Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,10 +197,10 @@ Policy engines apply Cedar-based pre/post-call policies to agent invocations —
Pay-per-call agent transactions via the [x402 protocol](https://www.x402.org/). When a tool call returns
`402 Payment Required`, the payments system signs and submits payment then retries automatically.

| Command | Description |
| ----------------------- | ---------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a payment connector with provider credentials (CoinbaseCDP, StripePrivy) |
| Command | Description |
| ----------------------- | ------------------------------------------------------------------------- |
| `add payment-manager` | Add a payment manager (orchestrates payment sessions for the agent) |
| `add payment-connector` | Add a Quick Create or manual payment connector (CoinbaseCDP, StripePrivy) |

> See [Payments](docs/payments.md) for the full setup including instrument creation and tool allowlists.

Expand Down
19 changes: 10 additions & 9 deletions docs/PERMISSIONS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -426,15 +426,16 @@ Required only when the project defines payment managers and connectors (the `pay
CLI calls the Payment control-plane and data-plane APIs directly with the developer's credentials; both are signed under
the `bedrock-agentcore` service.

| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |
| Action | CLI Commands | Purpose |
| --------------------------------------------------- | ------------------ | -------------------------------------------------------------------- |
| `bedrock-agentcore:GetPaymentCredentialProvider` | `deploy` | Check if a payment credential provider already exists |
| `bedrock-agentcore:CreatePaymentCredentialProvider` | `deploy` | Create a payment credential provider from connector secrets |
| `bedrock-agentcore:UpdatePaymentCredentialProvider` | `deploy` | Update a payment credential provider with new secret values |
| `bedrock-agentcore:DeletePaymentCredentialProvider` | `deploy` | Remove a payment credential provider when a connector is removed |
| `bedrock-agentcore:GetPaymentManager` | `status` | Look up payment manager status |
| `bedrock-agentcore:GetPaymentConnector` | `deploy`, `status` | Retrieve connector status and a pending authorization URL |
| `bedrock-agentcore:ListPaymentSessions` | `invoke` | Find an existing active payment session before creating a new one |
| `bedrock-agentcore:CreatePaymentSession` | `invoke` | Create a payment session with a default budget for `invoke` auto-pay |

Creating or updating a payment credential provider also writes the connector secrets into a service-managed Secrets
Manager secret (named `bedrock-agentcore-identity!default/payment/*`). Unlike API key and OAuth2 providers, the Payment
Expand Down
33 changes: 20 additions & 13 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -521,6 +521,12 @@ agentcore add payment-manager \
Add a payment connector to an existing payment manager. See [Payments](payments.md) for credential details.

```bash
# Quick Create (recommended)
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

# CoinbaseCDP provider
agentcore add payment-connector \
--manager MyManager \
Expand All@@ -541,19 +547,20 @@ agentcore add payment-connector \
--authorization-id your-auth-id
```

| Flag | Description |
| ----------------------------------- | ------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provider <provider>` | `CoinbaseCDP` (default) or `StripePrivy` |
| `--api-key-id <id>` | Coinbase CDP API Key ID |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret |
| `--app-id <id>` | Privy App ID (StripePrivy) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy) |
| `--json` | JSON output |
| Flag | Description |
| ----------------------------------- | ------------------------------------------------------ |
| `--manager <name>` | Parent payment manager (required) |
| `--name <name>` | Connector name (required) |
| `--provision-mode <mode>` | `QUICK_CREATE` or `MANUAL` (default) |
| `--provider <provider>` | `CoinbaseCDP` or `StripePrivy` (manual mode only) |
| `--api-key-id <id>` | Coinbase CDP API Key ID (manual mode) |
| `--api-key-secret <secret>` | Coinbase CDP API Key Secret (manual mode) |
| `--wallet-secret <secret>` | Coinbase CDP Wallet Secret (manual mode) |
| `--app-id <id>` | Privy App ID (StripePrivy manual mode) |
| `--app-secret <secret>` | Privy App Secret (StripePrivy manual mode) |
| `--authorization-private-key <key>` | ECDSA P-256 private key (StripePrivy manual mode) |
| `--authorization-id <id>` | Authorization key identifier (StripePrivy manual mode) |
| `--json` | JSON output |

### add credential

Expand Down
22 changes: 14 additions & 8 deletions docs/configuration.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -526,6 +526,11 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.
{
"name": "MyCDPConnector",
"provider": "CoinbaseCDP",
"provisionMode": "QUICK_CREATE"
},
{
"name": "MyManualConnector",
"provider": "CoinbaseCDP",
"credentialName": "my-cdp-creds"
}
]
Expand DownExpand Up@@ -572,17 +577,18 @@ wallet credentials. See [Payments](payments.md) for the full usage guide.

### Payment Connector

| Field | Required | Description |
| ---------------- | -------- | -------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | No | `"CoinbaseCDP"` (default) or `"StripePrivy"` |
| `credentialName` | Yes | Name of the credential (maps to `.env.local` vars) |
| Field | Required | Description |
| ---------------- | -------- | ----------------------------------------------------------------- |
| `name` | Yes | Connector name (alphanumeric + underscore, max 48) |
| `provider` | Yes | `"CoinbaseCDP"` for Quick Create; either provider for manual mode |
| `provisionMode` | Cond. | `"QUICK_CREATE"` for Quick Create; omit or use `"MANUAL"` |
| `credentialName` | Cond. | Required for manual mode; forbidden for Quick Create |

### Payment Credential Provider

Payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider` and
`OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. You do not need to add it to the `credentials` array manually.
Manual payment connectors use a `PaymentCredentialProvider` credential type, distinct from `ApiKeyCredentialProvider`
and `OAuthCredentialProvider`. The credential is automatically created during `agentcore deploy` from values in
`.env.local`. Quick Create provisions its provider through the service and does not add a local credential entry.

---

Expand Down
38 changes: 28 additions & 10 deletions docs/payments.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -18,16 +18,13 @@ cd MyProject
# 2. Add a payment manager
agentcore add payment-manager --name MyManager

# 3. Add a payment connector with CoinbaseCDP credentials
# 3. Add a Coinbase connector with Quick Create
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provider CoinbaseCDP \
--api-key-id your-api-key-id \
--api-key-secret your-api-key-secret \
--wallet-secret your-wallet-secret
--provision-mode QUICK_CREATE

# 4. Deploy (creates payment infrastructure on AWS)
# 4. Deploy, then open the authorization URL printed by the CLI
agentcore deploy -y

# 5. Create + fund an instrument out-of-band (SDK), then invoke with auto-session
Expand DownExpand Up@@ -126,8 +123,28 @@ For details on IAM role separation (ManagementRole vs ProcessPaymentRole), see
A payment connector links a credential provider (wallet credentials) to a payment manager. Each manager needs at least
one connector before it can process payments.

### Quick Create with Coinbase (Recommended)

Quick Create provisions the Coinbase credential provider through AWS after deployment. It does not collect credentials,
add a local credential entry, or write payment variables to `.env.local`.

```bash
agentcore add payment-connector \
--manager MyManager \
--name MyCDPConnector \
--provision-mode QUICK_CREATE

agentcore deploy -y
```

Deploy prints the live authorization URL. Open it to complete consent. The deployment succeeds while the connector is
`PENDING_AUTHENTICATION`; use `agentcore status --type payment` to retrieve the current status and URL. Once consent
completes, status becomes `READY` and the generated credential provider ARN appears in status output.

### CoinbaseCDP Provider

Manual mode remains available when you already manage Coinbase CDP credentials.

```bash
agentcore add payment-connector \
--manager MyManager \
Expand DownExpand Up@@ -174,8 +191,8 @@ agentcore add payment-connector \

### Credential Storage

Connector credentials are stored in `agentcore/.env.local` and never committed to source control. The env var naming
convention is:
Manual connector credentials are stored in `agentcore/.env.local` and never committed to source control. Quick Create
does not use local payment credentials. The manual env var naming convention is:

**CoinbaseCDP** (3 variables):

Expand DownExpand Up@@ -462,11 +479,12 @@ agentcore remove payment-manager --name MyManager -y
```

Removing a payment manager cascades: it deletes all associated connectors and credential providers from the local
configuration.
configuration. The CLI never imperatively deletes a provider generated by Quick Create.

## Validation

`agentcore validate` checks payment configuration for common issues:
`agentcore validate` checks payment configuration for common issues. Credential and `.env.local` checks apply only to
manual connectors:

- Credential cross-references: verifies each connector's `credentialName` maps to a valid credential entry
- `.env.local` existence: confirms the secrets file exists when payment connectors are configured
Expand Down
1 change: 1 addition & 0 deletions docs/policies/iam-policy-user.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -102,6 +102,7 @@
"bedrock-agentcore:UpdatePaymentCredentialProvider",
"bedrock-agentcore:DeletePaymentCredentialProvider",
"bedrock-agentcore:GetPaymentManager",
"bedrock-agentcore:GetPaymentConnector",
"bedrock-agentcore:ListPaymentSessions",
"bedrock-agentcore:CreatePaymentSession"
],
Expand Down
119 changes: 119 additions & 0 deletions integ-tests/add-remove-payment.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -317,6 +317,125 @@ describe('integration: add and remove payment managers and connectors', () => {
});
});

describe('Quick Create connector lifecycle', () => {
const managerName = `IntegQuickMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegQuick${Date.now().toString().slice(-6)}`;
let envBefore = '';

beforeAll(async () => {
await runCLI(['add', 'payment-manager', '--name', managerName], project.projectPath);
envBefore = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
});

it('adds Quick Create without provider or credential flags', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
connectorName,
'--provision-mode',
'QUICK_CREATE',
'--json',
],
project.projectPath
);

expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
expect(JSON.parse(result.stdout)).toEqual(
expect.objectContaining({
success: true,
managerName,
connectorName,
})
);

const config = await readProjectConfig(project.projectPath);
const manager = config.payments?.find((p: Record<string, unknown>) => p.name === managerName);
expect(manager?.connectors).toEqual([
{
name: connectorName,
provider: 'CoinbaseCDP',
provisionMode: 'QUICK_CREATE',
},
]);
expect(
config.credentials?.some((c: Record<string, unknown>) => c.authorizerType === 'PaymentCredentialProvider')
).toBe(false);
});

it('does not write payment secrets to .env.local', async () => {
const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

it('rejects credential flags with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Secret`,
'--provision-mode',
'QUICK_CREATE',
'--api-key-id',
'must-not-be-used',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('Credential options cannot be used with QUICK_CREATE');
});

it('rejects StripePrivy with Quick Create', async () => {
const result = await runCLI(
[
'add',
'payment-connector',
'--manager',
managerName,
'--name',
`${connectorName}Stripe`,
'--provision-mode',
'QUICK_CREATE',
'--provider',
'StripePrivy',
'--json',
],
project.projectPath
);

expect(result.exitCode).toBe(1);
expect(JSON.parse(result.stdout).error).toContain('QUICK_CREATE only supports the CoinbaseCDP provider');
});

it('validates a Quick Create connector without local credentials', async () => {
const result = await runCLI(['validate'], project.projectPath);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);
});

it('removes Quick Create without credential cleanup', async () => {
const result = await runCLI(
['remove', 'payment-connector', '--manager', managerName, '--name', connectorName, '--yes', '--json'],
project.projectPath
);
expect(result.exitCode, `stdout: ${result.stdout}, stderr: ${result.stderr}`).toBe(0);

const envAfter = await readFile(join(project.projectPath, 'agentcore', '.env.local'), 'utf-8').catch(() => '');
expect(envAfter).toBe(envBefore);
});

afterAll(async () => {
await runCLI(['remove', 'payment-manager', '--name', managerName, '--yes'], project.projectPath);
});
});

describe('StripePrivy connector lifecycle', () => {
const managerName = `IntegSpMgr${Date.now().toString().slice(-6)}`;
const connectorName = `IntegSpConn${Date.now().toString().slice(-6)}`;
Expand Down
Loading
Loading