Skip to content

feat(quotes): allow a per-transaction platform fee override on POST /quotes - #797

Open
jacklatourette wants to merge 3 commits into
mainfrom
jack/at-6193-platform-fee-override
Open

feat(quotes): allow a per-transaction platform fee override on POST /quotes#797
jacklatourette wants to merge 3 commits into
mainfrom
jack/at-6193-platform-fee-override

Conversation

@jacklatourette

Copy link
Copy Markdown
Contributor

What

Adds an optional platformFeeOverride object to the QuoteRequest schema (new components/schemas/quotes/PlatformFeeOverride.yaml, bundles regenerated).

When present, the override replaces all platform fees that would otherwise apply to the transaction:

  • platformFixedFee ({amount, currency}) and platformVariableFeeBps are both required within the object; negatives rejected at schema level (minimum: 0)
  • No standing fee config is required and there is no cap relative to one
  • USD source currency only today (including same-currency USD transfers); the fixed fee currency must equal the quote's source currency — 400 INVALID_INPUT otherwise
  • TRANSACTION_OVERRIDE is deliberately NOT added to config/FeeType.yaml: platforms must not create standing override configs via PATCH /config

No response-shape changes. Optional-field addition — passes the oasdiff breaking-change check.

Why

Grid Fees Phase 2d (AT-6193, epic AT-6136): platforms need per-transaction control of their own fee (promos, VIP pricing, negotiated rates) without editing standing config.

Sparkcore implementation: lightsparkdev/webdev stack for AT-6128 / AT-6194 (vendored client regen included there).

🤖 Generated with Claude Code

…quotes

Optional platformFeeOverride on QuoteRequest: when present it replaces all
platform fees that would otherwise apply — no standing fee config required
and no cap relative to one. platformFixedFee and platformVariableFeeBps are
both required within the object; negatives are rejected at schema level.
USD source currency only today (including same-currency USD transfers); the
fixed fee currency must equal the quote's source currency (AT-6193).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Aug 4, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

2 Skipped Deployments
Project Deployment Actions Updated (UTC)
grid-flow-builder Ignored Ignored Preview Aug 6, 2026 12:02am
grid-wallet-demo Ignored Ignored Preview Aug 6, 2026 12:02am

Request Review

@mintlify

mintlify Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
Grid 🟢 Ready View Preview Aug 4, 2026, 5:34 PM

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

✱ Stainless preview builds for grid

This PR will update the grid SDKs with the following commit messages.

cli

feat(api): add platform-fee-override parameter to quotes/agents:me:quotes create

go

feat(api): add platformFeeOverride parameter to quote requests

kotlin

feat(api): add platformFeeOverride parameter to QuoteRequest

openapi

feat(api): add platformFeeOverride parameter to QuoteRequest

php

feat(api): add platformFeeOverride parameter to quotes create method

python

feat(api): add platform_fee_override parameter to quotes create method

ruby

feat(api): add platform_fee_override parameter to quotes create method

typescript

feat(api): add platformFeeOverride parameter to quotes create methods

Edit this comment to update them. They will appear in their respective SDK's changelogs.

grid-typescript studio · code · diff

Your SDK build had at least one "note" diagnostic, but this did not represent a regression.
generate ✅build ✅lint ❗test ✅

npm install https://pkg.stainless.com/s/grid-typescript/89efa0540448464da274fe5761947795308a072d/dist.tar.gz
grid-openapi studio · code · diff

Your SDK build had at least one "warning" diagnostic, but this did not represent a regression.
generate ⚠️

grid-ruby studio · code · diff

Your SDK build had at least one "note" diagnostic, but this did not represent a regression.
generate ✅build ✅lint ✅test ✅

grid-go studio · code · diff

Your SDK build had at least one "note" diagnostic, but this did not represent a regression.
generate ✅build ✅lint ❗test ❗

go get github.com/stainless-sdks/grid-go@0a037a3733a70991c91254cdec5d4e733290d7c3
grid-kotlin studio · code · diff

Your SDK build had at least one "warning" diagnostic, but this did not represent a regression.
generate ⚠️build ✅lint ✅test ❗

grid-python studio · code · diff

Your SDK build had at least one "note" diagnostic, but this did not represent a regression.
generate ✅build ✅lint ❗test ❗

pip install https://pkg.stainless.com/s/grid-python/394d99a0635ed584cc9cb1d87d24d1515d007967/grid-0.0.1-py3-none-any.whl
grid-php studio · code · diff

Your SDK build had at least one "note" diagnostic, but this did not represent a regression.
generate ✅lint ✅test ✅

grid-cli studio · code · diff

Your SDK build had at least one "warning" diagnostic, but this did not represent a regression.
generate ⚠️build ❗lint ❗test ❗


This comment is auto-generated by GitHub Actions and is automatically kept up to date as you push.
If you push custom code to the preview branch, re-run this workflow to update the comment.
Last updated: 2026-08-06 00:06:41 UTC

@greptile-apps

greptile-apps Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

The PR adds an optional per-transaction platform fee override to quote creation and regenerates both committed OpenAPI bundles.

  • Defines required fixed and variable override components with non-negative values.
  • Adds the override to the shared QuoteRequest contract.
  • Documents current USD and source-currency restrictions.
  • The shared request also exposes the platform fee capability on the agent quote endpoint, where no fee-control permission exists.

Confidence Score: 4/5

The agent-facing fee-control exposure should be resolved before merging because the shared request schema bypasses the intended platform-only contract boundary.

POST /agents/me/quotes consumes the modified QuoteRequest, so agents with only CREATE_QUOTES are now advertised as able to select platform fees even though the permission model provides no corresponding fee-control authority.

Files Needing Attention: openapi/components/schemas/quotes/QuoteRequest.yaml

Security Review

The shared QuoteRequest allows callers of the agent quote endpoint to submit platform fee overrides despite the agent permission model having no fee-management capability. The agent contract should omit this field or introduce an explicit authorization boundary before the capability is advertised.

Important Files Changed

Filename Overview
openapi/components/schemas/quotes/QuoteRequest.yaml Adds the fee override to a request shared by platform and agent quote endpoints, unintentionally broadening the advertised capability.
openapi/components/schemas/quotes/PlatformFeeOverride.yaml Defines the required fixed and variable fee override fields consistently with the stated optional request feature.
openapi.yaml Correctly bundles the new schema but consequently exposes it on every endpoint using QuoteRequest, including agent quote creation.
mintlify/openapi.yaml Mirrors the generated root bundle and publishes the same over-broad agent request contract.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  P[Platform caller<br/>BasicAuth] --> PQ[POST /quotes]
  A[Agent caller<br/>CREATE_QUOTES] --> AQ[POST /agents/me/quotes]
  PQ --> QR[Shared QuoteRequest]
  AQ --> QR
  QR --> F[platformFeeOverride]
  F --> C[Platform fee calculation]
Loading
Prompt To Fix All With AI
### Issue 1
openapi/components/schemas/quotes/QuoteRequest.yaml:70-71
**Agent fee authority is unguarded**

When an agent with `CREATE_QUOTES` calls `POST /agents/me/quotes`, the shared `QuoteRequest` advertises `platformFeeOverride` even though no agent permission grants fee control, causing either unauthorized platform-fee changes when honored or a broken generated-client contract when rejected. **How this was verified:** The agent endpoint references this shared request schema, while the complete agent permission enum contains no fee-management permission.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Reviews (1): Last reviewed commit: "feat(quotes): allow a per-transaction pl..." | Re-trigger Greptile

Comment thread openapi/components/schemas/quotes/QuoteRequest.yaml
Agent tokens carry no fee-control permission, so note that the field
must be omitted on agent-authenticated requests like POST /agents/me/quotes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Matches the server-side bound and the sibling TransactionFeeConfig
variableFeeBps constraint.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant