Difficulty: Advanced (senior · 7/10). ~14–20h. Node/TypeScript CLI, HTTP, protocol config validation.
Context
Every recent community x402 submission on this repo failed against the real protocol for the same class of mistake: wrong payment header name (X-PAYMENT is v1; Nirium's v2 flow uses PAYMENT-SIGNATURE), a facilitator URL that doesn't support Stellar, or a missing facilitatorApiKey (the OpenZeppelin Channels facilitator rejects unauthenticated servers on testnet too — a production lesson that cost real debugging time). None of this is obvious from the protocol spec alone; it only shows up once you try to run against the live facilitator.
Goal
A nirium doctor command in the existing nirium CLI that inspects a project's x402/MPP configuration and reports concrete, actionable problems before a developer burns an hour debugging a silent 402.
Scope / Deliverables
nirium doctor [--network testnet|pubnet] — reads env vars (or a --config file) for payTo, facilitatorUrl/facilitatorApiKey, secretKey/network, and MPP equivalents.
- Validates:
payTo is a well-formed Stellar G... address (not a secret key); the configured facilitator responds to a live health/getSupported call for the target network; a facilitator API key is present when the facilitator requires one; the network passphrase implied by network matches what the configured RPC endpoint reports (catches the txBadAuth "wrong network" class of bug).
- Clear, colored pass/fail output per check, with a one-line fix suggestion for each failure — not just "invalid config".
--json output mode for CI use.
- Tests: each check runs against a mocked facilitator/RPC (both the pass and fail path).
- README section under
packages/cli/README.md with example output.
Acceptance criteria
- Run against a deliberately broken config (missing facilitator key, malformed
payTo, wrong network) and produce the correct diagnosis for each, proven by tests.
- Run against a known-good testnet config and report all green.
nirium doctor --help documents every flag; lint/CI pass.
Pointers
packages/sdk/src/index.ts — x402Serve()'s own validation (payTo regex, facilitatorApiKey requirement) is the canonical source of truth for what "valid" means; reuse or mirror it rather than re-deriving the rules.
- Facilitators: testnet
https://channels.openzeppelin.com/x402/testnet, mainnet https://channels.openzeppelin.com/x402.
- Existing CLI:
packages/cli/bin/nirium.js (commander-based, only has create today).
Out of scope
- Auto-fixing the misconfiguration —
doctor diagnoses, it does not rewrite the caller's config.
- Protocols beyond x402/MPP.
References
Reward
Eligibility is subject to GrantFox review under this campaign. Rewards are decided by GrantFox based on quality and available budget and are not guaranteed.
Difficulty: Advanced (senior · 7/10). ~14–20h. Node/TypeScript CLI, HTTP, protocol config validation.
Context
Every recent community x402 submission on this repo failed against the real protocol for the same class of mistake: wrong payment header name (
X-PAYMENTis v1; Nirium's v2 flow usesPAYMENT-SIGNATURE), a facilitator URL that doesn't support Stellar, or a missingfacilitatorApiKey(the OpenZeppelin Channels facilitator rejects unauthenticated servers on testnet too — a production lesson that cost real debugging time). None of this is obvious from the protocol spec alone; it only shows up once you try to run against the live facilitator.Goal
A
nirium doctorcommand in the existingniriumCLI that inspects a project's x402/MPP configuration and reports concrete, actionable problems before a developer burns an hour debugging a silent 402.Scope / Deliverables
nirium doctor [--network testnet|pubnet]— reads env vars (or a--configfile) forpayTo,facilitatorUrl/facilitatorApiKey,secretKey/network, and MPP equivalents.payTois a well-formed StellarG...address (not a secret key); the configured facilitator responds to a live health/getSupportedcall for the target network; a facilitator API key is present when the facilitator requires one; the network passphrase implied bynetworkmatches what the configured RPC endpoint reports (catches thetxBadAuth"wrong network" class of bug).--jsonoutput mode for CI use.packages/cli/README.mdwith example output.Acceptance criteria
payTo, wrong network) and produce the correct diagnosis for each, proven by tests.nirium doctor --helpdocuments every flag; lint/CI pass.Pointers
packages/sdk/src/index.ts—x402Serve()'s own validation (payToregex,facilitatorApiKeyrequirement) is the canonical source of truth for what "valid" means; reuse or mirror it rather than re-deriving the rules.https://channels.openzeppelin.com/x402/testnet, mainnethttps://channels.openzeppelin.com/x402.packages/cli/bin/nirium.js(commander-based, only hascreatetoday).Out of scope
doctordiagnoses, it does not rewrite the caller's config.References
Reward
Eligibility is subject to GrantFox review under this campaign. Rewards are decided by GrantFox based on quality and available budget and are not guaranteed.