Hono recipe
Implement ATM checkout and signed webhook verification in a Hono app.
Compatible with the closed-beta ATM app APIs and versioned ATM event headers. Check atm-api-version on every webhook or XRPC receiver event.
Install SDK
Use Hono when your AT Protocol app is a small service with Web Request routes. The same app export can run in Node-compatible Hono deployments and inform Workers-style code.
npm install @atmosphere-money/app-node@beta honoCreate checkout route
Create an app order first, check the recipient's payout status, confirm creator app approval, then ask ATM to create the hosted checkout. The route returns only the checkout URL and token to the browser.
import { Hono } from "hono";
import { createAtmAppClient } from "@atmosphere-money/app-node";
const app = new Hono();
const atm = createAtmAppClient({
getServiceAuthToken: ({ lxm, aud }) => mintAppServiceAuthJwt({ lxm, aud })
});
app.post("/checkout", async (context) => {
const { recipientDid, amountCents } = await context.req.json();
const payout = await atm.getPayoutStatus(recipientDid);
if (!payout.payable) {
return context.json({ error: "RecipientNotPayable" }, 409);
}
const approval = await atm.requestRecipientApproval({
recipientDid,
environment: "test",
paymentTypes: ["shop"],
feeShareBps: 300,
requestReason: "Enable Hono checkout"
});
if (approval.status !== "approved") {
return context.json({
error: "RecipientAppApprovalRequired",
approvalUrl: approval.dashboardUrl
}, 409);
}
const order = await createAppOrder({ recipientDid, amountCents });
const checkout = await atm.initiatePayment({
environment: "test",
recipient: order.recipientDid,
amount: order.amountCents,
currency: "usd",
paymentType: "shop",
returnUrl: `https://app.example/orders/${order.id}/return`,
cancelUrl: `https://app.example/orders/${order.id}`,
metadata: { appOrderId: order.id }
});
return context.json({ url: checkout.url, token: checkout.token });
});Verify webhook or XRPC receiver
Fulfillment should come from verified ATM events. Signed HTTP webhooks are the default; XRPC receiver callbacks are optional for apps that already host an AT Protocol service surface.
import { createHonoWebhookHandler } from "@atmosphere-money/app-node";
app.post("/webhooks/atm", createHonoWebhookHandler({
secret: process.env.ATM_WEBHOOK_SECRET!,
expectedType: "payment.completed",
insertDeliveryIdOnce,
onEvent: async (event) => {
const metadata = event.data.payment.metadata as
| { appOrderId?: string }
| undefined;
const appOrderId = String(metadata?.appOrderId ?? "");
if (!appOrderId) return { status: 422, body: { error: "MissingAppOrderId" } };
await fulfillOrder(appOrderId, event.data.payment.id);
return { body: { ok: true } };
}
}));Fulfill payment or ticket
The fulfillment step is the same in Hono: deduplicate the ATM delivery id, map the ATM payment or ticket event back to your app order, write the app-side fulfillment state once, and store the ATM id for support and reconciliation.
- 01
Deduplicate
Insert the ATM delivery id with a unique constraint before side effects.
- 02
Match order
Read appOrderId, ticket hold id, listing ref, or another private app correlation id from event metadata.
- 03
Fulfill
Grant access, issue app content, reveal tickets, update a subscription, or notify the buyer.
- 04
Reconcile
Store the ATM payment id and event id beside the app order for refunds, disputes, and redrive.
Run local test fixture
Use the runnable starter when one exists, or generate a signed webhook fixture with @atmosphere-money/testing. Your test should prove raw-body verification, duplicate delivery handling, and the app fulfillment mutation.
cd examples/atm-hono-worker-starter
npm install
npm run typecheck
npm run smokeRuntime notes
| Starter | examples/atm-hono-worker-starter is the lightweight starter checked in CI. |
|---|---|
| Web Request | The helper reads context.req.raw, so signed verification sees the original Request body. |
| Workers | For Cloudflare Workers, use the Workers page when you need platform-specific env and storage guidance. |