Skip to content

Ship Hosted Gate through the canonical Secretless Gateway - #491

Open
moelayyan90 wants to merge 10 commits into
mainfrom
feat/hosted-gate-authz-v3
Open

Ship Hosted Gate through the canonical Secretless Gateway#491
moelayyan90 wants to merge 10 commits into
mainfrom
feat/hosted-gate-authz-v3

Conversation

@moelayyan90

Copy link
Copy Markdown
Owner

Rebuilds the Hosted Gate work on the current Secretless Gateway main branch instead of the stale pre-Secretless wrapper.

What this adds:

  • GET /v1/gate machine discovery
  • GET|POST /v1/gate/authorize reverse-proxy payment authorization
  • x402 v2 PAYMENT-REQUIRED challenge generation
  • strict binding of scheme/network/asset/payTo/amount/resource before facilitator calls
  • verify -> settle -> origin authorization only after successful settlement
  • fail-closed handling for ambiguous/unavailable settlement
  • Nginx auth_request compatibility plus Caddy/Traefik guidance
  • MCP xguard_hosted_gate discovery tool
  • Hosted Gate augmentation in OpenAPI/architecture/LLM/skill surfaces
  • production smoke tests that fail deployment unless Hosted Gate is live and discoverable

The canonical production entry remains product-entry.js; no Secretless Egress, Action Rail, Durable Object, MCP identity, or x402 compatibility surfaces are removed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant