What is x402? HTTP 402 payments for APIs and AI agents
x402 is an open protocol that lets an API charge for a request with HTTP itself. The server answers 402 Payment Required with a price, the client pays with a signed stablecoin transfer and retries, and the server serves the response once the payment settles. No account, no API key, no subscription.
What x402 is
HTTP has reserved status code 402 Payment Required since the 1990s without ever saying how to pay. x402 fills that gap. It defines what a 402 response contains (the price, the network, the token and the address to pay), how a client attaches a payment to its retry, and how the server confirms the payment before it responds.
It is built on ordinary HTTP headers carrying base64-encoded JSON, so it works with any language, framework or proxy that can read and set headers.
Why AI agents need it
- No sign-up. An agent can't fill in a registration form or wait for an API key. With x402 it reads the price from the 402 and pays.
- Pay per request. Prices can be fractions of a cent, so you can charge for exactly what is used instead of selling plans.
- Machine-readable. The requirements are structured JSON, so a client can compare prices and decide on its own.
- Settles directly. Funds move from the payer's wallet to yours, with no invoices, chargebacks or payout schedule.
How a paid request works
- The client calls your endpoint, for example
GET /premium-data. - Your server answers
402with aPAYMENT-REQUIREDheader listing what itaccepts: scheme, network, amount in the token's smallest unit, token contract andpayToaddress. - The client picks an option and signs a payment for exactly that amount. On EVM chains this is an EIP-3009
transferWithAuthorizationsigned with EIP-712; nothing is sent on chain yet. - The client retries the same request with the signed payment in a
PAYMENT-SIGNATUREheader. - Your server asks a facilitator to verify the signature, runs your handler, and asks the facilitator to settle, which submits the transfer on chain.
- Your server responds
200with the resource and aPAYMENT-RESPONSEheader holding the settlement receipt and transaction hash.
If anything fails, such as insufficient funds or a bad signature, the server answers 402 again with a reason and the resource is not served.
Headers
Protocol version 2 carries everything in headers. Version 1, still read by many servers, put the requirements in the 402 body.
| Purpose | v2 header | v1 |
|---|---|---|
| Price and payment options (server โ client) | PAYMENT-REQUIRED | 402 response body |
| Signed payment (client โ server) | PAYMENT-SIGNATURE | X-PAYMENT |
| Settlement receipt (server โ client) | PAYMENT-RESPONSE | X-PAYMENT-RESPONSE |
Networks are written as CAIP-2 identifiers: eip155:8453 is Base, eip155:84532 is Base Sepolia. Amounts are strings in atomic units: with USDC's 6 decimals, 10000 is $0.01.
Where the money goes
Straight from the payer to the address in payTo. The payer's signature authorizes one transfer of one amount to one address within a time window, and the token contract refuses to execute the same authorization twice. Your server only needs your receiving address, never a private key, and no third party holds the funds in between.
Facilitators
A facilitator is a service your server calls to check payments and put them on chain. It exposes /verify, /settle and /supported. For EIP-3009 transfers the facilitator submits the transaction and pays the gas, so neither you nor the payer needs native tokens. You can use a hosted facilitator, such as the public one at x402.org/facilitator for testnets or Coinbase Developer Platform's, or run your own.
Testnet and mainnet
Build and test on a testnet, where tokens are free from a faucet and have no value: Base Sepolia (eip155:84532) is the usual choice. Switch to a mainnet such as Base (eip155:8453) when you are ready to take real payments. Requestway keeps the two apart, so test traffic never shows up as earnings.
Add it to your API
Laravel: requestway/laravel-x402 protects a route in one line, with observe mode for measuring demand before you charge.
Route::get('/premium-data', PremiumDataController::class)->middleware('x402:0.01');
Node: the official @x402/express, @x402/next and @x402/hono middleware do the same, and @requestway/reporter reports the outcomes.
Test and measure
Once a route charges, two questions follow: does payment actually work, and what is it earning? Requestway answers both for free. Its endpoint tester pays your route with test USDC and walks through every step of the exchange, and its dashboard shows earnings per route, failed payments by reason, and in observe mode, the demand you aren't charging for yet.
Create a free account or read the install guide.
FAQ
Is x402 a blockchain?
No. x402 is an HTTP protocol. Payments settle on an existing chain, most often as USDC on Base, but the client and server only exchange HTTP headers.
Who holds the money?
Nobody in the middle. The payer signs an authorization to transfer tokens straight to the address in payTo, and the facilitator submits it on chain. Your API never needs a private key.
Does x402 charge a fee?
The protocol itself has no fee. A facilitator may charge for verifying and settling payments, and the chain has gas costs that the facilitator pays for EIP-3009 transfers, so check your facilitator's terms.
Can people use x402, or only AI agents?
Anyone with a wallet and a client that speaks x402. It suits agents best, because a program can read a 402, decide and pay without a sign-up form or a stored card.
What happens if a payment fails?
The server answers 402 again with a reason, such as insufficient_funds or an invalid signature, and does not serve the resource. Nothing is charged.
How do I test without spending money?
Run your API on a testnet such as Base Sepolia (eip155:84532) and pay with test USDC from a faucet. Requestway's endpoint tester does this for you and shows each step.