# Vectors

> The seller door's vectors: the requests, the answers they must produce, and the ATR bytes they store.

Source: https://connectors.integraledger.com/reference/vectors

<!-- Generated by scripts/docs.mjs from contract/vectors/. Edit the source, then run: node scripts/docs.mjs -->

# Vectors

Each file in `contract/vectors/` is one exchange with the seller door, with every value fixed: the tenant and its credential, the declared resources, the storage base, the clock and the ATR identifiers minted in order. Any implementation of the door, and any test double a connector uses, must give each step's answer. The package exports them as `VECTORS`. See [the vectors guide](https://connectors.integraledger.com/guides/vectors) for the file format and how to replay them.

| Vector        | Name                                                     | Steps | Pairing                     |
| ------------- | -------------------------------------------------------- | ----- | --------------------------- |
| [CV1](#cv1)   | issue                                                    | 1     | `x402/exact/eip155/eip3009` |
| [CV2](#cv2)   | repeat                                                   | 2     | `x402/exact/eip155/eip3009` |
| [CV3](#cv3)   | reused id                                                | 2     | `x402/exact/eip155/eip3009` |
| [CV4](#cv4)   | content not JSON                                         | 1     | `x402/exact/eip155/eip3009` |
| [CV5](#cv5)   | refusals before work                                     | 2     | `x402/exact/eip155/eip3009` |
| [CV6](#cv6)   | claim                                                    | 3     | `x402/exact/eip155/eip3009` |
| [CV7](#cv7)   | a report with nothing read                               | 2     | `x402/exact/eip155/eip3009` |
| [CV8](#cv8)   | status unknown                                           | 1     | `x402/exact/eip155/eip3009` |
| [CV9](#cv9)   | plain card checkout                                      | 4     | `card/seller-reference`     |
| [CV10](#cv10) | a card payment reported before the agreement is recorded | 3     | `card/seller-reference`     |

## CV1

**issue.** Source: printf '%s' '\<stored bytes>' | sha256sum; openssl dgst -sha256 agrees. expiresAt: date -u -d @1790000060. Content: printf '%s' '"Pay 10000 base units of USDC for one report."' | base64

| Step | Request       | Answer | Stores                                                                                  |
| ---- | ------------- | ------ | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue` | 200    | 506 bytes, SHA-256 `0x3c2394624c8c9a61ebaf7d8750a6f9ac21bf73e6369b7c0b64c83e34509cc3d3` |

## CV2

**repeat.** Source: The same mint request id and the same request give the first answer, byte for byte, and no second stored file.

| Step | Request       | Answer | Stores                                                                                  |
| ---- | ------------- | ------ | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue` | 200    | 506 bytes, SHA-256 `0x3c2394624c8c9a61ebaf7d8750a6f9ac21bf73e6369b7c0b64c83e34509cc3d3` |
| 2    | `POST /issue` | 200    | 1 file(s) in storage                                                                    |

## CV3

**reused id.** Source: One mint request id names one checkout state; other offers under it are refused.

| Step | Request       | Answer                          | Stores                                                                                  |
| ---- | ------------- | ------------------------------- | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue` | 200                             | 506 bytes, SHA-256 `0x3c2394624c8c9a61ebaf7d8750a6f9ac21bf73e6369b7c0b64c83e34509cc3d3` |
| 2    | `POST /issue` | 409 `issue/mint-request-reused` |                                                                                         |

## CV4

**content not JSON.** Source: printf '%s' '\{"a":1} \{"b":2}' | base64: two JSON values in one slot are not one JSON value (RFC 8259).

| Step | Request       | Answer                      | Stores |
| ---- | ------------- | --------------------------- | ------ |
| 1    | `POST /issue` | 422 `core/content-not-json` |        |

## CV5

**refusals before work.** Source: RFC 6750 §2.1 and §3; the Fetch standard sends Origin on every cross-origin request, and the door serves servers only.

| Step | Request       | Answer                     | Stores |
| ---- | ------------- | -------------------------- | ------ |
| 1    | `POST /issue` | 401 `door/unauthenticated` |        |
| 2    | `POST /issue` | 403 `door/browser-origin`  |        |

## CV6

**claim.** Source: The signature is x402's MCP example signature; the claim checks that the authorization's nonce is the hash, not the signature's validity.

| Step | Request       | Answer                  | Stores                                                                                  |
| ---- | ------------- | ----------------------- | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue` | 200                     | 506 bytes, SHA-256 `0x3c2394624c8c9a61ebaf7d8750a6f9ac21bf73e6369b7c0b64c83e34509cc3d3` |
| 2    | `POST /claim` | 200 `state: settling`   |                                                                                         |
| 3    | `POST /claim` | 409 `claim/in-progress` |                                                                                         |

## CV7

**a report with nothing read.** Source: printf '%s' '\<stored bytes>' | sha256sum; the reported transaction is not read settled on the chain (no reader answers for it), so nothing is recorded and the report is answered 202 with the record issued: report again later.

| Step | Request        | Answer              | Stores                                                                                  |
| ---- | -------------- | ------------------- | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue`  | 200                 | 506 bytes, SHA-256 `0x44f9a0d126d985d37b81447205a70c6d2ecd386a9fca859ddd5f61496ec33733` |
| 2    | `POST /report` | 202 `state: issued` |                                                                                         |

## CV8

**status unknown.** Source: printf '%s' abc | sha256sum (FIPS 180-2's published vector): a hash never issued.

| Step | Request                                                                          | Answer               | Stores |
| ---- | -------------------------------------------------------------------------------- | -------------------- | ------ |
| 1    | `GET /status/0xba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad` | 404 `door/not-found` |        |

## CV9

**plain card checkout.** Source: printf '%s' '\<stored bytes>' | sha256sum; openssl dgst -sha256 agrees. The reference is Wix's documented providerTransactionId example. expiresAt: date -u -d @1790000900. The agreement URL is https\://\<the tenant's first host>/agreement/\<atrHash>; the agreement transaction is a stated input, recorded before the report. Once the agreement is recorded, the pattern's statement names it: sed 's/\<network>/eip155:84532/; s/\<transaction>/\<the agreement transaction>/'.

| Step | Request                                                                          | Answer                       | Stores                                                                                  |
| ---- | -------------------------------------------------------------------------------- | ---------------------------- | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue`                                                                    | 200                          | 206 bytes, SHA-256 `0xcfa3a6589bf1e273ab105bb7144a2d5944af1caed14f58b39145d46842f825d8` |
| 2    | `POST /claim`                                                                    | 422 `claim/nothing-to-check` |                                                                                         |
| 3    | `POST /report` (agreement recorded before it)                                    | 200 `state: paid`            |                                                                                         |
| 4    | `GET /status/0xcfa3a6589bf1e273ab105bb7144a2d5944af1caed14f58b39145d46842f825d8` | 200 `state: paid`            |                                                                                         |

## CV10

**a card payment reported before the agreement is recorded.** Source: printf '%s' '\<stored bytes>' | sha256sum; openssl dgst -sha256 agrees. The checkout bytes: printf '%s' '\{"id":"chk\_1002","total":\{"currency":"USD","amount":27999}}' | base64. expiresAt: date -u -d @1790000900. The agreement URL is https\://\<the tenant's first host>/agreement/\<atrHash>. The reference is Wix's documented providerTransactionId example. The payment has moved, so it is recorded on the seller's report, and the record states what is missing: no agreement was recorded before this payment, and nothing public carries this ATR's hash.

| Step | Request                                                                          | Answer            | Stores                                                                                  |
| ---- | -------------------------------------------------------------------------------- | ----------------- | --------------------------------------------------------------------------------------- |
| 1    | `POST /issue`                                                                    | 200               | 206 bytes, SHA-256 `0x61c55d46c99a6199e8917bfbbcf7cb59b19f731dbd15c7ab750e9c2a2c664b32` |
| 2    | `POST /report`                                                                   | 200 `state: paid` |                                                                                         |
| 3    | `GET /status/0x61c55d46c99a6199e8917bfbbcf7cb59b19f731dbd15c7ab750e9c2a2c664b32` | 200 `state: paid` |                                                                                         |
