Agent readinessโ€ขSeptember 28, 2026

    x402: Letting AI Agents Pay for Your Content or API

    HTTP 402 payments for agents: how the flow works, the discovery manifest we check for, and what you need to charge per request.

    What we check

    We fetch /.well-known/x402.json. It passes when the response is JSON and has any of: an x402Version (or x402_version) field, a non-empty resources array, or an accepts array. The manifest is how an agent learns which of your resources it can pay for, without probing every URL.

    How x402 works

    HTTP has had a status code for "Payment Required", 402, since 1997, but nothing standard said what came next. x402 fills that in:

    1. An agent requests a paid resource.
    2. Your server answers 402 Payment Required with the price and payment instructions.
    3. The agent pays, typically in a stablecoin, and retries the request with proof of payment.
    4. Your server verifies the payment and returns the resource.

    There is no account, API key or sign-up step. Coinbase open-sourced the protocol in 2025, and several CDNs and payment providers now offer it as a feature.

    Who it suits

    x402 fits anything you would sell per request: API calls, datasets, reports, or premium content. If your content is free, or you sell subscriptions to people rather than requests to machines, you do not need it.

    What you need

    • A price for each payable route.
    • A 402 response on those routes that carries the payment details, instead of a generic paywall page or login redirect.
    • Payment verification when the agent retries. A facilitator service can handle the on-chain part for you.
    • The discovery manifest at /.well-known/x402.json.

    A manifest entry describes each resource and what you accept for it:

    {
      "x402Version": 1,
      "resources": [
        {
          "resource": "https://api.acme.com/v1/reports",
          "description": "One market report, JSON.",
          "accepts": [
            { "scheme": "exact", "network": "base", "maxAmountRequired": "50000", "payTo": "0xYourAddress" }
          ]
        }
      ]
    }

    Check the x402 specification for the current field names before you publish. The protocol is young and its schema has changed between versions.

    ๐Ÿ’ก Quick win

    If you already protect an endpoint with an API key, put x402 in front of that one endpoint first. It is a payment layer in front of an API you already have, and you can learn what agents will pay before pricing anything else.

    Was this article helpful?