aws / aws/agentcore-cli

project deploy cannot create payment credential providers; support Quick Create connectors first

Open
#2,095 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
283
Forks
95
Avg merge
1d 2h
Merged PRs (30d)
183

Description

## Summary

`agentcore project deploy` refuses any project declaring a `PaymentCredentialProvider` credential:

```
Error: Credential 'my-pay' is a PaymentCredentialProvider, which 'agentcore project deploy'
cannot create: CloudFormation has no payment credential provider resource, and a payment
provider needs vendor configuration (API key, wallet and authorization secrets) that
agentcore.json has no fields for. Remove the credential and any payment connector referencing
it to deploy the rest of the project.
```

That is deliberate — see #2089, which moved credential providers into CloudFormation. Failing fast beats half-creating a provider. This issue is the follow-up to actually support payments under `project deploy`.

A payment credential can only reach `agentcore.json` by hand today: `agentcore project add credentials` offers only `api-key` and `oauth`. So no documented flow produces this error yet.

## Two paths, and the cheap one is already released

### Quick Create — needs no credential provider at all

[agentcore-l3-cdk-constructs#324](https://github.com/aws/agentcore-l3-cdk-constructs/pull/324) ("feat(payments): support Quick Create connectors") is on the L3's `main` and shipped in `0.1.0-alpha.49`. A Quick Create connector needs **no** `credentialProviderArn` — the customer completes authorization out of band via a returned URL.

This is the path to do first. It closes the common case without touching the credential schema at all:

- make `credentialName` optional in `src/projectSchemas/payment.ts`
- add a Quick Create connector variant to the spec
- surface the returned `authorizationUrl` so the user knows how to finish setup
- `src/assets/cdk/lib/cdk-stack.ts` skips the credential-map lookup for those connectors

**Unverified:** whether Quick Create is Coinbase-specific. If StripePrivy has no Quick Create equivalent, it still needs the Manual path below. Confirm before scoping.

### Manual — needs real work

The Manual path is what the fail-fast message describes, and the gap is genuine:

1. **No CloudFormation resource.** Unlike `ApiKeyCredentialProvider` and `OAuth2CredentialProvider`, there is no payment credential provider type usable from the stack, so the pattern #2089 established (CFN owns the provider, the CLI syncs the secret post-deploy) does not apply.

2. **`PaymentCredentialSchema` has nowhere to put vendor configuration.** It carries only `{authorizerType, name, provider}`. The API wants vendor identifiers *and* secrets:
- CoinbaseCDP: API key ID + secret, wallet secret
- StripePrivy: app ID, authorization ID, and their secrets

The non-secret identifiers need schema fields. The secrets need the same `.env.local`-or-`secretRef` story the other two credential kinds have, which means extending `credentialEnvVarName` beyond its current one-suffix shape (`_CLIENT_SECRET`) to several per credential.

## Also worth deciding here

`agentcore project add credentials payment` does not exist. Whichever path lands, the credential should be creatable without hand-editing `agentcore.json`.

## Related

- #2089 — moves credential providers into CloudFormation; adds the fail-fast this issue removes
- #2093 — the original credential-deploy issue and its remaining open items

Contributor guide

Open the contributing guide

Research direction

Start with src/projectSchemas/payment.ts and src/assets/cdk/lib/cdk-stack.ts, then inspect the payment credential and connector flows behind `agentcore project add credentials`. Confirm whether Quick Create is available for each supported vendor, define how authorizationUrl and credential creation should work, and verify that `agentcore project deploy` handles the selected path without rejecting the payment connector.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
cli, cloud, payments
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.