Skip to main content

Unreleased

Added

  • Browser-hosted pane mode for mobile hosts: the pane opens in the system browser (an OS auth-session, e.g. openAuthSessionAsync) — a supported hosting mode required for passkey-first products, which WebViews cannot serve (no WebAuthn on Android WebView; iOS WKWebView would need a webcredentials association file 0xramp does not serve). No bridge in this mode; the flow is create, open, return deep link, authoritative status. Stage-1 SELL is designed to work with zero bridge — planned pane-side work, not yet live in the deployed pane (no QR/copy outside a native WebView; no return-link navigation yet). See the Integration Guide.
  • Draft zec-send deep-link handoff codec for that mode — unfrozen; first-partner integration in progress; encoding may change; pane-side conformance not claimed: parseZecSendHandoffUrl (pane-to-wallet payment request; the expected session is required — a link from any other session throws SessionMismatch; fail-closed on duplicated query parameters, malformed parameters, and non-canonical amounts; a trailing #fragment is ignored; output is ZecSendRequestPayload-compatible so existing sendStore claim/journal semantics apply unchanged) and buildZecSendResumeUrl (wallet-to-pane resume URL with advisory txid evidence, 1-32 individual 64-hex IDs; the 2048-character deep-link bound binds first — roughly 28-30 txids fit on realistic pane URLs, larger sets reconcile via the status endpoint). Exported from the root package and @0xramp/sdk/session. See the API Reference.

Changed

  • createSession rejects a returnUrl whose scheme is not letter-first per RFC 3986 with ConfigError before any POST — digit-first schemes and values without a scheme prefix fail closed; https: URLs and schemes without // are accepted; an absent returnUrl stays a no-op. Register the exact string: the server’s return-link allowlist compares the full value exactly — a query string or fragment makes session create fail with 403. Enforced client-side: the wire schema and golden fixtures are unchanged.

v0.0.2 — Recovery additions

  • createZecSendStore(storage) — durable journal over secure get/set storage.
  • restoreSession(saved) — revalidates session and origin, restores status ticket without POST.
  • isAllowedPaneUrl(url) — exposes client origin policy.
  • requestTimeoutMs — bounds fetch plus body parsing; redirects and retries disabled.
  • sendZecSendResult / sendZecSendCancel — persist before replying; only accept known requests.
  • onSendRecoveryRequired — receives pending reason and known transaction IDs.
  • psp/zec-send-pending host reply with reasons: in-progress, broadcast-unknown, multiple-transactions, storage-unavailable.
  • Multi-transaction ID support (1-32 individual 64-hex IDs).
  • sessionUrl checked against pane allowlist on create.
  • Bridge binds only on psp/ready; pre-ready messages rejected.
  • ApiError redacts raw sessionRef from error messages.
  • Status ticket Map capped at 16 most recent.

v0.0.1 — Initial scaffold

  • createRampClient with environment, partnerId, sendStore config.
  • createSession — POST to partner sessions endpoint.
  • attachPaneBridge — host-side bridge with origin lock, single-use requestIds, session mismatch handling.
  • getStatus — ticketed read-only status endpoint.
  • parseReturnUrl — advisory deep-link parsing.
  • PSP-v1 envelope: { v: 1, type, sessionRef, payload }.
  • Four bridge events: psp/ready, psp/zec-send-request, psp/result, psp/close.
  • Two host replies: psp/zec-send-result, psp/zec-send-cancel.
  • Golden wire fixtures for conformance testing.
  • Sandbox pane for development without 0xramp access.
  • Electron and React Native example hosts.
  • Pure ESM, strictly typed, React-free. Zero runtime dependencies besides schema validation.
The SDK is under active development. The public API and wire format are additive-only until the protocol freezes at 0.1.0.