Repository navigation
Remove the unused identity-token gate - #152
Merged
Merged
Conversation
The token-based identity path is retired: the gate option and its offline verifier, the framework adapter gates, the agent-card extension, and the discovery and agent-memory advertising for it are removed, along with their tests. Takes @agent-score/sdk ^2.9.0. Minor bump: no merchant uses it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Removes the unused identity-token path from the merchant SDK.
Checkout: the gate option for it, its offline verifier and key cache, the per-issuer policy override that applied only to it, and its deny bodies. A gate is back to wallet and operator-token identity only, with its own compliance fields sent as before.llms.txt,skill.md,mpp.jsonand OpenAPI security schemes.hasIdentityHeader: no longer counts that header.@agent-score/sdk^2.9.0, which drops the same input.Version 3.1.0: a minor, because no merchant uses it. The content-type passthrough on deny responses stays, since a merchant's own
onDeniedcan still set one.Worked with Varun, who asked for the feature to be removed everywhere.
Type of change
Public API
Removes the gate option and its exported verifier, signing, key-cache and type surface, the adapter gates and their accessors, the agent-card extension builder and URI, and the token flag on the discovery builders (
agentscoreSecuritySchemesnow takes no options).Test plan
lint, typecheck, knip, test (1636 passed, 4 skipped) and build, all green locally. A replacement test pins that only an operator token or a wallet address counts as an identity.
Checklist