DomGenie Payment Advisor
Payment-domain answers inside VS Code — ISO 8583, card-scheme rules, EMV, settlement, chargebacks, interchange — with a one-click Copy answer that pastes cleanly into Claude Code.
DomGenie advises. It does not touch your repository.
What it does
- Ask payment questions from a panel in the right-hand (secondary) side bar, next to Chat and Claude Code, without leaving the editor. Drag it elsewhere if you prefer; VS Code remembers where you put it.
- Ask about code you select, and only code you select.
- Read answers with their warnings and references so you can tell a firm rule from a scheme-specific caveat.
- Copy the last answer as Markdown and hand it to Claude Code as the domain context for an implementation prompt.
What it never does
DomGenie Payment Advisor is a read-only advisor. It does not:
- run Git commands, or read your branches, commits, remotes, or history;
- open a terminal, run a task, or start any process;
- create, edit, rename, or delete any file in your project;
- read your workspace. It never scans, indexes, or opens files.
The only content that ever leaves your machine is the question you type and, when you explicitly run DomGenie: Ask About Selected Code, the text you had selected. Nothing else — not the active file, not neighbouring files, not the project layout.
These are enforced by tests that fail the build if the shipped source so much as references a process, filesystem, or Git API. See src/test/safety.test.ts.
Because it reads nothing, the extension is enabled in restricted (untrusted) workspaces and virtual workspaces.
Commands
| Command |
What it does |
DomGenie: Open Q&A |
Focus the sidebar panel. |
DomGenie: Ask About Selected Code |
Prompt for a question and send it with the current editor selection. Cmd+Alt+D / Ctrl+Alt+D. |
DomGenie: Sign In |
Sign in in your browser (or store a company API key in API-key mode). |
DomGenie: Sign Out |
Erase the stored tokens and API key from the OS keychain. |
DomGenie: Copy Last Answer |
Put the last answer, with its warnings and references, on the clipboard as Markdown. |
Signing in
domgenie.authMode defaults to oauth, the browser sign-in below. Company-managed
installs can set it to apiKey instead: run DomGenie: Sign In and paste the key your
administrator issued. It is stored in the OS keychain and used only as:
POST https://domgenie.ai/api/v1/webhook/inbound
Authorization: Bearer dg-sk-...
Browser sign-in works the way Claude Code's does. It needs the
/v1/oauth/authorize and /v1/oauth/token endpoints and the site's
/oauth/authorize and /oauth/code pages deployed. Once they are live, set
domgenie.authMode to oauth and sign in as an individual:
- Run
DomGenie: Sign In. VS Code asks whether to open the sign-in link or
copy it. Either works: a copied link can be opened in any browser, on any
device. (The Copy link button in the DomGenie panel copies it too.)
- Sign in if you need to, then click Approve. The page shows a code.
- Paste the code into the field in the DomGenie panel and press Sign In.
You are signed in.
Under the hood this is an OAuth 2.0 authorization-code request with PKCE
(RFC 7636). The code the browser carries is useless on its own: redeeming it
needs a secret verifier that never leaves VS Code. Codes expire after five
minutes and work once.
Access and refresh tokens are stored only in VS Code SecretStorage, which is backed by the OS keychain (Keychain on macOS, Credential Manager on Windows, libsecret on Linux). They are never written to settings, workspace state, or a file on disk. DomGenie: Sign Out deletes both.
No shared API key is bundled in the published extension — one embedded in a VSIX could be extracted and abused by anyone who downloads it.
Settings
| Setting |
Default |
Purpose |
domgenie.apiBaseUrl |
https://domgenie.ai/api |
API origin (production). Versioned paths are appended by the extension. DEV: https://dev.domgenie.ai/api. |
domgenie.authorizeUrl |
https://domgenie.ai/oauth/authorize |
Browser page where you approve a sign-in. The code page for the copied link is /oauth/code on the same site. |
domgenie.clientId |
domgenie-vscode |
OAuth client id. The server only accepts this extension's callback for domgenie-vscode. |
domgenie.authMode |
oauth |
oauth for individual browser sign-in (default), apiKey for company-managed installs. |
domgenie.requestTimeoutSeconds |
120 |
Give up on a silent request after this long. |
Endpoints used
| Purpose |
Request |
| Sign-in page (browser) |
{authorizeUrl}?response_type=code&client_id=…&redirect_uri=…&code_challenge=…&code_challenge_method=S256&state=… |
| Token exchange |
POST {apiBaseUrl}/v1/oauth/token with grant_type=authorization_code |
| Ask |
POST {apiBaseUrl}/v1/oauth/ask |
| Models |
GET {apiBaseUrl}/v1/oauth/models |
| Identity |
GET {apiBaseUrl}/v1/oauth/whoami |
| Refresh |
POST {apiBaseUrl}/auth/refresh |
| Ask (API-key mode) |
POST {apiBaseUrl}/v1/webhook/inbound |
| Models (API-key mode) |
GET {apiBaseUrl}/v1/webhook/models |
The sign-in link returns to /oauth/code on the sign-in site, which shows the
code to paste. The server accepts that address, and the editor's
vscode://domgenie.domgenie-payment-advisor/auth-callback (which this version
no longer uses), only for domgenie-vscode.
Backend contract notes
Four things about the DomGenie backend are load-bearing and easy to get wrong:
Both ask endpoints read a single text field and ignore everything else.
Selected code therefore travels inside text, fenced and labelled with its
file — sending it as its own field would drop it silently.
Input is capped at 2,000 characters. The extension checks before sending
and names how far over you are, rather than surfacing a bare 422.
OAuth errors arrive as {"detail": {"error": "..."}}, since FastAPI
wraps HTTPException payloads in detail. Reading a top-level error would
make every failed exchange look like an unknown failure.
/auth/refresh is not under /v1. It is mounted at /auth (app.include_router(auth_router, prefix="/auth")), unlike the OAuth endpoints. The extension builds the two families of URL separately for this reason.
/auth/refresh reads the refresh token from a header named token, not Authorization, in the form Bearer <refresh_token>. It now rotates the pair and returns the replacement refresh_token alongside the new access_token; the extension stores both, and keeps the existing refresh token if a server predating that change returns only an access token.
domgenie-vscode is a registered OAuth client. The domgenie-cli client keeps
the device-code flow and cannot use browser sign-in, so a server that predates
/v1/oauth/authorize cannot sign this extension in. Use API-key mode against
it.
Privacy and terms
Questions and explicitly selected code are sent to the DomGenie API to produce an answer. Sign-in identity is used to authorise the request and count it against your quota. The extension collects no telemetry of its own.
Requirements
VS Code 1.106 or later, the first release that lets an extension add a panel to the secondary side bar. A DomGenie account, or a company-issued API key.
Support
Report problems to your DomGenie administrator or at https://domgenie.ai.