x402 Protocol
x402 explained: the HTTP 402 payment flow, facilitators, supported networks, Linux Foundation governance and the security issues to check before you go live.
What is x402?
The x402 protocol turns the old HTTP 402 “Payment Required” status code into a working way for AI agents to pay for API access, digital content, and computational resources in the same request-response loop they already use. No accounts, no API keys, no invoices.
Coinbase built it in 2025. Since July 2026 it has been governed by the x402 Foundation at the Linux Foundation, alongside Cloudflare, Google, Stripe, Visa, Mastercard, AWS and others. That matters if you are choosing a protocol: x402 is now a neutral standard rather than one company’s product, and the first serious attempt to standardize machine-to-machine payments at the HTTP layer.
How x402 Works
The flow in the current spec (v2) looks like this:
- The agent requests a resource with a normal HTTP request.
- The server answers 402 and puts the price, asset, network and payee in a
PAYMENT-REQUIREDheader. - The agent signs a payment authorization (for example an EIP-3009 transfer, so it does not need gas).
- The agent retries with a
PAYMENT-SIGNATUREheader carrying the signed payload. - A facilitator verifies and settles the payment through its
/verifyand/settleendpoints. - The server returns 200 with the resource and a
PAYMENT-RESPONSEheader describing the settlement.
If you see X-PAYMENT in your code, that is the v1 header. v2 servers and clients need a migration.
Key Technical Details
- Payment schemes:
exact(fixed price),upto(pay up to a ceiling, useful for metered work) andbatch-settlementon EVM - Networks: Base, Polygon, Arbitrum, Solana, Stellar, Aptos and more through the SDKs
- Assets: USDC dominates, but any EIP-3009 or Permit2 token on EVM and SPL tokens on Solana work
- Facilitators: hosted (Coinbase CDP, PayAI, Fireblocks and others) or self-hosted
- Network IDs: CAIP-2 format in v2
How Much Is Actually Flowing?
Less than the headlines suggest, but the trend is real. Visa’s onchain analysis counted about 109.6 million x402 transactions and roughly $15 million in adjusted volume from launch in May 2025 to April 2026, after removing wash and test activity. Self-reported dashboards show bigger numbers. Plan for a protocol that is growing quickly from a small base.
Security Issues to Check Before You Go Live
A May 2026 paper, Five Attacks on x402 Agentic Payment Protocol, tested three open-source SDKs and four live endpoints and found 11 vulnerabilities. The five classes are worth checking in your own stack:
- Revert-grant: the server releases the resource before the payment is final.
- Settlement preemption: someone settles the agent’s authorization first, so the agent pays and gets nothing.
- Replay and idempotency: one payment is reused across retries or parallel requests. One live endpoint granted 248 resources for a single payment.
- Proxy and header confusion: a CDN or proxy caches a paid response and serves it to clients who never paid.
- Server selection: fake listings steer agents toward attacker-controlled servers.
Spending limits are the other gap. A facilitator verifies each payment on its own, so 500 individually valid payments in an hour all pass. Budgets and rate limits across payments have to live in your agent or wallet layer.
We test for all of this in our agentic payment security audit. For a broader checklist, see our agentic payment security guide. We are also building a free x402 endpoint checker that tests for replay, caching and settlement-order bugs automatically.
Use Cases
- API monetization: charge per request for data feeds, model inference and compute
- Content access: agents pay for premium research and content
- Agent-to-agent payments: services that bill each other without a human in the loop
- Micropayments: sub-cent payments that card rails cannot handle
Our x402 Services
- x402 implementation: server gating, agent clients, facilitator setup
- Security audit: replay, settlement, caching and spend-control review
- Protocol selection: x402 vs MPP vs card-based flows, see our protocol comparison
Last updated October 9, 2026
Frequently Asked Questions
Who owns the x402 protocol?
Nobody owns it outright any more. Coinbase created x402 and contributed it to the Linux Foundation. The x402 Foundation launched operationally on July 14, 2026, with Premier members including Coinbase, Cloudflare, Google, Stripe, Visa, Mastercard and AWS. The canonical repo is github.com/x402-foundation/x402.
Is x402 only for USDC on Base?
No. Base is the busiest network, but the SDKs support EVM chains, Solana, Stellar, Aptos, Algorand, TON and Hedera. Any token that supports EIP-3009 or Permit2 on EVM, and SPL tokens on Solana, can be used. USDC still carries most of the volume.
What changed in x402 v2?
v2 renamed the headers (PAYMENT-REQUIRED, PAYMENT-SIGNATURE and PAYMENT-RESPONSE replace X-PAYMENT and X-PAYMENT-RESPONSE), moved to CAIP-2 network identifiers, and added extensions such as discovery and wallet-based sessions. If your code still reads X-PAYMENT, you are on v1.
Do I need to run my own facilitator?
Not to start. Hosted facilitators exist, including Coinbase CDP (free for the first 1,000 transactions a month, then $0.001 each) and PayAI. Teams run their own when they need a specific network, data residency, or no dependency on a third party for settlement.
Is x402 secure enough for production?
It is running in production today, but the details matter. A May 2026 study found 11 vulnerabilities across three open-source x402 SDKs and four live endpoints, including one endpoint that granted 248 resources for a single payment. Check replay protection, settlement timing and caching before you launch.
Get Started for Free
Schedule a free consultation with our payment infrastructure team. 30-minute call, actionable results in days.
Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian
Talk to an Expert