Wallet setup

bash
wasit wallet status [--role x402|mpp-charge] [--json]
wasit wallet create --role x402|mpp-charge|mpp-channel [--fund]
wasit wallet fund --role x402|mpp-charge [--asset xlm|usdc] [--amount <n>]

Testnet-only convenience commands for the payer keys the other subcommands read from .env — none of them take a --network flag, since Friendbot, the printed USDC issuer, and the whole idea of a disposable generated key only make sense on testnet.

status shows each configured role's on-chain balances (or "not yet created" for a key that has never been funded). create generates a new key and prints the exact .env line(s) to paste — it never writes to .env itself, so it can never overwrite something already there. mpp-channel generates a commitment key (a raw hex ed25519 seed that signs off-chain, not a funded account — see Configuration); x402 and mpp-charge generate a funded-account keypair. status and fund reject --role mpp-channel outright, since it has no account to inspect or fund.

A key that is set but malformed — a truncated paste, a G... public key, or a hex commitment seed in a Stellar-secret slot — is reported by name ("X is not a valid Stellar secret key") and exits 2, rather than surfacing as an SDK error. status with no --role reports it against that one role, still checks the other, and exits 0: one unchecked role is a row in a table. status --role answers one question, so it exits 2 whenever that role could not be checked — key not set, unreadable, or its balance lookup failed — and wasit wallet status --role x402 && … never goes ahead on an unchecked key. An account that has never been funded is an answer, and exits 0.

fund --asset xlm calls Stellar's public Friendbot directly and is fully automatic. fund --asset usdc creates a trustline to Circle's official testnet USDC issuer automatically, but actually receiving a balance always needs a human step: there is no scriptable, unauthenticated USDC faucet for Stellar. Either visit https://faucet.circle.com once yourself (paste the public key wasit wallet fund prints), or set WASIT_USDC_DISTRIBUTOR_SECRET in .env to an account you already funded that way — every run after that sends automatically from it.