p2pme-encrypted-payment-proof
v1.6.0
Published
Headless client SDK for P2P payment proofs. Framework-agnostic API client + sign-in helper used by the user, merchant, and ops UIs. Proofs are stored raw and gated by role-authorized APIs.
Readme
p2pme-encrypted-payment-proof
Headless client SDK for P2P payment proofs. No UI — pure, framework-agnostic TypeScript: an API client plus a sign-in helper. The user-app, merchant-app, and ops-dashboard install this and wire the calls into their own screens, so all three talk to the proof server identically. Proofs are stored raw on the server and gated by role-authorized APIs.
The package keeps the
encrypted-payment-proofname for continuity; the current design is raw storage + role-authorized APIs, not client-side encryption. See ../../docs/AUTH.md.
What it does
createSessionAuthorization({ baseUrl, address, chainId, signMessage, storage? })— onepersonal_sign→ a short-lived bearer token, reused for the whole session. Returns theauthorization()you hand tocreateProofClient, plus a synchronoushasFreshSession()probe. Passstorage(e.g.sessionStorage) to survive reloads; concurrent calls share one in-flight mint (one signature for a burst of requests).createProofClient({ baseUrl, authorization })— request / list / upload / download proofs, pluscountPendingProofRequests({ address, circleIds })(unauthenticated badge count, no signature). Files cross the wire as base64; the note as 0x-hex.uploadProofFile(client, request, file)/downloadProofFile(client, file)/ALLOWED_PROOF_MIME— shared raw upload/download flow (strips EXIF before upload, returns a typedBlobon download) so all three apps behave identically.stripExif(bytes)/flattenImage(file, opts)— client-side privacy + size helpers to run before upload (flattenImagedownscales a multi-MB phone photo to ~150–400 KB and drops EXIF; guard withcanFlattenImage()).
Auth
createSessionAuthorization(...) signs a single compact message
(payment-proof.p2p.me:sign-in:<address>:<chainId>:<timestamp>) via personal_sign,
exchanges it at POST /auth/session for a bearer token, and caches it (re-signing only
near expiry). Claim your on-chain identity in address (the smart-account address
in the user/merchant apps; the EOA in ops); the server verifies EOA, ERC-1271, and
ERC-6492 signatures. See ../../docs/AUTH.md and
../../docs/VERIFY.md.
Fast, clean uploads
Up to 5 files hang off one order (delete one to free a slot). Strip EXIF / flatten
client-side, then upload the raw bytes; uploads have no ordering dependency, so run them
in parallel with Promise.all. proofClient.deleteProof(requestId, fileId) frees a
slot when at the cap.
