Orcestr Commerce Solana for Python
orcestr-commerce-solana adds non-custodial native SOL and Token-2022 checkout to CommerceXL. It verifies raw finalized Solana transactions through standard JSON-RPC and does not require a paid API, webhook provider, private key, or custody service.
The first release deliberately rejects the legacy SPL Token Program, swaps, CPI transfers, batch payments, partial payments, transfer-fee mints, and unknown Token-2022 extensions. Correctness comes from the raw transaction and an immutable settlement snapshot. Public RPC endpoints remain rate-limited infrastructure without an availability SLA; applications can inject any compatible HTTP RPC endpoint or their own node without changing payment contracts.
Install
pip install orcestr-commerce-solana
For local ecosystem development from the Orcestr backend:
uv pip install --python .venv --editable ../../orcestr-commerce-solana/backend
The host application owns the database engine, sessions, Alembic migrations, authentication, authorization, CSRF policy, scheduler, WebSocket transport, treasury configuration, and product pricing. Import orcestr_commerce_solana.models before collecting CommerceBase.metadata; the package intentionally ships no migrations.
Minimal verifier
from orcestr_commerce_solana import HttpSolanaRpc, SolanaTransactionVerifier
from orcestr_commerce_solana.config import SolanaRpcConfig
from orcestr_commerce_solana.constants import MAINNET_GENESIS_HASH
rpc = HttpSolanaRpc(
SolanaRpcConfig(
genesis_hash=MAINNET_GENESIS_HASH,
endpoints=("https://api.mainnet-beta.solana.com",),
),
)
verifier = SolanaTransactionVerifier(rpc, used_signatures=my_database_signature_registry)
Build a VerificationRequest from the persisted intent and issuance snapshots, then call await verifier.verify(request). confirmed is always provisional; only a fully decoded finalized transaction produces authoritative MATCH. UNKNOWN is retryable and must never grant a product. REVIEW preserves an on-chain mismatch for reconciliation.
See the repository documentation for the state machine, asset activation, transaction-request endpoint, free RPC operations, CommerceXL registration, FastAPI ports, and threat model.
The default host wiring is intentionally small:
SolanaApplicationService.build_default(...)supplies authenticated checkout orchestration.SolanaFastApiRouterFactorysupplies typed routes; the host injects Orcestr Auth actor, ownership, and CSRF dependencies.create_sqlalchemy_reconciler(...)supplies leased background reconciliation, DB-backed signature uniqueness, paginated reference scans, and safe expiry.SolanaProviderRegistrationFactoryregisters the provider explicitly in CommerceXL 0.3.1 or newer. Version 0.3.1 is the minimum because its state machine permits a provisional confirmed payment to expire after a complete final reference scan.
SolanaProviderDependencies requires a host SettlementPriceKeyResolver. It must resolve a stable product/plan/pack code from the order; broad order kinds are intentionally not used as a pricing fallback. Fixed prices are keyed by (resolved_price_key, asset_option_id), so Beauty packs of the same order kind can have different token amounts. A custom SettlementQuoteProvider may replace fixed prices while preserving the immutable quote snapshot. A custom RecipientResolver supports either a Beauty treasury or host-verified P2P recipients without changing the verifier.
Transaction issuance is bounded by max_issuances_per_intent (default 16) under the intent row lock. expires_at is the public payment deadline; a successful complete scan expires the payment at that deadline. An immutable reconcile_until grace horizon keeps cancelled/expired attempts discoverable only for late finalized evidence. Every distinct late transfer is written to CommerceXL with the same terminal state and never grants the product.
Detailed integration and security contracts are in architecture, host integration, and security.
Development
uv sync --frozen
uv run pytest tests
uv build
Python 3.12, 3.13, and 3.14 are supported. All timestamps are timezone-aware UTC and all blockchain amounts cross API boundaries as integer strings.
TransactionVersion.LEGACY denotes Solana's legacy wire-message format for verification only. The package emits v0 transactions, and it does not expose the legacy SPL Token Program as a supported public root API.
Release files for orcestr-commerce-solana 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| orcestr_commerce_solana-0.1.0.tar.gz | 109.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| orcestr_commerce_solana-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 190.2 kB
Release files / orcestr_commerce_solana-0.1.0.tar.gz
| Download URL | orcestr_commerce_solana-0.1.0.tar.gz |
|---|---|
| Size | 109.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c3d43774fcd2b5da8754028b9b10905d50f5f75eb65db4a0236cc2549fc9aa7b
|
|
BLAKE2b-256 checksum How to use checksums |
d7818b0909b28f2069db1bbab711e47ff2c03454387f5bf13729731dbea49120
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / orcestr_commerce_solana-0.1.0-py3-none-any.whl
| Download URL | orcestr_commerce_solana-0.1.0-py3-none-any.whl |
|---|---|
| Size | 80.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
339a285dd9f3a692bfa2aafea26c764340035f694d3c6da7ad2f2b761515d073
|
|
BLAKE2b-256 checksum How to use checksums |
6c9d5a8aa85a7927bd17f64bb07b14d90a8d6a394ec8f8183cd158a9c97f1589
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|