How x402 works
HTTP has had the 402 Payment Required status code since the 1990s, yet the standard still describes it as reserved for future use — no common payment scheme ever sat behind it. x402 fills that gap: payment becomes part of the normal request–response cycle, with no accounts, forms or API keys. The protocol has three roles: the client (an application or an AI agent), the server holding the paid resource, and the facilitator — a service that verifies the payment and settles it on-chain.
| Step | Direction | What happens |
|---|---|---|
| 1 | Client → server | An ordinary request for a resource, e.g. GET /api/prices |
| 2 | Server → client | A 402 response with a PAYMENT-REQUIRED header: amount, asset, network, recipient |
| 3 | Client → server | The request is retried with a PAYMENT-SIGNATURE header — the signed payment |
| 4 | Server ↔ facilitator | Payment verification (/verify) and on-chain settlement (/settle) |
| 5 | Server → client | A 200 response with the resource and a PAYMENT-RESPONSE header confirming settlement |
That is version 2 of the protocol. In version 1 the payment terms travelled in the body of the 402 response, the payment in an X-PAYMENT header and the confirmation in X-PAYMENT-RESPONSE. Header contents are Base64-encoded JSON. The settlement method is set by a scheme: exact for a fixed amount, upto for usage-based payment within a limit, and batch-settlement for settling repeated requests in batches.
Where it is used
- Paid APIs. A service charges per call, and the agent needs neither an account nor a stored key.
- Content and data per item. The example in the x402 documentation is paying one dollar to read a single article.
- Agent tools. Besides HTTP, the specification defines transports for MCP and A2A: a paid tool answers the agent with a payment request.
- Pay per crawl. In September 2025 Cloudflare proposed a deferred settlement scheme for charging AI crawlers that visit sites.
Status as of September 2026
x402 is developed by the x402 Foundation under Linux Foundation governance; the Coinbase repository is now only a development fork of the main one. Stripe accepts x402 payments alongside its own MPP, and Google connected x402 to its AP2 through the A2A x402 extension. The protocol is designed to be network- and currency-agnostic, but in practice it means stablecoins on EVM chains, Solana and other blockchains.
What it means for a store
- A shopper’s basket does not need x402: orders from AI agents go through checkout protocols such as ACP and UCP and the card infrastructure.
- If you sell data — prices, availability, content — x402 lets you charge machines without a contract or a customer account.
- If AI crawlers put load on your site, keep an eye on pay-per-crawl models: x402 is one of the candidates for a standard way to charge for them.
- Keep the layers apart: x402 answers “how do I pay for a request”, not “how do I place an order”.
Important: x402 settles in stablecoins by default, so before experimenting check that such payments are permitted in your jurisdiction and workable for your accounting.