Skip to content

Clarify Vault payment security guidance - #560

Merged
AnnaXWang merged 4 commits into
mainfrom
hypeship/clarify-vault-launch-docs
Sep 10, 2026
Merged

Clarify Vault payment security guidance#560
AnnaXWang merged 4 commits into
mainfrom
hypeship/clarify-vault-launch-docs

Conversation

@AnnaXWang

@AnnaXWang AnnaXWang commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Summary

  • rename "stripe link" to "link by stripe" across the docs, including the navigation title
  • document how Link credentials, Agentcard cards, Vault metadata, and action URLs are handled
  • replace blanket PCI scope claims with qualified guidance

Testing

  • mint broken-links
  • ran the local docs preview and verified the four affected routes returned HTTP 200

Note

Low Risk
Documentation-only changes to naming and compliance/security wording; no runtime or API behavior changes.

Overview
This PR updates Vault and browser-agent payment docs to use link by stripe (and shorter link) instead of stripe link, including the stripe-link page title and comparison tables, CLI prompts, and cross-links.

It replaces absolute PCI DSS scope claims with wording that focuses on not exposing card number/CVC and on reducing exposure rather than guaranteeing out-of-scope status.

Security handling is spelled out more explicitly: Link OAuth and one-use card data are described as KMS-backed envelope encryption; Agentcard is clarified as keeping the underlying card with Agentcard; Vault API responses still exclude sensitive values; and action URLs are framed as short-lived bearer links that must stay out of logs and model context.

Reviewed by Cursor Bugbot for commit 3e3becd. Bugbot is set up for automated code reviews on this repo. Configure here.

@mintlify

mintlify Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
Kernel 🟢 Ready View Preview Sep 10, 2026, 2:53 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
cursor[bot]
cursor Bot approved these changes Sep 10, 2026
Comment thread integrations/payments/overview.mdx Outdated
Comment thread vaults.mdx Outdated
Comment thread vaults.mdx Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Very Low

Decision: Keep existing approval (risk did not increase)

Re-evaluated after the latest push (91e4be94). This automation already approved c3f2ce9c as Very Low. The new commit only edits one sentence in integrations/payments/overview.mdx (PCI wording: “may help limit… confirm with your QSA” → “avoids expanding pci dss scope”).

The full diff is still four Mintlify .mdx pages (browsers/enable-payments-in-browser-agent.mdx, integrations/payments/overview.mdx, integrations/payments/stripe-link.mdx, vaults.mdx). No application code, config, CI, infrastructure, or docs.json changes. No CODEOWNERS file is present.

Scope remains a product-name rename (stripe linklink by stripe) plus documentation wording for vault/payment security guidance. That does not change production logic, auth, billing, or shared services. Blast radius is published docs copy only.

Risk stays Very Low. Approval is unchanged.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

Comment thread vaults.mdx Outdated
Comment thread integrations/payments/stripe-link.mdx Outdated
Comment thread integrations/payments/stripe-link.mdx Outdated
Comment thread integrations/payments/stripe-link.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread integrations/payments/overview.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Comment thread browsers/enable-payments-in-browser-agent.mdx Outdated
Co-authored-by: Anna Wang <annawangx@gmail.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Very Low

Decision: Keep existing approval (risk did not increase)

Re-evaluated after 3e3becd (“Apply batched suggestions from code review”). This automation already approved c3f2ce9c as Very Low.

The new commit only edits the same four Mintlify .mdx pages:

  • browsers/enable-payments-in-browser-agent.mdx
  • integrations/payments/overview.mdx
  • integrations/payments/stripe-link.mdx
  • vaults.mdx

Changes vs the last assessed commit (91e4be94) are documentation copy: shorten “link by stripe” to “link” in running text, and drop a paragraph in vaults.mdx that warned against storing secrets in item metadata. No application code, docs.json, CI, config, or infrastructure files changed. No CODEOWNERS file is present.

Full PR scope remains published docs (product-name wording plus vault/payment security guidance). That does not change production logic, auth, billing, or shared services. Blast radius is docs copy only.

Risk stays Very Low. Approval is unchanged.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk assessment: Very Low

Decision: Keep existing approval (risk did not increase)

Re-evaluated after the latest push (3e3becda). This automation already approved c3f2ce9c as Very Low and kept that approval on 91e4be94.

The new commit is still documentation-only: it shortens remaining link by stripe mentions to link across the same four Mintlify .mdx pages (browsers/enable-payments-in-browser-agent.mdx, integrations/payments/overview.mdx, integrations/payments/stripe-link.mdx, vaults.mdx) and trims one paragraph of vault-metadata guidance. No application code, config, CI, infrastructure, or docs.json changes. No CODEOWNERS file is present.

The full diff remains a product-name rename plus published security/compliance wording. That does not change production logic, auth, billing, or shared services. Blast radius is docs copy only.

Risk stays Very Low. Approval is unchanged.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@AnnaXWang
AnnaXWang merged commit b8f7dcc into main Sep 10, 2026
4 checks passed
@AnnaXWang
AnnaXWang deleted the hypeship/clarify-vault-launch-docs branch September 10, 2026 04:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant