Add post-payment delivery validation without retrying possible spend
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- python
- Área
- backend-api-design, payments
Línea de trabajo
Comienza con el flujo de pagos de AgentCore LangGraph en src/bedrock_agentcore/payments/integrations/langgraph/README.md y sigue los tres puntos de entrada nombrados: wrap_tool_call, awrap_tool_call y Strands after_tool_call. Reproduce el flujo simulado de PaymentManager con un challenge, una credencial, un reintento pagado y una salida malformada. Se considera terminado cuando el callback opcional comparte una semántica coherente, conserva la evidencia de un posible gasto al rechazar, evita otro intento de pago automático y deja sin cambios el comportamiento cuando no hay callback.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is your feature request related to a problem? Please describe.
The AgentCore Payments LangGraph middleware and Strands plugin can detect a
payment challenge, obtain a credential, retry the tool, and return the paid
result. There is no opt-in application-output gate between that paid retry and
result promotion.
That leaves a buyer unable to reject malformed or contract-invalid application
output while preserving two facts: a payment credential may already have spent,
and the middleware must not automatically pay or retry again.
A credential-free reproduction uses a fake PaymentManager and a local tool:
- The first tool call returns an x402 or MPP payment challenge.
- The fake manager returns one payment credential.
- The paid retry returns HTTP 200 with malformed application output.
- The current middleware returns that output through LangGraph sync,
LangGraph async, or Strands without a buyer-owned validation hook.
No AWS account, wallet, signature, or live payment is needed to reproduce the
control-flow gap.
Describe the solution you'd like
Add an optional post-payment delivery callback to the existing integrations.
When configured, it should:
- receive the raw paid result plus an immutable snapshot of the selected
payment requirement or challenge; - run after exactly one credential generation and one paid retry;
- preserve the original paid result and explicit possible-spend evidence when
validation rejects or raises; - return a deterministic failure through the native LangGraph or Strands path;
- set native retry behavior so the same result cannot trigger another automatic
payment attempt; and - leave current behavior unchanged when the callback is absent.
Protocol-native evidence should retain its authority label. An x402 Payment
Response or MPP Receipt can be exposed as observed, unverified evidence. Calling
settlement verified should require a separate protocol-specific verifier that
reconciles the native transaction or reference against the frozen payment
terms.
The three public integration paths should share the same semantics:
- LangGraph
wrap_tool_call - LangGraph
awrap_tool_call - Strands
after_tool_call
Describe alternatives you've considered
- Tool-specific wrappers duplicate payment middleware and can lose the selected
challenge and possible-spend context. - LLM inspection after the result returns is not a fail-closed output contract.
- Requiring a seller to echo protocol, network, scheme, challenge or offer ID,
amount, asset, payee, credential digest, and transaction in one custom bag is
not portable. Standard x402 settlement responses and MPP receipts do not echo
that complete set, and seller-authored echoes are not independent settlement
verification.
Additional context
Current source references:
- AgentCore LangGraph payment flow
- x402 settlement response shape
- x402 Payment Response header codec
- MPP receipt shape
The repository's current contribution policy asks external users to report
problems and request features rather than submit code pull requests, so this is
intentionally a feature request without an external patch.
- Lenguaje dominante
- Python
- Estrellas
- 776
- Forks
- 153
- Merge medio
- 1 d 8 h
- PR fusionados (30 d)
- 15
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de aws/bedrock-agentcore-sdk-python
-
bug high-severity
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
aws/bedrock-agentcore-sdk-python#698 ·
Los mantenedores suelen responder en 1 día
-
AgentCoreMemorySessionManager discards the two boto3 clients MemoryClient builds; boto_session and boto_client_config are not passed throughPosiblemente ocupada @avneetbansal-aws la tomó hace 9 días. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
aws/bedrock-agentcore-sdk-python#681 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug high-severity
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
aws/bedrock-agentcore-sdk-python#680 ·
Los mantenedores suelen responder en 1 día
-
[Bug] update_message fails with parameter validation error when SessionMessage.message_id is a Strands positional integer indexPosiblemente ocupada @citizen204 la tomó hace 99 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
aws/bedrock-agentcore-sdk-python#556 ·
Los mantenedores suelen responder en 1 día
-
CodeInterpreter should not require a region argumentPosiblemente ocupada @citizen204 la tomó hace 114 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
aws/bedrock-agentcore-sdk-python#511 ·
Los mantenedores suelen responder en 1 día
Todos los issues de aws/bedrock-agentcore-sdk-python
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
Vector35/community-plugins#376 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
py-econometrics/pyfixest#1883 ·
Los mantenedores suelen responder en 1 día
-
bad links in rfc5890.htmlAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
ietf-tools/rfc2html#81 ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
mysql/mysql-operator#60 ·
-
Python: Bug: split_plaintext_paragraph / split_markdown_paragraph can return a chunk larger than max_tokensPosiblemente ocupada @xThreeh la tomó hoy. Abiertopython triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
microsoft/semantic-kernel#14566 ·
Los mantenedores suelen responder en 4 días