Skip to main content

Orcestr Commerce Solana for Python

orcestr-commerce-solana adds non-custodial native SOL and Token-2022 checkout to CommerceXL. It verifies raw finalized Solana transactions through standard JSON-RPC and does not require a paid API, webhook provider, private key, or custody service.

The first release deliberately rejects the legacy SPL Token Program, swaps, CPI transfers, batch payments, partial payments, transfer-fee mints, and unknown Token-2022 extensions. Correctness comes from the raw transaction and an immutable settlement snapshot. Public RPC endpoints remain rate-limited infrastructure without an availability SLA; applications can inject any compatible HTTP RPC endpoint or their own node without changing payment contracts.

Install

pip install orcestr-commerce-solana

For local ecosystem development from the Orcestr backend:

uv pip install --python .venv --editable ../../orcestr-commerce-solana/backend

The host application owns the database engine, sessions, Alembic migrations, authentication, authorization, CSRF policy, scheduler, WebSocket transport, treasury configuration, and product pricing. Import orcestr_commerce_solana.models before collecting CommerceBase.metadata; the package intentionally ships no migrations.

Minimal verifier

from orcestr_commerce_solana import HttpSolanaRpc, SolanaTransactionVerifier
from orcestr_commerce_solana.config import SolanaRpcConfig
from orcestr_commerce_solana.constants import MAINNET_GENESIS_HASH

rpc = HttpSolanaRpc(
    SolanaRpcConfig(
        genesis_hash=MAINNET_GENESIS_HASH,
        endpoints=("https://api.mainnet-beta.solana.com",),
    ),
)
verifier = SolanaTransactionVerifier(rpc, used_signatures=my_database_signature_registry)

Build a VerificationRequest from the persisted intent and issuance snapshots, then call await verifier.verify(request). confirmed is always provisional; only a fully decoded finalized transaction produces authoritative MATCH. UNKNOWN is retryable and must never grant a product. REVIEW preserves an on-chain mismatch for reconciliation.

See the repository documentation for the state machine, asset activation, transaction-request endpoint, free RPC operations, CommerceXL registration, FastAPI ports, and threat model.

The default host wiring is intentionally small:

  • SolanaApplicationService.build_default(...) supplies authenticated checkout orchestration.
  • SolanaFastApiRouterFactory supplies typed routes; the host injects Orcestr Auth actor, ownership, and CSRF dependencies.
  • create_sqlalchemy_reconciler(...) supplies leased background reconciliation, DB-backed signature uniqueness, paginated reference scans, and safe expiry.
  • SolanaProviderRegistrationFactory registers the provider explicitly in CommerceXL 0.3.1 or newer. Version 0.3.1 is the minimum because its state machine permits a provisional confirmed payment to expire after a complete final reference scan.

SolanaProviderDependencies requires a host SettlementPriceKeyResolver. It must resolve a stable product/plan/pack code from the order; broad order kinds are intentionally not used as a pricing fallback. Fixed prices are keyed by (resolved_price_key, asset_option_id), so Beauty packs of the same order kind can have different token amounts. A custom SettlementQuoteProvider may replace fixed prices while preserving the immutable quote snapshot. A custom RecipientResolver supports either a Beauty treasury or host-verified P2P recipients without changing the verifier.

Transaction issuance is bounded by max_issuances_per_intent (default 16) under the intent row lock. expires_at is the public payment deadline; a successful complete scan expires the payment at that deadline. An immutable reconcile_until grace horizon keeps cancelled/expired attempts discoverable only for late finalized evidence. Every distinct late transfer is written to CommerceXL with the same terminal state and never grants the product.

Detailed integration and security contracts are in architecture, host integration, and security.

Development

uv sync --frozen
uv run pytest tests
uv build

Python 3.12, 3.13, and 3.14 are supported. All timestamps are timezone-aware UTC and all blockchain amounts cross API boundaries as integer strings.

TransactionVersion.LEGACY denotes Solana's legacy wire-message format for verification only. The package emits v0 transactions, and it does not expose the legacy SPL Token Program as a supported public root API.

Release files for orcestr-commerce-solana 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for orcestr-commerce-solana 0.1.0
File Size Uploaded
orcestr_commerce_solana-0.1.0.tar.gz 109.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for orcestr-commerce-solana 0.1.0
File Interpreter ABI Platform
orcestr_commerce_solana-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 190.2 kB

Release files / orcestr_commerce_solana-0.1.0.tar.gz

Download URL orcestr_commerce_solana-0.1.0.tar.gz
Size 109.3 kB
Tags Source
SHA-256 checksum
How to use checksums
c3d43774fcd2b5da8754028b9b10905d50f5f75eb65db4a0236cc2549fc9aa7b
BLAKE2b-256 checksum
How to use checksums
d7818b0909b28f2069db1bbab711e47ff2c03454387f5bf13729731dbea49120
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / orcestr_commerce_solana-0.1.0-py3-none-any.whl

Download URL orcestr_commerce_solana-0.1.0-py3-none-any.whl
Size 80.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
339a285dd9f3a692bfa2aafea26c764340035f694d3c6da7ad2f2b761515d073
BLAKE2b-256 checksum
How to use checksums
6c9d5a8aa85a7927bd17f64bb07b14d90a8d6a394ec8f8183cd158a9c97f1589
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page