Files
amethyst/contextvm
Claude ce717751b0 feat(contextvm): CEP-8 pricing and payment, CEP-21 PMI conventions
Build item 13, client side. Tag family, both lifecycles, the canonical
invocation identity, and the negotiation state machine.

The canonical identity is the part with teeth. A payment authorizes a future
execution and the client is told to retry "the same request", so the identity
is the client pubkey plus sha256(JCS({method, params})) with params._meta
removed. The exclusion is load-bearing rather than tidy: MCP regenerates
progressToken on every callTool, so without it two semantically identical
invocations hash differently and a paid authorization could never be matched.
It applies to identity derivation only -- semanticParams() returns a copy, so
the full original params still reach the handler at execution time.

The other rule with consequences is that neither side may silently fall back.
PaymentSession makes a failed explicit_gating negotiation visible instead of
degrading, and mayAutoPay() is the gate a handler must pass: a client that
required visible payments will not settle a transparent payment_required it
receives anyway. A handler that simply pays what it is asked violates the
client half of CEP-8, so the refusal lives in the type rather than in a
comment.

Also covers the cap tag with fixed and inclusive-range prices, PMI validation
against the W3C format with the -direct bearer suffix from CEP-21, the
transparent notifications, and the -32042/-32043 error payloads.

31 CVM-8-* and CVM-21-* tests. Verified by mutation: including _meta in the
identity, and dropping the visible-payments check, each kill exactly their
guarding test. Module suite at 120.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n
2026-09-18 01:49:30 +00:00
..