Skip to content

Feat/subscription delegation update - #10339

Merged
tuna1207 merged 30 commits into
mainfrom
feat/subscription-delegation-update
Sep 29, 2026
Merged

tuna1207 merged 30 commits into
mainfrom
feat/subscription-delegation-update

Conversation

@tuna1207

@tuna1207 tuna1207 commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Explanation

Adds SubscriptionDelegationService:startSubscriptionWithDelegation, providing a single-approval subscription checkout flow that:

  • Combines Money Account vault permissions with the recurring subscription permission.
  • Creates an immutable, fingerprinted authorization bundle for confirmation.
  • Requests MM Pay funding through ApprovalController.
  • Ensures Money Account delegation readiness after approval.
  • Signs, validates, persists, and registers the subscription delegation.
  • Verifies that CHOMP reports the intent as active before creating the subscription.
  • Reuses compatible existing delegations where possible.
  • Revalidates trial eligibility before subscription creation.

This also:

  • Adds temporary local Money Account readiness contracts until the owning package exports them.
  • Adds canonical EIP-712 typed-data construction, hashing, authority decoding, and bundle fingerprinting.
  • Wires the required actions into the wallet initialization messenger.
  • Adds Approval Controller, signature utility, and hashing dependencies.
  • Expands unit coverage for approval validation, readiness changes, delegation reuse, CHOMP failures, and trial eligibility changes.

The authorization bundle is sent to confirmations so the complete effective permission set can be displayed. The local assertTrialEligibility guard is removed before the backend request.

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating the package changelog
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

High Risk
Orchestrates user consent, MM Pay funding, delegation signing, and subscription creation with a breaking messenger contract—errors or ordering bugs could affect payments and recurring charges.

Overview
Adds SubscriptionDelegationService:startSubscriptionWithDelegation, an end-to-end Money Account Plus checkout that refreshes subscription state, ensures vault readiness via MoneyAccountUpgradeController:forceUpgradeAccount, shows a single subscription_delegation approval (immutable permission bundle + mUSD funding), then signs/commits the recurring payment delegation (CHOMP verify, AUS persist, active intent) and calls startSubscriptionWithCrypto with assertTrialEligibility: true. Optional skipApproval skips consent/funding when the caller already handled it.

Breaking: SubscriptionDelegationServiceMessenger must delegate ApprovalController:addRequest, MoneyAccountUpgradeController:forceUpgradeAccount, and several SubscriptionController:* actions; default wallet initialization is updated accordingly. New dependencies on approval-controller and money-account-upgrade-controller.

SubscriptionController:startSubscriptionWithCrypto gains optional assertTrialEligibility and throws TrialEligibilityChanged when trial intent no longer matches authoritative state after authorization. Supporting exports include EIP-712 typed-data helpers and approval/bundle types; CHOMP intent registration now uses the typed cash-subscription metadata without alpha workarounds.

Reviewed by Cursor Bugbot for commit dafb59d. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security

socket-security Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@tuna1207
tuna1207 marked this pull request as ready for review September 28, 2026 11:52
@tuna1207
tuna1207 requested review from a team as code owners September 28, 2026 11:52
@tuna1207
tuna1207 deployed to default-branch September 28, 2026 11:53 — with GitHub Actions Active

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21de504. Configure here.

@github-actions

Copy link
Copy Markdown
Contributor

Preview builds have been published. Learn how to use preview builds in other projects.

Expand for full list of packages and versions.
@metamask-previews/account-tree-controller@11.0.0-preview-c4f7eb130
@metamask-previews/accounts-controller@40.0.0-preview-c4f7eb130
@metamask-previews/address-book-controller@8.0.0-preview-c4f7eb130
@metamask-previews/advanced-chart-core@0.0.0-preview-c4f7eb130
@metamask-previews/ai-controllers@2.0.0-preview-c4f7eb130
@metamask-previews/analytics-controller@3.2.0-preview-c4f7eb130
@metamask-previews/analytics-data-regulation-controller@0.0.0-preview-c4f7eb130
@metamask-previews/announcement-controller@9.0.0-preview-c4f7eb130
@metamask-previews/app-metadata-controller@3.0.0-preview-c4f7eb130
@metamask-previews/approval-controller@10.0.0-preview-c4f7eb130
@metamask-previews/assets-controller@17.0.0-preview-c4f7eb130
@metamask-previews/assets-controllers@112.0.4-preview-c4f7eb130
@metamask-previews/authenticated-user-storage@4.1.0-preview-c4f7eb130
@metamask-previews/base-controller@10.0.0-preview-c4f7eb130
@metamask-previews/base-data-service@2.1.0-preview-c4f7eb130
@metamask-previews/bitcoin-regtest-up@2.0.0-preview-c4f7eb130
@metamask-previews/bridge-controller@81.3.3-preview-c4f7eb130
@metamask-previews/bridge-status-controller@76.3.3-preview-c4f7eb130
@metamask-previews/build-utils@4.0.0-preview-c4f7eb130
@metamask-previews/chain-agnostic-permission@2.0.0-preview-c4f7eb130
@metamask-previews/chomp-api-service@6.0.0-preview-c4f7eb130
@metamask-previews/claims-controller@1.0.2-preview-c4f7eb130
@metamask-previews/client-controller@2.0.0-preview-c4f7eb130
@metamask-previews/client-utils@3.0.3-preview-c4f7eb130
@metamask-previews/compliance-controller@3.0.0-preview-c4f7eb130
@metamask-previews/composable-controller@13.0.0-preview-c4f7eb130
@metamask-previews/config-registry-controller@4.0.0-preview-c4f7eb130
@metamask-previews/connectivity-controller@1.0.0-preview-c4f7eb130
@metamask-previews/controller-utils@13.0.0-preview-c4f7eb130
@metamask-previews/core-backend@11.0.0-preview-c4f7eb130
@metamask-previews/cryptography@0.0.0-preview-c4f7eb130
@metamask-previews/delegation-controller@4.0.0-preview-c4f7eb130
@metamask-previews/earn-controller@13.0.2-preview-c4f7eb130
@metamask-previews/eip-5792-middleware@4.0.1-preview-c4f7eb130
@metamask-previews/eip-7702-internal-rpc-middleware@1.0.0-preview-c4f7eb130
@metamask-previews/eip1193-permission-middleware@3.0.0-preview-c4f7eb130
@metamask-previews/eth-block-tracker@16.0.0-preview-c4f7eb130
@metamask-previews/eth-json-rpc-middleware@25.0.0-preview-c4f7eb130
@metamask-previews/eth-json-rpc-provider@7.0.0-preview-c4f7eb130
@metamask-previews/foundryup@2.0.0-preview-c4f7eb130
@metamask-previews/gas-fee-controller@27.0.0-preview-c4f7eb130
@metamask-previews/gator-permissions-controller@6.0.1-preview-c4f7eb130
@metamask-previews/geolocation-controller@2.0.0-preview-c4f7eb130
@metamask-previews/java-tron-up@2.0.0-preview-c4f7eb130
@metamask-previews/json-rpc-engine@11.0.0-preview-c4f7eb130
@metamask-previews/json-rpc-middleware-stream@9.0.0-preview-c4f7eb130
@metamask-previews/keyring-controller@28.1.0-preview-c4f7eb130
@metamask-previews/kyc-controller@0.6.0-preview-c4f7eb130
@metamask-previews/local-node-utils@2.0.0-preview-c4f7eb130
@metamask-previews/logging-controller@10.0.0-preview-c4f7eb130
@metamask-previews/message-manager@15.0.0-preview-c4f7eb130
@metamask-previews/messenger@3.0.0-preview-c4f7eb130
@metamask-previews/messenger-cli@1.0.0-preview-c4f7eb130
@metamask-previews/money-account-api-data-service@2.1.0-preview-c4f7eb130
@metamask-previews/money-account-balance-service@3.1.1-preview-c4f7eb130
@metamask-previews/money-account-controller@2.0.0-preview-c4f7eb130
@metamask-previews/money-account-upgrade-controller@5.1.0-preview-c4f7eb130
@metamask-previews/money-account-utils@2.1.0-preview-c4f7eb130
@metamask-previews/multichain-account-service@14.1.0-preview-c4f7eb130
@metamask-previews/multichain-api-middleware@5.0.0-preview-c4f7eb130
@metamask-previews/multichain-network-controller@4.0.0-preview-c4f7eb130
@metamask-previews/multichain-transactions-controller@8.0.0-preview-c4f7eb130
@metamask-previews/name-controller@10.0.0-preview-c4f7eb130
@metamask-previews/network-connection-banner-controller@1.0.0-preview-c4f7eb130
@metamask-previews/network-controller@37.0.0-preview-c4f7eb130
@metamask-previews/network-enablement-controller@7.0.1-preview-c4f7eb130
@metamask-previews/notification-services-controller@29.0.2-preview-c4f7eb130
@metamask-previews/passkey-controller@4.1.0-preview-c4f7eb130
@metamask-previews/permission-controller@14.0.0-preview-c4f7eb130
@metamask-previews/permission-log-controller@6.0.0-preview-c4f7eb130
@metamask-previews/perps-controller@18.0.1-preview-c4f7eb130
@metamask-previews/phishing-controller@18.1.1-preview-c4f7eb130
@metamask-previews/platform-api-docs@0.2.1-preview-c4f7eb130
@metamask-previews/polling-controller@17.0.0-preview-c4f7eb130
@metamask-previews/preferences-controller@24.0.0-preview-c4f7eb130
@metamask-previews/profile-metrics-controller@5.1.2-preview-c4f7eb130
@metamask-previews/profile-sync-controller@33.0.0-preview-c4f7eb130
@metamask-previews/ramps-controller@26.0.1-preview-c4f7eb130
@metamask-previews/rate-limit-controller@8.0.0-preview-c4f7eb130
@metamask-previews/react-data-query@2.0.0-preview-c4f7eb130
@metamask-previews/remote-feature-flag-controller@7.0.0-preview-c4f7eb130
@metamask-previews/sample-controllers@6.0.0-preview-c4f7eb130
@metamask-previews/seedless-onboarding-controller@11.0.1-preview-c4f7eb130
@metamask-previews/selected-network-controller@27.0.0-preview-c4f7eb130
@metamask-previews/sentinel-api-service@2.0.0-preview-c4f7eb130
@metamask-previews/shield-controller@7.0.3-preview-c4f7eb130
@metamask-previews/signature-controller@40.0.0-preview-c4f7eb130
@metamask-previews/smart-transactions-controller@27.0.3-preview-c4f7eb130
@metamask-previews/snap-account-service@4.0.0-preview-c4f7eb130
@metamask-previews/social-controllers@3.4.0-preview-c4f7eb130
@metamask-previews/solana-test-validator-up@2.0.0-preview-c4f7eb130
@metamask-previews/stellar-quickstart-up@0.0.0-preview-c4f7eb130
@metamask-previews/storage-service@2.0.0-preview-c4f7eb130
@metamask-previews/subscription-controller@10.0.1-preview-c4f7eb130
@metamask-previews/transaction-controller@72.0.1-preview-c4f7eb130
@metamask-previews/transaction-pay-controller@29.2.3-preview-c4f7eb130
@metamask-previews/user-operation-controller@42.0.1-preview-c4f7eb130
@metamask-previews/utils@12.0.0-preview-c4f7eb130
@metamask-previews/wallet@15.0.1-preview-c4f7eb130
@metamask-previews/wallet-cli@0.0.0-preview-c4f7eb130

Comment thread packages/subscription-controller/src/subscription-delegation/types.ts Outdated
tanguyenvn
tanguyenvn previously approved these changes Sep 29, 2026
GuillaumeRx
GuillaumeRx previously approved these changes Sep 29, 2026

@GuillaumeRx GuillaumeRx left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM for core-platform

@tuna1207
tuna1207 disabled auto-merge September 29, 2026 09:18
@tuna1207

Copy link
Copy Markdown
Member Author

@metamaskbot publish-previews

@github-actions

Copy link
Copy Markdown
Contributor

Preview builds have been published. Learn how to use preview builds in other projects.

Expand for full list of packages and versions.
@metamask-previews/account-tree-controller@11.0.0-preview-5f7897422
@metamask-previews/accounts-controller@40.0.0-preview-5f7897422
@metamask-previews/address-book-controller@8.0.0-preview-5f7897422
@metamask-previews/advanced-chart-core@0.0.0-preview-5f7897422
@metamask-previews/ai-controllers@2.0.0-preview-5f7897422
@metamask-previews/analytics-controller@3.2.0-preview-5f7897422
@metamask-previews/analytics-data-regulation-controller@0.0.0-preview-5f7897422
@metamask-previews/announcement-controller@9.0.0-preview-5f7897422
@metamask-previews/app-metadata-controller@3.0.0-preview-5f7897422
@metamask-previews/approval-controller@10.0.0-preview-5f7897422
@metamask-previews/assets-controller@17.0.0-preview-5f7897422
@metamask-previews/assets-controllers@112.0.4-preview-5f7897422
@metamask-previews/authenticated-user-storage@4.1.0-preview-5f7897422
@metamask-previews/base-controller@10.0.0-preview-5f7897422
@metamask-previews/base-data-service@2.1.0-preview-5f7897422
@metamask-previews/bitcoin-regtest-up@2.0.0-preview-5f7897422
@metamask-previews/bridge-controller@81.3.3-preview-5f7897422
@metamask-previews/bridge-status-controller@76.3.3-preview-5f7897422
@metamask-previews/build-utils@4.0.0-preview-5f7897422
@metamask-previews/chain-agnostic-permission@2.0.0-preview-5f7897422
@metamask-previews/chomp-api-service@6.0.0-preview-5f7897422
@metamask-previews/claims-controller@1.0.2-preview-5f7897422
@metamask-previews/client-controller@2.0.0-preview-5f7897422
@metamask-previews/client-utils@3.0.3-preview-5f7897422
@metamask-previews/compliance-controller@3.0.0-preview-5f7897422
@metamask-previews/composable-controller@13.0.0-preview-5f7897422
@metamask-previews/config-registry-controller@4.0.0-preview-5f7897422
@metamask-previews/connectivity-controller@1.0.0-preview-5f7897422
@metamask-previews/controller-utils@13.0.0-preview-5f7897422
@metamask-previews/core-backend@11.0.0-preview-5f7897422
@metamask-previews/cryptography@0.0.0-preview-5f7897422
@metamask-previews/delegation-controller@4.0.0-preview-5f7897422
@metamask-previews/earn-controller@13.0.2-preview-5f7897422
@metamask-previews/eip-5792-middleware@4.0.1-preview-5f7897422
@metamask-previews/eip-7702-internal-rpc-middleware@1.0.0-preview-5f7897422
@metamask-previews/eip1193-permission-middleware@3.0.0-preview-5f7897422
@metamask-previews/eth-block-tracker@16.0.0-preview-5f7897422
@metamask-previews/eth-json-rpc-middleware@25.0.0-preview-5f7897422
@metamask-previews/eth-json-rpc-provider@7.0.0-preview-5f7897422
@metamask-previews/foundryup@2.0.0-preview-5f7897422
@metamask-previews/gas-fee-controller@27.0.0-preview-5f7897422
@metamask-previews/gator-permissions-controller@6.0.1-preview-5f7897422
@metamask-previews/geolocation-controller@2.0.0-preview-5f7897422
@metamask-previews/java-tron-up@2.0.0-preview-5f7897422
@metamask-previews/json-rpc-engine@11.0.0-preview-5f7897422
@metamask-previews/json-rpc-middleware-stream@9.0.0-preview-5f7897422
@metamask-previews/keyring-controller@28.1.0-preview-5f7897422
@metamask-previews/kyc-controller@0.6.0-preview-5f7897422
@metamask-previews/local-node-utils@2.0.0-preview-5f7897422
@metamask-previews/logging-controller@10.0.0-preview-5f7897422
@metamask-previews/message-manager@15.0.0-preview-5f7897422
@metamask-previews/messenger@3.0.0-preview-5f7897422
@metamask-previews/messenger-cli@1.0.0-preview-5f7897422
@metamask-previews/money-account-api-data-service@2.1.0-preview-5f7897422
@metamask-previews/money-account-balance-service@3.1.1-preview-5f7897422
@metamask-previews/money-account-controller@2.0.0-preview-5f7897422
@metamask-previews/money-account-upgrade-controller@5.1.0-preview-5f7897422
@metamask-previews/money-account-utils@2.1.0-preview-5f7897422
@metamask-previews/multichain-account-service@14.1.0-preview-5f7897422
@metamask-previews/multichain-api-middleware@5.0.0-preview-5f7897422
@metamask-previews/multichain-network-controller@4.0.0-preview-5f7897422
@metamask-previews/multichain-transactions-controller@8.0.0-preview-5f7897422
@metamask-previews/name-controller@10.0.0-preview-5f7897422
@metamask-previews/network-connection-banner-controller@1.0.0-preview-5f7897422
@metamask-previews/network-controller@37.0.0-preview-5f7897422
@metamask-previews/network-enablement-controller@7.0.1-preview-5f7897422
@metamask-previews/notification-services-controller@29.0.2-preview-5f7897422
@metamask-previews/passkey-controller@4.1.0-preview-5f7897422
@metamask-previews/permission-controller@14.0.0-preview-5f7897422
@metamask-previews/permission-log-controller@6.0.0-preview-5f7897422
@metamask-previews/perps-controller@18.0.1-preview-5f7897422
@metamask-previews/phishing-controller@18.1.1-preview-5f7897422
@metamask-previews/platform-api-docs@0.2.1-preview-5f7897422
@metamask-previews/polling-controller@17.0.0-preview-5f7897422
@metamask-previews/preferences-controller@24.0.0-preview-5f7897422
@metamask-previews/profile-metrics-controller@5.1.2-preview-5f7897422
@metamask-previews/profile-sync-controller@33.0.0-preview-5f7897422
@metamask-previews/ramps-controller@26.0.1-preview-5f7897422
@metamask-previews/rate-limit-controller@8.0.0-preview-5f7897422
@metamask-previews/react-data-query@2.0.0-preview-5f7897422
@metamask-previews/remote-feature-flag-controller@7.0.0-preview-5f7897422
@metamask-previews/sample-controllers@6.0.0-preview-5f7897422
@metamask-previews/seedless-onboarding-controller@11.0.1-preview-5f7897422
@metamask-previews/selected-network-controller@27.0.0-preview-5f7897422
@metamask-previews/sentinel-api-service@2.0.0-preview-5f7897422
@metamask-previews/shield-controller@7.0.3-preview-5f7897422
@metamask-previews/signature-controller@40.0.0-preview-5f7897422
@metamask-previews/smart-transactions-controller@27.0.3-preview-5f7897422
@metamask-previews/snap-account-service@4.0.0-preview-5f7897422
@metamask-previews/social-controllers@3.4.0-preview-5f7897422
@metamask-previews/solana-test-validator-up@2.0.0-preview-5f7897422
@metamask-previews/stellar-quickstart-up@0.0.0-preview-5f7897422
@metamask-previews/storage-service@2.0.0-preview-5f7897422
@metamask-previews/subscription-controller@10.0.1-preview-5f7897422
@metamask-previews/transaction-controller@72.0.1-preview-5f7897422
@metamask-previews/transaction-pay-controller@29.2.3-preview-5f7897422
@metamask-previews/user-operation-controller@42.0.1-preview-5f7897422
@metamask-previews/utils@12.0.0-preview-5f7897422
@metamask-previews/wallet@15.0.1-preview-5f7897422
@metamask-previews/wallet-cli@0.0.0-preview-5f7897422

@tuna1207
tuna1207 enabled auto-merge September 29, 2026 10:25
tanguyenvn
tanguyenvn previously approved these changes Sep 29, 2026
Comment thread packages/wallet/CHANGELOG.md Outdated

### Changed

- **BREAKING:** Grant `SubscriptionDelegationService` access to the additional messenger actions required by `SubscriptionDelegationService:startSubscriptionWithDelegation` ([#10339](https://github.com/MetaMask/core/pull/10339))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I missed this. It's not breaking on the wallet side

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

updated in dafb59d

@tuna1207
tuna1207 added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 4fd97c0 Sep 29, 2026
54 checks passed
@tuna1207
tuna1207 deleted the feat/subscription-delegation-update branch September 29, 2026 11:03
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 29, 2026
## Explanation

The crypto subscription start flow and `getSubscriptions` were both
failing on successful API responses because our response structs did not
match what the Subscription API actually returns.

### Crypto start response shape

`SubscriptionService:startSubscriptionWithCrypto` validated the `POST
/subscriptions/crypto` response against
`StartCryptoSubscriptionResponseStruct` (`{ subscriptionId, status }`).
The API actually returns the full created `Subscription` object (crypto
subscriptions are created immediately, unlike card checkout which
returns a checkout session URL). Because the response never had a
`subscriptionId` field, `create()` threw on every successful call, so
the crypto start flow always failed after the API had already created
the subscription.

This PR:

- Removes `StartCryptoSubscriptionResponseStruct` and validates the
response against `SubscriptionStruct` instead.
- Redefines `StartCryptoSubscriptionResponse` as an alias of
`Subscription`. This is **BREAKING** for consumers reading
`response.subscriptionId`; they should read `response.id` instead.
`response.status` is unchanged. This affects
`SubscriptionService:startSubscriptionWithCrypto`,
`SubscriptionController:startSubscriptionWithCrypto`, and
`SubscriptionDelegationService:startSubscriptionWithDelegation`.

### Optional fields on `Subscription`

`SubscriptionStruct` required `lastInvoice.updatedAt` and
`paymentMethod.card.displayBrand`, but both are optional in the API. Any
subscription with a `lastInvoice` (i.e. anything that has been billed at
least once) failed validation and `getSubscriptions` threw. Both fields
are now optional in the struct and on the `SubscriptionInvoice` /
`SubscriptionCardPaymentMethod` types.

### `awaiting_funds` status

The API returns an `awaiting_funds` status for crypto subscriptions that
were created but whose first invoice has not been funded yet. This
status was not in `SUBSCRIPTION_STATUSES`, so such subscriptions also
failed validation. This PR adds `SUBSCRIPTION_STATUSES.awaitingFunds`
and teaches `SubscriptionController:submitSubscriptionCryptoApproval` to
treat it like `past_due` / `unpaid`: submitting a new approval for a
subscription in this state updates the existing subscription's payment
method instead of attempting to start a new one.

### Tests

- `SubscriptionService.test.ts`: crypto start tests now use full
subscription fixtures; added cases for a missing `updatedAt`, a missing
`displayBrand`, the `awaiting_funds` status, pass-through of additional
subscription fields, and rejection of a non-subscription response.
- `SubscriptionController.test.ts` and
`SubscriptionDelegationService.test.ts`: updated to the new response
shape and added coverage for the `awaiting_funds` branch in
`submitSubscriptionCryptoApproval`.

## References

- Follow-up to MetaMask#10339 (subscription delegation update), which added the
crypto start flow this fixes.
<!-- Add client PRs adopting the `response.subscriptionId` ->
`response.id` change here -->

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Breaking return type on crypto subscription start affects all
consumers; changes subscription status handling and crypto approval
routing for payment recovery.
> 
> **Overview**
> Fixes crypto subscription and `getSubscriptions` flows that **threw on
successful API responses** because client validation did not match the
Subscription API.
> 
> **Breaking:** `StartCryptoSubscriptionResponse` is now the full
created **`Subscription`** (validated with `SubscriptionStruct`), not `{
subscriptionId, status }`. Callers must use **`response.id`** instead of
`response.subscriptionId` on `startSubscriptionWithCrypto` and
delegation start paths.
> 
> **Validation fixes:** `lastInvoice.updatedAt` and card
**`displayBrand`** are optional so billed subscriptions and card payment
methods no longer fail `getSubscriptions`. Adds
**`SUBSCRIPTION_STATUSES.awaitingFunds`** for crypto subs waiting on
first-invoice funding.
> 
> **Behavior:** `submitSubscriptionCryptoApproval` treats
**`awaiting_funds`** like `past_due` / `unpaid`—a new approval **updates
the existing subscription’s payment method** instead of starting a new
subscription.
> 
> Tests and changelog updated for the new response shape, optional
fields, and the awaiting-funds approval branch.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
82a2b98. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@tuna1207 tuna1207 mentioned this pull request Oct 2, 2026
3 of 4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants