Unreleased
Added
- Browser-hosted pane mode for mobile hosts: the pane opens in the system browser (an OS auth-session, e.g.
openAuthSessionAsync) — a supported hosting mode required for passkey-first products, which WebViews cannot serve (no WebAuthn on Android WebView; iOS WKWebView would need awebcredentialsassociation file 0xramp does not serve). No bridge in this mode; the flow is create, open, return deep link, authoritative status. Stage-1 SELL is designed to work with zero bridge — planned pane-side work, not yet live in the deployed pane (no QR/copy outside a native WebView; no return-link navigation yet). See the Integration Guide. - Draft zec-send deep-link handoff codec for that mode — unfrozen; first-partner integration in progress; encoding may change; pane-side conformance not claimed:
parseZecSendHandoffUrl(pane-to-wallet payment request; the expected session is required — a link from any other session throwsSessionMismatch; fail-closed on duplicated query parameters, malformed parameters, and non-canonical amounts; a trailing#fragmentis ignored; output isZecSendRequestPayload-compatible so existingsendStoreclaim/journal semantics apply unchanged) andbuildZecSendResumeUrl(wallet-to-pane resume URL with advisory txid evidence, 1-32 individual 64-hex IDs; the 2048-character deep-link bound binds first — roughly 28-30 txids fit on realistic pane URLs, larger sets reconcile via the status endpoint). Exported from the root package and@0xramp/sdk/session. See the API Reference.
Changed
createSessionrejects areturnUrlwhose scheme is not letter-first per RFC 3986 withConfigErrorbefore any POST — digit-first schemes and values without a scheme prefix fail closed;https:URLs and schemes without//are accepted; an absentreturnUrlstays a no-op. Register the exact string: the server’s return-link allowlist compares the full value exactly — a query string or fragment makes session create fail with 403. Enforced client-side: the wire schema and golden fixtures are unchanged.
v0.0.2 — Recovery additions
createZecSendStore(storage)— durable journal over secure get/set storage.restoreSession(saved)— revalidates session and origin, restores status ticket without POST.isAllowedPaneUrl(url)— exposes client origin policy.requestTimeoutMs— bounds fetch plus body parsing; redirects and retries disabled.sendZecSendResult/sendZecSendCancel— persist before replying; only accept known requests.onSendRecoveryRequired— receives pending reason and known transaction IDs.psp/zec-send-pendinghost reply with reasons:in-progress,broadcast-unknown,multiple-transactions,storage-unavailable.- Multi-transaction ID support (1-32 individual 64-hex IDs).
sessionUrlchecked against pane allowlist on create.- Bridge binds only on
psp/ready; pre-ready messages rejected. ApiErrorredacts raw sessionRef from error messages.- Status ticket Map capped at 16 most recent.
v0.0.1 — Initial scaffold
createRampClientwith environment, partnerId, sendStore config.createSession— POST to partner sessions endpoint.attachPaneBridge— host-side bridge with origin lock, single-use requestIds, session mismatch handling.getStatus— ticketed read-only status endpoint.parseReturnUrl— advisory deep-link parsing.- PSP-v1 envelope:
{ v: 1, type, sessionRef, payload }. - Four bridge events:
psp/ready,psp/zec-send-request,psp/result,psp/close. - Two host replies:
psp/zec-send-result,psp/zec-send-cancel. - Golden wire fixtures for conformance testing.
- Sandbox pane for development without 0xramp access.
- Electron and React Native example hosts.
- Pure ESM, strictly typed, React-free. Zero runtime dependencies besides schema validation.
The SDK is under active development. The public API and wire format are additive-only until the protocol freezes at 0.1.0.