IMD Flow separates asset acquisition from IdentityMD settlement. The router knows an output amount, not the price or meaning of an action.
Release status: the implementation has local and mainnet-fork verification. A production router address and live acceptance result are not yet available. Do not substitute a local deployment address on Ethereum.
Architecture
- Read
/requests/capabilitiesand the current/openapi.jsonfrom the official IMD API. - Validate the
job.openrequest using/requests/check, then create its quote using/requests/quote. - Read the payer's IMD balance and compute the shortfall using integer token units.
- Quote exact-output ETH acquisition for that shortfall through the configured POOL4 market.
- Ask the connected wallet to confirm the swap, then verify its receipt and new IMD balance.
- Prepare the current x402 challenge and same-payer QuoteApproval.
- Obtain explicit wallet authorizations and a separate final payment confirmation.
missingIMD = max(requiredIMD - currentIMD, 0)
Router interface
function buyIMDWithETH(
uint256 imdAmountOut,
uint256 maxEthIn,
address recipient,
uint256 deadline
) external payable returns (uint256 ethSpent);
Send msg.value equal to maxEthIn. In the checkout, the recipient is the connected payer. Unused input is refunded to the caller. Enforce the correct network and verify deployed runtime code before preparing a real transaction.
Payment boundary
ETH acquisition does not bypass IMD. IdentityMD settles IMD from the payer's wallet using its existing x402 flow. The wallet that signs Permit2 must also sign QuoteApproval.
Validate asset, amount, payTo, quoteHash, resource, network and expiry against the current challenge. Derive the authorization window from maxTimeoutSeconds and verify that it fits strictly inside the quote expiry. Do not invent a deadline by subtracting a fixed number from quote expiry.
The Next.js API routes forward supported requests; they do not sign payments. Keep private keys out of the browser app's configuration and backend. Preserve the existing restrictions on methods, paths, request sizes and wallet context.
Recovery
Persist order identity and transaction references before continuing. For an uncertain signed submission, recover the same order and payload rather than creating a second payment. Do not reset unresolved payment state. A confirmed admitted job permits an explicit new order with fresh authorizations.
Scope
V1 supports Ethereum, ETH input and job.open. It does not implement USDC input, escrow, protocol fees, smart accounts or a project token. See the integration reference, architecture and deployment guide for implementation details.