X402 Payments: Install, Source and Security | FunnelSlayer

X402 Payments

Published by aznatkoiny in zai-skills

Review recommended19 installs

What this skill does

|

Add X402 Payments to your agent

Review the source and files first. When you are ready, copy the prompt instruction or use the CLI command supported by your environment.

Install with a prompt

Paste this into a compatible coding agent:

add this skill "x402-payments" from https://github.com/aznatkoiny/zai-skills

Install with the CLI

Run this command in a controlled environment after reviewing the repository:

npx skills add https://github.com/aznatkoiny/zai-skills --skill x402-payments

Skill instructions

x402 Protocol Skill

Facts current as of July 2026 — verify pricing and model IDs against https://docs.claude.com, and protocol/package details against the x402 docs.

Protocol Overview

x402 embeds stablecoin payments into HTTP by using the 402 "Payment Required" status code. A server responds with payment requirements; the client signs a payment authorization, resubmits the request, and gets the resource after verification and settlement.

Payment flow:

  1. Client sends HTTP request → Server returns 402 + PAYMENT-REQUIRED header (base64 JSON)
  2. Client reads requirements, creates signed payment payload
  3. Client resubmits request with PAYMENT-SIGNATURE header (base64 JSON)
  4. Server verifies payment via facilitator POST /verify
  5. Server performs work, settles via facilitator POST /settle
  6. Server returns 200 + resource + PAYMENT-RESPONSE header (contains txHash)

Key concepts:

  • Facilitators verify and settle payments without holding funds. Use https://x402.org/facilitator for testnet, CDP facilitator for mainnet.
  • Schemes: exact (fixed price per request) is the production scheme. upto and deferred are proposed.
  • Networks: Identified by CAIP-2 format — eip155:84532 (Base Sepolia), eip155:8453 (Base Mainnet), solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1 (Solana Devnet).
  • EVM uses EIP-3009 gasless TransferWithAuthorization. Solana uses SPL token transfers.

Quick-Start: Protect an API Endpoint (Seller)

npm install @x402/express @x402/core @x402/evm
import express from "express";
import { paymentMiddleware } from "@x402/express";
import { x402ResourceServer, HTTPFacilitatorClient } from "@x402/core/server";
import { registerExactEvmScheme } from "@x402/evm/exact/server";

const app = express();
const payTo = process.env.PAY_TO!;

const facilitatorClient = new HTTPFacilitatorClient({
  url: "https://x402.org/facilitator",
});
const server = new x402ResourceServer(facilitatorClient);
registerExactEvmScheme(server);

app.use(
  paymentMiddleware(
    {
      "GET /weather": {
        accepts: [
          { scheme: "exact", price: "$0.001", network: "eip155:84532", payTo },
        ],
        description: "Get current weather data",
        mimeType: "application/json",
      },
    },
    server,
  ),
);

app.get("/weather", (req, res) => {
  res.json({ weather: "sunny", temperature: 70 });
});

app.listen(4021, () => console.log("Server on :4021"));

Quick-Start: Pay for x402 Resources (Buyer/Agent)

npm install @x402/fetch @x402/core @x402/evm viem
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client, x402HTTPClient } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const signer = privateKeyToAccount(process.env.EVM_PRIVATE_KEY as `0x${string}`);
const client = new x402Client();
registerExactEvmScheme(client, { signer });

const fetchWithPayment = wrapFetchWithPayment(fetch, client);

const response = await fetchWithPayment("http://localhost:4021/weather");
const data = await response.json();
console.log(data);

// Read payment receipt
const httpClient = new x402HTTPClient(client);
const receipt = httpClient.getPaymentSettleResponse(
  (name) => response.headers.get(name),
);
console.log("Tx:", receipt?.txHash);

Decision Tree

DecisionChoicePackages
Server: ExpresspaymentMiddleware from @x402/express@x402/express @x402/core @x402/evm
Server: Next.jspaymentProxy from @x402/next@x402/next @x402/core @x402/evm
Server: HonopaymentMiddleware from @x402/hono@x402/hono @x402/core @x402/evm
Client: fetchwrapFetchWithPayment@x402/fetch @x402/core @x402/evm viem
Client: axioswrapAxiosWithPayment@x402/axios @x402/core @x402/evm viem axios
Client: manualx402Client + x402HTTPClient from @x402/core@x402/core @x402/evm viem
Chain: EVMregisterExactEvmScheme@x402/evm + viem
Chain: SolanaregisterExactSvmScheme@x402/svm + @solana/kit @scure/base
Chain: bothRegister both schemes on same client/serverAll chain deps
Env: testingFacilitator https://x402.org/facilitatorBase Sepolia / Solana Devnet
Env: productionCDP facilitator + API keysBase Mainnet / Solana Mainnet
Agent: MCPMCP server with @x402/axiosSee references/agentic-patterns.md
Agent: AnthropicTool-use with @x402/fetchSee references/agentic-patterns.md

Reference File Navigation

TaskRead this file
Headers, payloads, CAIP-2 IDs, facilitator API, V1→V2 changesreferences/protocol-spec.md
Express / Hono / Next.js middleware, multi-route, dynamic pricingreferences/server-patterns.md
Fetch / axios client, wallet setup, lifecycle hooks, error handlingreferences/client-patterns.md
AI agent payments, MCP server, tool discovery, budget controlsreferences/agentic-patterns.md
Testnet→mainnet migration, CDP keys, faucets, security, sessionsreferences/deployment.md

Critical Implementation Notes

  1. Register schemes before wrapping fetch/axios — order matters.
  2. Two equivalent registration APIs:
    • Function: registerExactEvmScheme(server) / registerExactEvmScheme(client, { signer })
    • Method: server.register("eip155:84532", new ExactEvmScheme())
  3. V2 headers (current): PAYMENT-REQUIRED, PAYMENT-SIGNATURE, PAYMENT-RESPONSE. V1 headers (legacy): X-PAYMENT, X-PAYMENT-RESPONSE. SDK is backward-compatible.
  4. Price format: "$0.001" (dollar string) — SDK converts to atomic units (6 decimals for USDC).
  5. Python SDK uses V1 patterns only. Use TypeScript or Go for V2.
  6. Node.js v24+ required for the TypeScript SDK.
  7. Repo: https://github.com/coinbase/x402 — canonical examples in examples/typescript/.
  8. Docs: https://docs.cdp.coinbase.com/x402/welcome and https://x402.gitbook.io/x402.

Files included

  • references/agentic-patterns.md
  • references/client-patterns.md
  • references/deployment.md
  • references/protocol-spec.md
  • references/server-patterns.md
  • SKILL.md

More skills