Skip to content

Latest commit

 

History

History
841 lines (515 loc) · 34.4 KB

File metadata and controls

841 lines (515 loc) · 34.4 KB

accounts

0.16.0

Minor Changes

  • 29c91b1: Added CLI device code approval for updating published and pending access key spending limits.

    await provider.request({
      method: "wallet_updateAccessKey",
      params: [
        {
          address: accountAddress,
          accessKeyAddress,
          limits: [{ token, limit }],
        },
      ],
    });

0.15.5

Patch Changes

  • 77a68ab: Fixed the Privy React adapter to select embedded wallets and continue when an embedded wallet is available before Privy reports wallet readiness.

0.15.4

Patch Changes

  • 0a39059: Fixed MPP clients routing chain RPCs through the active chain instead of the requested chain.

0.15.3

Patch Changes

  • 7480125: Forward fee payer URLs to JSON-RPC wallets.

0.15.2

Patch Changes

  • 9d2bdc8: Skipped EIP-6963 provider announcement when crypto.randomUUID is unavailable (e.g. insecure contexts).
  • 29776b4: Added { domains } form to the wallet_connect identity.email capability for restricting email entry to allowed domains.
  • 5351e1c: Added paradigm.xyz to the list of trusted hosts.

0.15.1

Patch Changes

  • 03c1161: Added string and { address } forms to the wallet_connect identity.email capability for requiring a specific email.

0.15.0

Minor Changes

  • 2cfca91: Updated viem (>=2.54.0) and ox (~0.14.30) for the config-id-free TIP-1061 multisig format, removing genesisConfigId from the multisig relay ResolveConfig, Operation, and Status shapes.

0.14.12

Patch Changes

  • 186b1f7: Added provider MPP account resolution parameters for locally managed access keys.
  • 2e092e9: Added exact access-key selection for provider-backed mppx parameters.
  • d5c0d66: Changed Mount.auto to allow trusted hosts to use iframe mounts without IntersectionObserver v2 support.
  • 98a8138: Added identity to Provider.create, minting verified-email id tokens from a configured OIDC issuer when local adapters fulfill wallet_connect.
  • 4aa479d: Add SIWE resources to wallet_connect auth challenges, support server-provided SIWE statements in Handler.auth, and preserve extra auth verify JSON fields.

0.14.11

Patch Changes

  • 3610539: Added adapter-supplied default access-key keystores via Adapter.Instance.accessKey.keystores, replacing the removed generateAccessKey.
  • a94dcff: Bumped hono to 4.12.25 (catalog + override for transitive @modelcontextprotocol/sdk paths) to clear the remaining pnpm audit advisories: CORS middleware origin reflection (high), serve-static path traversal, and the AWS Lambda Set-Cookie/body-limit/header issues.
  • 0406c1c: Upgraded vulnerable transitive dependencies to patched versions to clear pnpm audit (vite-plus, vite, ws, tmp, form-data, protobufjs, tar, js-yaml, launch-editor, @babel/core, dompurify).
  • a65930b: Bumped the mppx dependency to ^0.7.0.
  • 9aa1ed4: Fixed eth_fillTransaction to estimate gas for the signing key's signature size instead of always assuming secp256k1.
  • 3610539: Added an accessKey option group to Provider.createaccessKey.keystores for pluggable per-key-type access-key keystores and accessKey.authorize superseding the now-deprecated top-level authorizeAccessKey.
  • 0b960e2: Restored popup treatment in Safari for wallet_connect in the postMessage adapter.
  • b588aa8: Upgraded the wata dependency to 0.2.0 and migrated the postMessage and mobileWebAuth adapters to its async wata.start() session API.

0.14.10

Patch Changes

  • fa0434f: Added wallet_updateAccessKey to update an access key's spending limits in place.

  • c5bbc8d: Added multisig approval collection to Handler.relay.

  • ab78127: Fixed raw sponsored transaction signing to restore the configured fee token when the serialized transaction omits it.

  • a993dff: Remove the accounts/react-native subpath; import asyncStorage from accounts/react-native/async-storage instead.

  • 05d5458: Removed the T5 hardfork gate so TIP-1053 witness binding always collapses access-key authorization and the auth proof into a single passkey ceremony.

  • 8203e44: Add encrypted MMKV-backed React Native storage that manages its SecureStore encryption key internally.

    Remove secureStorage from accounts/react-native/expo-secure-store; use secureMmkv from accounts/react-native/secure-mmkv instead.

  • a188f7e: Introduced postMessage adapter built on the Wata transport of the same name.

    Updated the tempoWallet adapter to use postMessage.

    Deprecated dialog adapter in favor of postMessage.

0.14.9

Patch Changes

  • e15e2a4: Added mobileWebAuth() and tempoWalletMobileWebAuth() adapters, also available from accounts/mobileWebAuth as mobileWebAuth and tempoWallet.

    Added accounts/react-native/expo-web-browser.

    Added ProviderRequest.parse().

    Renamed accounts/react-native/secure-storage to accounts/react-native/expo-secure-store.

    Removed the reactNative() adapter.

0.14.8

Patch Changes

  • d0d3cea: Added OIDC identity-token support for verified email extraction.

0.14.7

Patch Changes

  • 8a9564b: Persist CLI access keys in filesystem-backed provider storage.

  • edab403: Allow Provider.create({ authorizeAccessKey }) to return undefined to skip access-key authorization for the current wallet_connect.

  • df1615e: Persist access keys through provider storage.

  • 1478791: Add provider-owned RPC action handling for adapters that expose a viem account with getAccount.

    Adapters can now implement getAccount and optional generateAccessKey instead of duplicating transaction, signing, and access-key RPC actions.

  • ad48834: Allowed the React Native adapter to connect without requesting an access key.

  • 648df76: Make accounts/react-native adapter-only and move React Native storage adapters behind explicit subpaths.

  • 694e022: Added a React Privy adapter at accounts/react/privy, backed Privy Ethereum signing with secp256k1_sign, and stopped exporting the lower-level Core JS Privy adapter from the root package entrypoint.

  • b1a3a69: Added ability to batch key authorization + server auth into one digest.

  • 18052eb: Added opt-in identity.email request capability to wallet_connect.

0.14.6

Patch Changes

  • 89a107f: Fixed getAccounts to respect signable.

0.14.5

Patch Changes

  • a33ed22: Added a strict option to Remote.validateSearch to let trusted wallet routes defer access-key policy validation.
  • b6fb206: Added showDeposit support to wallet_authorizeAccessKey requests.

0.14.4

Patch Changes

  • 8afc239: Fix React Native auth token handling and mobile auth URL encoding.

0.14.3

Patch Changes

  • 801e18a: Simplified Privy account loading and fixed stale wallet cache handling after failed account selection.
  • f176676: Point React Native mobile authentication at the remote manager route.

0.14.2

Patch Changes

  • 022d947: Simplified Privy account loading and fixed stale wallet cache handling after failed account selection.

0.14.1

Patch Changes

  • 62705cb: Added an on filter to the wallet_connect showDeposit capability to direct if the deposit screen should be shown on login or register.

0.14.0

Minor Changes

  • feb1ab6: Breaking: Updated Tempo chain imports to use scoped chain entrypoints. Bump your Viem version to >=2.50.4.

Patch Changes

  • 7aeec48: Fixed access key authorization to reject requests that require external key material when none is provided.
  • 78778cb: Added a Privy adapter for connecting and signing with app-provided Privy embedded wallet accounts.
  • e15757f: Added a showDeposit capability to wallet_connect.

0.13.0

Minor Changes

  • 0666744: Breaking: Changed Handler.auth() to require callers to provide origin or domain, so SIWE challenge and verify flows pinned domain binding instead of deriving it from request Host headers.

  • f652ff2: Breaking: Updated wallet_deposit params to use amount and token and removed value.

    provider.request({
      method: 'wallet_deposit',
    - params: [{ value: '25' }],
    + params: [{ amount: '25', token: 'pathUSD' }],
    })

Patch Changes

  • ab516b7: Fixed WebAuthn credential storage to bind credentials to their registered user id and use atomic duplicate rejection when the configured Kv supports it.
  • 4029a37: Fixed dialog auth capability handling to forward returned auth tokens through wallet connection account results.
  • bdd6b39: Rejected unsafe app-provided external fee-payer URLs unless relay config explicitly allowed unsafe URLs.
  • c64d825: Fixed wallet_connect auth handling to allow derived or forwarded auth endpoints without dropping the SIWE signature.
  • dd5d399: Fixed access-key authorization lifecycle handling so pending authorizations stayed attached until publication was known.

0.12.2

Patch Changes

  • 22153c8: Added access-key publication status helpers and matched scoped key policies locally without crashing on malformed scope data.
  • c97987d: Documented chain-qualified relay routes and showed the MPP example server sponsoring pull-mode charge transactions.
  • 652ae1a: Added error details to wallet_sendCalls failures so viem push-mode fallbacks preserved the original provider error.
  • 91b5699: Passed MPP session options from Provider.create({ mpp }) through to mppx so clients could configure session deposits.
  • 8c4b343: Kept pending access-key authorization through fill and signing-only flows so first-use MPP charges and activation gas estimates could publish the key.
  • 20cf1d2: Preserved wallet-host RPC error codes when dialog requests failed so validation errors were no longer reported as user rejection.

0.12.1

Patch Changes

  • 2f2f85e: Removed signature from authorizeAccessKey.Parameters.
  • e91311f: Defaulted feeToken to chain settlement token in Path A. Protected resolved token from fill() null-clobber. Fixed sponsored transactions reverting with insufficient FeeAMM liquidity.

0.12.0

Minor Changes

  • 91711b3: Changed the default value of mpp on Provider.create to true. Machine Payment Protocol (mppx) support is now enabled by default -- pass mpp: false to opt out.

  • 5c46dd4: Breaking: Renamed wallet_send to wallet_transfer. The method now defaults to "read-only" mode.

    For previous behavior, pass editable: true to open the editable flow.

    provider.request({
    - method: 'wallet_send',
    - params: [{ token: '0x...' }],
    + method: 'wallet_transfer',
    + params: [{ editable: true, token: '0x...' }],
    })

Patch Changes

  • d545edf: Carried keyType through on non-signable json-rpc accounts so the viem/tempo transaction formatter can derive the correct keyType/keyData placeholder bytes during eth_fillTransaction gas estimation (notably for WebAuthn EOAs).
  • 59046a4: Made keyAuthorization.address optional in the RPC schema. RPC nodes return prepared transactions with only keyId (the access key address), so requiring address rejected valid eth_signTransaction payloads when MPP signed via an access key.
  • 5a15e7d: Relaxed the id parameter on Kv.durableObject.Namespace.get from unknown to any so Cloudflare's DurableObjectNamespace<T> is structurally assignable without an intermediate cast at the call site.
  • 6d6cc9e: Skipped the mppx globalThis.fetch polyfill on runtimes where fetch is read-only (e.g. Cloudflare Workers). Added mpp.polyfill option for explicit control; defaults to auto-detect via the property descriptor.
  • d545edf: Fixed local and turnkey adapters dropping publicKey when preparing key authorizations, which caused the wallet to sign authorizations for a freshly-generated address instead of the caller-supplied one.
  • 63c9d5c: Removed console warning from expected signing paths in dialog adapter.
  • f0757a4: Simplified loadAccounts and createAccount in turnkey adapter.
  • 9d20725: Issued a Handler.webAuthn session on successful registration (matching /login), revoked it via wallet_disconnect in the WebAuthn adapter, and surfaced a consistent base64url-encoded userId across /register and /login.
  • 5a15e7d: Defaulted Handler.auth({ trustProxy }) to true on Cloudflare Workers and appended a trustProxy / origin hint to "domain mismatch" / "uri mismatch" errors raised from wallet_connect.

0.11.0

Minor Changes

  • 0a73f2c: Renamed the wallet_send value parameter to amount.

     await provider.request({
       method: 'wallet_send',
       params: [{
         to: '0x...',
         token: '0x20c0000000000000000000000000000000000001',
    -    value: '1.5',
    +    amount: '1.5',
       }],
     })

Patch Changes

  • 43b8700: Fixed access keys selection to include chain.
  • b4a08ef: Fixed access key selection in the dialog adapter by forwarding calls.
  • b4a08ef: Added console logging in the dialog adapter's access key fallback path.
  • 0a73f2c: Added an optional memo parameter to wallet_send that the wallet attaches to TIP-20 transfers and rejects with InvalidParamsError for non-TIP-20 tokens.
  • 0a73f2c: Widened the wallet_send token parameter to accept a curated tokenlist symbol (case-insensitive, e.g. "pathUsd") in addition to a contract address.

0.10.7

Patch Changes

  • 7cb2162: Exposed the Adapter namespace from the package root so consumers can author custom adapters with Adapter.define.
  • 195d6e8: Fixed scoped access key selection to only match keys whose scopes covered the current transaction calls.
  • 70814cd: Made turnkey createAccount optional and default registration requests to loadAccounts.

0.10.6

Patch Changes

  • e12ae75: Added auth option to the webAuthn adapter, mirroring the Provider auth capability shape (string | { url, ... }); the existing authUrl option is preserved as a deprecated alias.

    - webAuthn({ authUrl: '/webauthn' })
    + webAuthn({ auth: '/webauthn' })

0.10.5

Patch Changes

  • b65893e: Renamed the dangerous_secp256k1 adapter to secp256k1. The old name is preserved as a deprecated alias so existing imports keep working.

    - import { dangerous_secp256k1 } from 'accounts'
    + import { secp256k1 } from 'accounts'

0.10.4

Patch Changes

  • f36c350: Widened getSession to accept Node.js http.IncomingMessage in addition to Fetch API Request.
  • ef44a68: Fixed Handler.relay() to return an actionable error when eth_signRawTransaction is called without a fee payer configured, instead of forwarding to the RPC node which returns an opaque "Method not found".

0.10.3

Patch Changes

  • a5ca0be: Fixed Handler.relay forwarding keyAuthorization to eth_fillTransaction in the internal envelope shape instead of the RPC shape the chain expects.
  • dccc343: Added a Turnkey adapter for connecting and signing with app-provided Turnkey wallet accounts.

0.10.2

Patch Changes

  • 4095a24: Fixed support for external feePayer URLs on Handler.relay.
  • 4095a24: Added feeToken to Handler.relay's feePayer option so the sponsor can pin the fee token used on sponsored fills.

0.10.1

Patch Changes

  • f1cddef: Bumped hono to ^4.12.18.

0.10.0

Minor Changes

  • 1334969: Breaking: Made the errors capability opt-in on Handler.relay's eth_fillTransaction so reverts now throw JSON-RPC errors by default unless capabilities.errors: true is set.

  • e995c28: Breaking: Renamed Handler.webAuthn option challengeTtl to ttl.challenge.

      Handler.webAuthn({
        kv,
        origin: 'https://example.com',
        rpId: 'example.com',
    -   challengeTtl: 600,
    +   ttl: { challenge: 600 },
      })
  • e995c28: Breaking: Changed Handler.webAuthn's onAuthenticate hook rejection status from 400 to 401 when the hook throws.

      // POST /login response when `onAuthenticate` throws `new Error('blocked')`:
    - HTTP/1.1 400 Bad Request
    + HTTP/1.1 401 Unauthorized
      Content-Type: application/json
    
      {"error":"blocked"}
  • e995c28: Breaking: Made Handler.webAuthn issue a session cookie and persist a session entry under session:<token> in kv on successful /login by default -- opt out via session: false or cookie: false.

      // Default behavior -- `/login` now sets a cookie and writes to kv.
      Handler.webAuthn({ kv, origin, rpId })
    
      // Pre-PR behavior (no cookie, no kv session writes, no `/logout`):
    + Handler.webAuthn({ kv, origin, rpId, session: false })
    
      // Or just disable cookie issuance and return the token in the body:
    + Handler.webAuthn({ kv, origin, rpId, cookie: false })

Patch Changes

  • 340509d: Added an auth capability to wallet_connect.
  • 1a2cdfa: Required byte-equality between the submitted SIWE message and the stored challenge in the auth server handler's verify endpoint.
  • e995c28: Added session option to Handler.auth and allowed onAuthenticate to return a Response whose body and status are merged onto the verify response.
  • 1334969: Changed the default host on the CLI Provider.create from https://wallet.tempo.xyz/cli-auth to https://wallet.tempo.xyz/api/auth/cli.
  • 1334969: Fixed the dialog adapter to fall through to the dialog (instead of removing the access key) when a sign action reverts with InsufficientBalance.
  • 38a840a: Added a personalSign capability to wallet_connect.
  • 1334969: Widened mpp on Provider.create to accept an options object with a mode: 'push' | 'pull' field and changed the default mode to 'push' (the CLI Provider still defaults to 'pull').
  • 1334969: Added relay and transports options to Provider.create for per-chain RPC routing.
  • 1334969: Surfaced the underlying upstream JSON-RPC error from Handler.relay instead of viem's RpcRequestError wrapper, and forwarded keyAuthorization through eth_fillTransaction normalization.
  • e995c28: Added cookie, cookieName, session, and ttl.session options, a getSession() method, and a /logout route to Handler.webAuthn.

0.9.1

Patch Changes

  • 654f607: Updated trusted hosts

0.9.0

Minor Changes

  • 063680a: Generalized remote theme handling: switched to data-theme-radius, data-theme-accent, and --theme-accent hooks, included scheme in live theme messages, and let the consuming app own preset-to-UI mapping. The font URL param and --font-body injection were removed — consumers now own font loading.

    - [data-accent='blue'] { … }
    + [data-theme-accent='blue'] { … }
    
    - [data-radius='medium'] { … }
    + [data-theme-radius='medium'] { … }
    
    - :root { background: var(--accent-base); }
    + :root { background: var(--theme-accent); }
    
    - // ?accent=…&radius=…&font=…&scheme=…
    + // ?accent=…&radius=…&scheme=…

Patch Changes

  • ce5677d: Added relay virtual-address resolution metadata to eth_fillTransaction capabilities.

0.8.10

Patch Changes

  • fc3d61c: Optimized Handler.relay's eth_fillTransaction path with a speculative sponsored fill (skipping fee-token resolution when the sponsor accepts), KV-cached Actions.fee.getUserToken lookups, and a capabilities.balanceDiffs: false opt-out that skips the post-fill tempo_simulateV1 round trip.

0.8.9

Patch Changes

  • 56d9b26: Added keyType, keyId, and keyData to the transactionRequest Zod schema so they survive decoding when callers (e.g. wagmi) include them on eth_fillTransaction / eth_sendTransaction / eth_signTransaction payloads.

0.8.8

Patch Changes

  • 451f4f5: Added the transaction's call targets as fallback fee-token candidates in Handler.relay so users transferring a token they hold can pay gas in that token without an autoSwap.
  • 1d75917: Fixed Handler.relay to treat the pre-emptive fee-token autoSwap as best-effort, falling back to the resolved feeToken instead of failing when the swap itself can't be filled.
  • 451f4f5: Added chainId to the wallet_send return value alongside receipt so callers can identify which chain the receipt belongs to.

0.8.7

Patch Changes

  • 763ccfc: Treated undefined as "no value" in Storage.combine reads so adapters that return undefined for missing keys (Map-backed, custom caches) fell through to the next adapter instead of short-circuiting.

0.8.6

Patch Changes

  • a15e214: Renamed inputtoken and outputpairToken in POST /exchange/quote
  • 81f8183: Included token logo URIs (logoUri) in the GET /exchange/tokens response.
  • 9a19429: Added receipts to the wallet_deposit RPC response.
  • 176c1d3: Added wallet_depositZone and wallet_withdrawZone RPC methods for moving funds between the parent Tempo chain and a private zone.

0.8.5

Patch Changes

  • a9c2b0d: Added Handler.exchange() for the Tempo Stablecoin DEX, exposing GET /exchange/tokens and POST /exchange/quote.
  • 5c5988f: Exported ExecutionError.
  • 5c5988f: Fixed relay default pass-through to return upstream RPC errors as structured JSON-RPC errors instead of HTTP 500.

0.8.4

Patch Changes

  • b06061e: Changed wallet_swap amount parameter from raw hex to a human-readable decimal string (e.g. "1.5"), matching wallet_send's value.

0.8.3

Patch Changes

  • f3ac13b: Bumped mppx to 0.6.5.
  • 3c77fe7: Passed the resolved CLI auth chain ID to CliAuth.Policy.validate.
  • ba69e15: Allowed CLI auth approvals to return a different expiry or spending limits when the submitted signature covers those values.
  • 37cf2a9: Replaced the .local shortcut in TrustedHosts.match with an opt-in source parameter that treats hostnames sharing the same registrable domain ("eTLD+1") as source as trusted.
  • 08c0e12: Added wallet_swap RPC action.

0.8.2

Patch Changes

  • 9ffdd28: Modified wallet_send to return { receipt } instead of { transactionHash }
  • 9ffdd28: Resolved relative feePayer URLs in Client.fromChainId against window.location.origin in the browser.
  • 3ec1b23: Added wallet_send RPC action.
  • 7c62e76: Fixed Remote.ready() reverting persisted chain by removing stale chainId URL param switch.
  • 8b6265a: Logged access key sign errors in the dialog adapter's withAccessKey catch block via console.warn before removing the stale key.
  • 9ffdd28: Merged original eth_fillTransaction request fields (calls, chainId, validBefore, key data, feePayer) into the chain's filled tx so sponsorship envelope serialization no longer throws CallsEmptyError.
  • 9ffdd28: Forwarded upstream relay capabilities.autoSwap and InsufficientBalance errors through the wallet relay so external fee-payer fills surface autoSwap metadata and trigger the local autoSwap fallback.
  • 447707a: Made wallet_revokeAccessKey on the local adapter send a revokeKey transaction to the AccountKeychain precompile via Actions.accessKey.revoke before removing the key from the local store.
  • 77b094b: Fixed wallet_revokeAccessKey in the local adapter crashing with KeyNotFound when the access key was only authorized locally and never registered on-chain via a transaction.
  • 9ffdd28: Added feePayer parameter to wallet_send for per-call fee payer override.
  • 9ffdd28: Exported Rpc.wallet_send.parameters zod schema for the wallet_send parameters object.

0.8.1

Patch Changes

  • c4b669b: Fixed relay handler gas bump not applying when feePayer is present. The condition checked result.tx.feePayer (node response) which is not set; now checks request.feePayer (the input).

0.8.0

Minor Changes

  • d058f26: Updated default dialog host from https://wallet.tempo.xyz/embed to https://wallet-next.tempo.xyz.
  • d058f26: Added runtime theme sync for iframe dialog. Theme changes (accent, radius, font) now propagate to the cached iframe without reloading via the syncTheme method and a new theme messenger topic.

Patch Changes

  • d058f26: Changed chainId type in wallet_authorizeAccessKey parameters and Adapter.authorizeAccessKey.Parameters from number to bigint to match ox/viem's KeyAuthorization.chainId.
  • d058f26: Added label-based deduplication in wallet_connect to sign in with an existing credential when a matching account label is found during registration.
  • d058f26: Fixed feePayer: false to correctly propagate through resolveFeePayer and prepareTransactionRequest, allowing per-request opt-out of fee payers.
  • d058f26: Added support for app-provided fee payer URLs in Handler.relay. The relay now proxies eth_fillTransaction through an external fee payer service when a URL is provided, and passes through sponsor metadata from the upstream response.
  • d058f26: Added a 20k gas buffer for sponsored transactions in the relay to prevent out-of-gas reverts from signature size differences.
  • d058f26: Changed fee token resolution in the relay to lazily resolve swap source tokens on InsufficientBalance instead of eagerly resolving upfront.
  • d058f26: Restructured relay fill logic into three paths (guaranteed, conditional, no sponsorship) with parallelized simulation, signing, and autoSwap metadata resolution.
  • d058f26: Added name and url fields to relay sponsor metadata in eth_fillTransaction responses.
  • d058f26: Added feePayerSignature, period on key authorization limits, and displayName on wallet_deposit to RPC schemas. Exported wallet_authorizeAccessKey.returns.
  • d058f26: Added maxAccounts option to Provider.create and Store.create for LRU eviction of persisted accounts.
  • d058f26: Added .local TLD to trusted hosts for local development.
  • d058f26: Passed registration name through the webAuthn challenge store so it is available in the onRegister callback.

0.7.2

Patch Changes

  • 6be8e14: Added chainId parameter to wallet_authorizeAccessKey to allow scoping key authorizations to a specific chain instead of defaulting to the active chain.
  • b8863bb: Deprecated accounts/wagmi. Consumers should use the following entrypoints instead: wagmi/tempo, @wagmi/core/tempo, or wagmi/connectors (when they only need tempoWallet).
    • wagmi@0.0.0

0.7.1

Patch Changes

  • 8792ea4: Added scopes and limits.period to authorizeAccessKey.
  • 8792ea4: Added support for Tempo Devnet.
  • fbd691f: Updated dependencies.

0.7.0

Minor Changes

  • bcd4ec3: Breaking: Added features option to Handler.relay to control feature enablement.

    • features: 'all' enables fee token resolution, auto-swap, and simulation (balance diffs + fee breakdown), at the cost of network latency.
    • If features is not present, only enables fee payer sponsorship by default.
  • 97ea5b4: Removed Handler.feePayer. Updated Handler.relay to be backwards compatible with Handler.feePayer.

Patch Changes

  • d6a4620: Added error and requireFunds capabilities to eth_fillTransaction relay responses.
  • 3064657: Add a shared CliAuth.from() helper to reuse CLI auth defaults and cached clients across create, pending, poll, and authorize flows, and reject device-code requests for unconfigured chains.

0.6.7

Patch Changes

  • 572cde0: Bumped trusted hosts

0.6.6

Patch Changes

  • 85d462d: Added JSON-RPC batch request support to Handler.relay. The handler now accepts arrays of JSON-RPC request objects and returns an array of responses, matching the JSON-RPC 2.0 batch spec.

0.6.5

Patch Changes

  • f3d04b5: Updated RPC types.

0.6.4

Patch Changes

  • a5f538a: Added calls to capabilities.autoSwap containing the injected swap calls (approve + buy).

0.6.3

Patch Changes

  • e12d57c: Added autoSwap: false to disable automatic AMM resolution on Handler.relay.
  • e12d57c: Renamed feeSwap to autoSwap on Handler.relay options and response metadata.
  • 60e0f5f: Renamed meta to capabilities in eth_fillTransaction response.

0.6.2

Patch Changes

  • 3f2ce93: Fixed external access key authorisation in dialog adapter.
  • 3f2ce93: Added validate callback to Handler.feePayer and Handler.relay for conditional sponsorship.
  • 3f2ce93: Added Handler.relay with fee token resolution, simulation, AMM auto-swap, and sponsoring.

0.6.1

Patch Changes

  • 1aa18fe: Added feePayer to wallet_sendCalls capabilities and wallet_getCapabilities response.
  • 1aa18fe: Support feePayer: false to opt out of fee payers on a per-transaction basis when a provider-level fee payer is configured.

0.6.0

Minor Changes

  • 36db0d9: Breaking: Renamed feePayerUrl to feePayer.

0.5.9

Patch Changes

  • 901cfee: Fixed iframe dialog getting stuck on "Check prompt" when the store is swapped during React re-renders.

0.5.8

Patch Changes

  • b4c87a3: Fixed iframe dialog getting stuck on "Check prompt" when the store is swapped during React re-renders.
  • 567bf0a: Added accounts/react-native entrypoint with React Native adapter and storage implementation.

0.5.7

Patch Changes

  • cc334ff: Injected active chainId into transaction requests when the consumer does not provide one.

0.5.6

Patch Changes

  • 6eff229: Added privateKey support to dangerous_secp256k1() so wagmi configs could pin distinct signers per connector.

0.5.5

Patch Changes

  • b03c228: Bumped deps

0.5.4

Patch Changes

  • 4936c12: Fixed Dialog.iframe() injecting duplicate iframes by caching the instance as a singleton keyed by host.

0.5.3

Patch Changes

  • 7134f07: Updated internal dependencies.

0.5.2

Patch Changes

  • 1450dd5: Fixed the wagmi WebAuthn connector to forward authUrl so server-backed WebAuthn flows correctly called /auth/* instead of falling back to local-only mode.

0.5.1

Patch Changes

  • 6c80aba: Fixed dialog backdrop appearing black on macOS Light mode.

0.5.0

Minor Changes

  • 5b4ce03: Public release.

0.4.25

Patch Changes

  • 0228a50: Fixed Dialog.isInsecureContext() to return true for http: protocol — http://localhost is a secure context but WebAuthn still requires HTTPS, so the dialog now correctly defaults to popup.
  • 0228a50: Fixed feePayerUrl to be used by default when configured — previously required feePayer: true on each transaction, now auto-applies unless explicitly opted out with feePayer: false.

0.4.24

Patch Changes

  • 825ece0: Added dangerous_secp256k1 wagmi connector.

0.4.23

Patch Changes

  • 88ff46d: Added tempo-docs-git-jxom-accounts-sdk-docs-tempoxyz.vercel.app to trusted hosts.

0.4.22

Patch Changes

  • 0289ff0: Renamed Handler.webauthn to Handler.webAuthn.

0.4.21

Patch Changes

  • e892698: Renamed Ceremony to WebAuthnCeremony.
  • 59d5d90: Renamed Handler.webauthn to Handler.webAuthn.

0.4.20

Patch Changes

  • f7929e2: Added onError option to Remote.respond. Return true from the callback to suppress the error response to the parent, allowing the dialog to show a recovery UI instead of rejecting.

0.4.19

Patch Changes

  • 54a9395: Added wallet_deposit RPC method for requesting funds. On testnet, shows a faucet UI. On mainnet, shows a bridge deposit flow. Fixed Remote.respond to correctly handle void return types.

0.4.18

Patch Changes

  • 0a3396c: Handle eth_fillTransaction in Provider to inject pending keyAuthorization for access key accounts.

0.4.17

Patch Changes

  • ba93170: Enabled MPP on provider with pull mode by default.

0.4.16

Patch Changes

  • 46cd976: Made CLI use wallet.tempo.xyz as server and keys.toml
  • 00de151: Added provider transport to getClient() so viem actions route through the provider adapter. Accepted standard to/data fields in eth_sendTransaction and converted them to Tempo calls format.

0.4.15

Patch Changes

  • 715d830: Moved trusted hosts list to trusted-hosts.json at the project root.

0.4.14

Patch Changes

  • b7151af: Added chainId in wallet_connect to set the active chain before the dialog opens.

0.4.13

Patch Changes

  • 0df27dd: Added *.localhost and benedict.dev to trusted hosts.

0.4.12

Patch Changes

  • 867b9ae: Fixed Safari using popup instead of iframe for non-WebAuthn requests (e.g. sendTransaction).
  • dfb552b: Added *.tempo.xyz to trusted hosts.

0.4.11

Patch Changes

  • 7341ffc: Added TrustedHosts.match() with wildcard pattern support (e.g. *.porto.workers.dev).

0.4.10

Patch Changes

  • 3854ee4: Added TrustedHosts module with per-dialog-host trusted origin mappings. Accepted readonly string[] for trustedHosts in Remote.create.

0.4.9

Patch Changes

  • e006f99: Fixed duplicate EIP-6963 provider announcements for the same wallet rdns.

0.4.8

Patch Changes

  • 5795462: Broke circular dependency between Schema and rpc modules that caused runtime errors when bundled with esbuild.
  • a622e07: Defaulted to popup dialog on insecure (HTTP) contexts where iframes cannot use WebAuthn.
  • a622e07: Stripped www. prefix when checking trusted hosts for dialog origin validation.

0.4.7

Patch Changes

  • 1b9e9a6: Added Remote.noop() for SSR environments and handled Bitwarden blocking WebAuthn in cross-origin iframes.
  • 457f7a7: Added strict parameter validation for wallet_authorizeAccessKey and wallet_connect in dialog adapters. limits is now required when authorizing access keys through the dialog. Added Remote.validateSearch to validate search params with formatted error messages and automatic rejection via remote.rejectAll.

0.4.6

Patch Changes

  • e0724cd: Added wallet_authorizeAccessKey support to the CLI adapter, allowing access keys to be authorized independently from wallet_connect.

0.4.5

Patch Changes

  • c86cd60: Added fee payer support for the dialog adapter. When feePayerUrl is configured, transactions sent through the dialog embed now use withFeePayer transports for preparation and sending.
  • 1525992: Added warning when dialog adapter is initialized on a non-secure (HTTP) origin.

0.4.4

Patch Changes

  • c7c1682: Fixed wallet_getCallsStatus returning status 500 for pending transactions. Now returns status 100 when eth_getTransactionReceipt is null, allowing waitForCallsStatus to continue polling until inclusion.
  • bd37754: Fixed dialog wagmi connector dropping Provider.create options like authorizeAccessKey and feePayerUrl. Now forwards all remaining options to setup().

0.4.3

Patch Changes

  • 75e4cf2: Fixed iframe dialog being silently removed by React 19 hydration in Next.js App Router. A MutationObserver now detects removal and re-appends the dialog with a fresh messenger bridge.

0.4.2

Patch Changes

  • bf06710: Added CLI adapter & provider via an accounts/cli entrypoint.
  • 4a52018: Added accounts/react entrypoint with Remote.useState and Remote.useEnsureVisibility hooks. Exposed trustedHosts on the Remote type.

0.4.1

Patch Changes

  • b2a347c: Updated zile.

0.4.0

Minor Changes

  • f257ccc: Initial release.