Interactive mode

Running wasit with no subcommand at all, in a real terminal, opens a small menu instead of printing help:

bash
wasit

The menu screen shows which environment variables are already set (STELLAR_PRIVATE_KEY, MPP_PAYER_SECRET, COMMITMENT_SECRET_HEX) before you pick anything, so a missing key is visible up front rather than discovered after typing a target URL. Pick x402 (read-only checks), MPP channel (non-destructive checks), MPP charge, or browse the check catalogue, then type a target URL. Each action reuses the same environment-variable defaults as the matching subcommand below.

This is deliberately narrower than the subcommands themselves: no X402-06–10 payment checks, no --allow-destructive, no header/method/body overrides, no --json. Anything past "run the safe default checks and read the result" still goes through the direct subcommand — wasit test --payer-key ..., wasit mpp-channel --allow-destructive ..., and so on. MPP charge always settles a real payment (it has no read-only mode), so picking it asks for an explicit confirmation before anything runs.

Keys: arrows + Enter to move and select, Esc to go back, q to quit from any screen without a text field, Ctrl+C to quit immediately from anywhere, including mid-keystroke while typing a target URL. Once a run finishes, s saves its results as JSON (the same shape as --json below) to wasit-<protocol>-<timestamp>.json in the current directory.

A run in progress shows a live elapsed timer next to the spinner; the summary line at the end adds the total run time and the average time per check. A missing key or an invalid target is reported as its own focused error screen rather than a stack trace, since no check ever ran.

"Manage testnet wallets" on the menu opens the same generate/fund flow as wasit wallet below, but interactively: it shows all three roles' status up front, and after generating a key it asks whether to save it straight to .env (updating the running process's environment immediately, so the menu reflects it without restarting wasit) or just display it for you to copy. The .env it writes is the one in the directory wasit was started from, written atomically and with owner-only permissions (0600).

A generated secret is shown on screen in both cases — skip this screen if you are recording your terminal.

Piping wasit into something else, or running it in CI, does not open the menu — it falls back to printing help, exactly as before this existed.