Docs

Express recipe

Implement ATM checkout and signed webhook verification in an Express app.

Closed beta@atmosphere-money/app-nodeSDK beta: 0.0.0-beta.3ATM API beta: 2026-0671 published lexicons

Compatible with the closed-beta ATM app APIs and versioned ATM event headers. Check atm-api-version on every webhook or XRPC receiver event.

Install SDK

Use normal JSON parsing for your checkout route, but preserve the raw request body for ATM webhook verification.

sh
npm install @atmosphere-money/app-node@beta express

Create checkout route

Create an app order first, check the recipient's payout status, confirm creator app approval, then ask ATM to create the hosted checkout. Persist ATM's app status token beside the order before returning only the checkout URL to the browser. The URL contains a separate browser bearer.

ts
import express from "express";
import { createAtmAppClient } from "@atmosphere-money/app-node";

const app = express();
app.use("/checkout", express.json());

const atm = createAtmAppClient({
  getServiceAuthToken: ({ lxm, aud }) => mintAppServiceAuthJwt({ lxm, aud })
});

app.post("/checkout", async (req, res) => {
  const { recipientDid, amountCents } = req.body;
  const payout = await atm.getPayoutStatus(recipientDid);
  if (!payout.payable) {
    return res.status(409).json({ error: "RecipientNotPayable" });
  }

  const approval = await atm.requestRecipientApproval({
    recipientDid,
    environment: "test",
    paymentTypes: ["shop"],
    feeShareBps: 300,
    requestReason: "Enable Express checkout"
  });
  if (approval.status !== "approved") {
    return res.status(409).json({
      error: "RecipientAppApprovalRequired",
      approvalUrl: approval.dashboardUrl
    });
  }

  const order = await createAppOrder({ recipientDid, amountCents });
  const checkout = await atm.initiatePayment({
    environment: "test",
    recipient: order.recipientDid,
    amount: order.amountCents,
    currency: "usd",
    paymentType: "shop",
    returnUrl: `https://app.example/orders/${order.id}/return`,
    cancelUrl: `https://app.example/orders/${order.id}`,
    metadata: { appOrderId: order.id }
  });

  await saveAtmStatusToken(order.id, checkout.token);
  res.json({ url: checkout.url });
});

Add event receiver

New AT Protocol-native apps use the canonical#AtmEventReceiver / money.atmosphere.event.receiveEvent wake-up transport. A conventional web app can explicitly select the signed HTTP webhook compatibility path shown by this framework recipe. Verify the configured receiver before using it to wake an immediate canonical status/query read.

ts
import { createExpressWebhookHandler } from "@atmosphere-money/app-node";

const atmWebhook = createExpressWebhookHandler({
  secret: process.env.ATM_WEBHOOK_SECRET!,
  expectedType: "payment.completed",
  deliveryStore: {
    claim: claimWebhookDelivery,
    complete: completeWebhookDelivery,
    release: releaseWebhookDelivery
  },
  onEvent: async (event) => {
    const metadata = event.data.payment.metadata as
      | { appOrderId?: string }
      | undefined;
    const appOrderId = String(metadata?.appOrderId ?? "");
    if (!appOrderId) return { status: 422, body: { error: "MissingAppOrderId" } };

    await fulfillOrder(appOrderId, event.data.payment.id);
    return { body: { ok: true } };
  }
});

app.post(
  "/webhooks/atm",
  express.raw({ type: "application/json" }),
  atmWebhook
);

Fulfill payment or ticket

The fulfillment step is the same in Express: poll with the stored status handle, map the completed ATM payment back to your app order, and write the app-side fulfillment state once. Deduplicate each receiver delivery id before waking the same poller.

  1. 01

    Deduplicate

    Apply the same completed status once; optionally claim a push delivery id before waking reconciliation.

  2. 02

    Match order

    Load the app order that stores the initiation status token and private correlation data.

  3. 03

    Fulfill

    Grant access, issue app content, reveal tickets, update a subscription, or notify the buyer.

  4. 04

    Reconcile

    Store canonical ATM state and any optional event id beside the app order for refunds and disputes.

Run local test fixture

Use the runnable starter when one exists. Your core test should prove status-token persistence, authenticated polling, duplicate terminal handling, and the app fulfillment mutation. If you enable push, also generate a signed fixture with@atmosphere-money/testing and prove raw-body verification plus duplicate delivery handling.

sh
node --test test/atm-webhook.test.js
# or use @atmosphere-money/testing to create a signed payment.completed fixture

Runtime notes

Raw bodyMount express.raw() on /webhooks/atm before any JSON parser touches that route.
Snippetdocs/developer/examples/express-webhook-route.ts is the copyable route example.
Starter statusExpress has a recipe and snippet; promote to a runnable starter only if beta testers need it.