrun.