← All guides

Locus product guide · Updated

What is x402? How HTTP 402 payments work

x402 is an open standard for paying for an HTTP request with stablecoins. The server answers with a 402 status and a price. The client signs a payment and retries with a PAYMENT-SIGNATURE header. A facilitator verifies and settles it onchain. Coinbase started it in 2025, and the x402 Foundation now runs it.

How does an x402 payment work?

An x402 payment happens inside one request and one retry. The server states the price in a 402 response, the client signs a payment for that price, and the server returns the resource after the payment settles.

In x402 V2 all three headers carry Base64-encoded JSON. PAYMENT-REQUIRED goes from server to client with the accepted options. PAYMENT-SIGNATURE goes from client to server with the signed payload. PAYMENT-RESPONSE comes back with the settlement result.

  • 1. The client requests a resource with no payment.
  • 2. The server returns HTTP 402 and a PAYMENT-REQUIRED header listing price, asset, network, and recipient.
  • 3. The client picks an option, signs a payment, and resends the same request with PAYMENT-SIGNATURE.
  • 4. The server asks a facilitator to verify the payload.
  • 5. The server does the work, then asks the facilitator to settle the payment onchain.
  • 6. The server returns the resource with a PAYMENT-RESPONSE header.

What is inside a 402 PAYMENT-REQUIRED header?

The decoded header is a JSON object with the protocol version, the resource, and an accepts list of payment options. The example below comes from a live Locus x402 endpoint on September 29, 2026 (Alpha Vantage company overview).

What is inside a 402 PAYMENT-REQUIRED header?
FieldExample valueMeaning
x402Version2Protocol version
schemeexactPay this exact amount
networkeip155:8453CAIP-2 ID for Base mainnet
amount8000Atomic units. USDC has 6 decimals, so $0.008
asset0x8335...2913USDC contract on Base
payTo0x3C5C...d5fASeller wallet that receives funds
maxTimeoutSeconds300How long the signed payment stays valid
extensions.bazaarInput example and JSON schemaDiscovery metadata for catalogs

What is an x402 facilitator?

A facilitator is a service that verifies signed payment payloads and settles them onchain for the seller. The seller server calls its /verify endpoint before doing the work and its /settle endpoint after.

The x402 docs call a facilitator optional but recommended. A seller can verify and settle on its own. The facilitator does not hold funds. It broadcasts a transfer the buyer already signed, and it cannot change the amount or recipient.

Coinbase runs the CDP Facilitator. Its docs list Base, Polygon, Arbitrum, World, and Solana, with 1,000 free onchain transactions a month and $0.001 per transaction after that. Verification is free. Other facilitators run in production too.

What does EIP-3009 transferWithAuthorization do in x402?

EIP-3009 lets a token holder sign a transfer that someone else submits. This is how the exact scheme works on EVM chains, and it is why the buyer pays no gas.

The buyer signs from, to, value, validAfter, validBefore, and a nonce. The facilitator sends the transaction and pays the gas. The nonce blocks replays, and the time window caps how long the signature can be used. USDC supports EIP-3009. For tokens that do not, the spec falls back to Permit2, which needs a token approval first.

What are the exact and upto schemes?

A scheme defines how much the buyer authorizes. exact is a fixed price for one request. upto sets a maximum for one request, and the seller settles the measured usage. batch-settlement collects many small authorizations and settles them later.

Use exact for flat-priced calls like a search or a lookup. Use upto for usage-priced calls like an LLM completion, where the token count is not known until the response is done.

What changed in x402 V2?

x402 V2 launched on December 11, 2025. It renamed the headers, moved network IDs to CAIP-2, and added multi-facilitator support and an extensions framework.

  • Headers: the old X-PAYMENT style headers became PAYMENT-REQUIRED, PAYMENT-SIGNATURE, and PAYMENT-RESPONSE.
  • Networks: CAIP-2 IDs such as eip155:8453 for Base, so one format covers EVM chains, Solana, and others.
  • Facilitators: a seller can use several at once, and the SDK picks the best match.
  • Extensions: new features such as discovery ship as extensions instead of forks.
  • Sessions: wallet-based identity lets a returning buyer skip the full payment flow for a resource it already bought.

What is the x402 Bazaar?

The x402 Bazaar is a public catalog of x402 services, indexed by the CDP Facilitator. Buyers search it through the CDP SDKs, REST endpoints, or a Bazaar MCP server. No API key is needed to search.

Sellers get indexed through the V2 discovery extension. The seller adds input examples and a schema to its 402 response, and the facilitator indexes the endpoint so buyers can find it.

Who created x402 and who supports it?

Coinbase started x402 and announced it in May 2025. On July 14, 2026, the Linux Foundation announced the operational launch of the x402 Foundation, which now governs the protocol with 40 members.

Premier members include AWS, Circle, Cloudflare, Coinbase, Google, Mastercard, Shopify, Stripe, and Visa. Cloudflare added x402 to its Agents SDK and MCP tools. Stripe accepts x402 payments in USDC on Base. For the 30 days before September 29, 2026, x402.org reported 75.41M transactions and $24.24M in volume.

What are the limits of x402?

x402 moves money. It does not decide whether a payment is a good idea. The buyer still needs a funded wallet, a signer, and rules for what the agent may spend.

  • The buyer must hold the right token on the right network. A Base USDC wallet cannot pay a Solana-only offer.
  • Each seller sets its own price, and some prices are live. Check the amount in the 402 before you sign.
  • The protocol has no budget or approval layer for the payer. Spending limits live in the wallet or platform that signs.
  • Settlement depends on a facilitator that supports your network and scheme.
  • Payment proves you paid. It does not prove the response is useful. Test a known input before you rely on a seller.

Can an MCP agent pay x402 endpoints?

Yes, in two ways. The agent can hold its own wallet and use an x402 client, for example through the Cloudflare Agents SDK. Or it can call x402 services through a platform that pays for it.

Locus Pro is the second kind. The agent calls the hosted Locus MCP server, and Locus pays the seller.

How does Locus work with x402?

Locus Pro lists hundreds of third-party x402 and MPP services in its catalog. Your agent calls them from one prepaid credit balance, with no wallet or crypto. Locus pays the seller in USDC on Base with a V2 exact payment and charges your credits.

These services are priced live per call. Ask for a no-payment quote with the MCP estimate_cost tool and preflight_external_quote set to true. Or pass max_charge_credits as a ceiling. If the quote is higher, Locus declines the call before dispatch and charges nothing.

Locus also sells its managed APIs over x402. Each provider has a host such as alphavantage.x402.paywithlocus.com, paid in USDC on Base with the exact or upto scheme. No Locus account is needed. The full list is at paywithlocus.com/x402/index.md.

Frequently asked questions

Is x402 a cryptocurrency or token?

No. x402 is a protocol. Payments use existing assets, most often USDC.

Do I need a facilitator to accept x402?

No, but most sellers use one. Without a facilitator you must verify signatures and submit settlement transactions yourself.

Who pays the gas fee in an x402 payment?

The facilitator submits the transaction and pays the gas. With EIP-3009 the buyer only signs a message.

Can I use x402 without holding crypto?

Not directly, since the buyer signs a stablecoin transfer. A platform such as Locus Pro can pay x402 sellers for you and bill a prepaid credit balance instead.

How is x402 different from MPP?

Both use HTTP 402. x402 uses PAYMENT-* headers and facilitators. MPP uses the Payment HTTP authentication scheme and supports cards through Stripe. The MPP guide has a full comparison.

Implementation references

Use these first-party references for current request contracts and account requirements. Tool availability, prices, and negotiated terms can change.

Sources

Third-party details were checked on September 29, 2026. Vendors change pricing and features often, so confirm on their site before you decide.

Related guides