8ec6286ff7
Signed /api/moonpay-url endpoint: public key from MOONPAY_PUBLIC_KEY env or site config, SECRET from MOONPAY_SECRET_KEY env ONLY (never site config, since /api/config exposes siteConfig). Wallet-prefilled signed MoonPay URL when keys are set, else a generic buy page. "Buy POL with a card" button under the Buy packages tiles. Zero custody: MoonPay is merchant of record; crypto goes straight to the buyer's wallet. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>