{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "circle-gateway-nanopayments",
    "name": "Circle Gateway Nanopayments",
    "vendor": "Circle",
    "vendorUrl": "https://www.circle.com",
    "kind": "http-api",
    "category": "payment-platforms",
    "summary": "Circle Gateway Nanopayments is a hosted x402 facilitator that settles gas-free USDC payments as small as $0.000001. Buyers sign offchain authorisations against a Gateway balance, and Circle settles net positions onchain in batches.",
    "url": "https://www.anchorterminal.com/tools/circle-gateway-nanopayments",
    "markdownUrl": "https://www.anchorterminal.com/tools/circle-gateway-nanopayments.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/circle-gateway-nanopayments.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/circle-gateway-nanopayments.json",
    "repo": "https://github.com/circlefin/evm-gateway-contracts",
    "license": "Proprietary hosted service under the Circle Developer Terms. The `@circle-fin/x402-batching` SDK on npm and the Gateway contracts on GitHub are Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://gateway-api.circle.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@circle-fin/x402-batching"
      }
    ],
    "auth": "none",
    "authNotes": "No API key or account on the self-managed route. A buyer signs each payment as an EIP-3009 `TransferWithAuthorization` with an EOA private key, and a seller supplies only a receiving address. The SDK's facilitator client sends no credential by default and accepts optional headers. The OpenAPI file defines a Bearer key scheme and applies it to no operation. The Circle Wallets route in the buyer quickstart needs a Circle Console account, an API key and an entity secret. Smart contract accounts are not supported.",
    "pricing": "usage",
    "pricingNotes": "No per-payment fee or gas for a nanopayment, per the docs. The buyer pays chain gas once for the deposit. Crosschain withdrawals carry a 0.005% transfer fee plus a gas fee by source chain, from $0.001 to $1.00, and same-chain withdrawals carry no transfer fee. Testnets work with faucet USDC and no account. No subscription or card. The developer terms say Gateway fees are communicated through the API and may change (checked 2026-10-09).",
    "priceSummary": "0.01% fee",
    "where": "hosted",
    "x402": {
      "level": "partial",
      "evidence": "Circle runs the facilitator. Sellers using `createGatewayMiddleware` or `BatchFacilitatorClient` answer `402 Payment Required` with a `PAYMENT-REQUIRED` header and settle through `POST /v1/x402/settle` on gateway-api.circle.com, under the x402 `exact` scheme with `extra.name` set to `GatewayWalletBatched`. Circle's own API is not paid over x402 (https://developers.circle.com/gateway-nanopayments; https://developers.circle.com/openapi/gateway-nanopayments.yaml, checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 16895,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://developers.circle.com/gateway-nanopayments",
    "llmsTxt": "https://developers.circle.com/llms.txt",
    "openapi": "https://developers.circle.com/openapi/gateway-nanopayments.yaml",
    "capabilities": [
      "payments.x402",
      "payments.stablecoin"
    ],
    "tags": [
      "hosted",
      "usage-based",
      "x402",
      "facilitator",
      "stablecoins",
      "usdc",
      "micropayments",
      "batched-settlement",
      "non-custodial",
      "keyless",
      "openapi",
      "llms-txt",
      "typescript",
      "open-source-sdk"
    ],
    "lastRelease": "2026-09-16",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.6,
      "grade": "B",
      "agentReady": false,
      "rank": 247,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 75,
        "maintenance": 77,
        "payments": 80,
        "reliability": 56,
        "schema": 80,
        "security": 64,
        "transparency": 72
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 56,
          "points": 11.2,
          "reason": "Graded as a hosted service on gateway-api.circle.com. status.circle.com is a Statuspage with Circle Gateway components for each chain, mainnet and testnet (20). The page's history feed runs from 2 September to 9 October 2026 and names no Gateway incident. The 90-day component record is drawn by script and was not read, so the record takes 20 of 30. No rate limit with numbers was found for the Gateway API (0). No 429 or `Retry-After` guidance was found. Each authorisation carries a unique nonce, a repeat returns `nonce_already_used`, and the error reference says to retry `unexpected_error` (6 of 15). No SLA was found, and the developer terms allow changes without prior notice (0). The release notes record the mainnet launch on 29 April 2026 and the pages read carry no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 80,
          "points": 13,
          "reason": "A public OpenAPI 3.0.3 file covers the five operations. It gives the 400 responses no body schema and attaches its Bearer scheme to no operation (23 of 25). llms.txt and a Markdown twin of every docs page (10). The docs say when to use this facilitator and when Circle's other one, and to call `settle` without `verify` in production (15 of 20). Transfer status and settle error reasons are enums and required fields are marked. `payload`, `extra` and `extensions` are open objects, and `pageSize` has no maximum (10 of 15). Every SDK method has a typed signature and an example, and 16 API error codes have a cause and a recovery step. The error reference says the validity window must be 3 days where the quickstart and SDK say 7 (11 of 15). Paths are under `/v1`, the SDK follows semver and the release notes are dated. The npm package ships no changelog (11 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "The API is five operations and the buyer path is one `pay(url)` call. Transfer search takes `pageSize` (20 of 25). Cursor pagination with `pageAfter` and `pageBefore`, and filters by sender, recipient, nonce, network, status and date. A status filter needs a second filter since 26 August 2026 (17 of 20). Sixteen error codes with recovery steps, and typed SDK error messages (17 of 20). The nonce stops one authorisation being settled twice and a `completed` or `failed` state tells a caller when to stop. No idempotency key was found, and a failed payment needs a newly signed authorisation (13 of 20). The seller middleware needs one address and a price, and the buyer client a chain and a key. The only official SDK is TypeScript (8 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 64,
          "points": 11.2,
          "reason": "No API key. The buyer's EOA private key signs each payment, and each authorisation is bound to one amount, recipient, validity window and nonce. The same key controls the whole wallet, the SDK takes it as a plain config value, and smart contract accounts with their own policies are not supported (18 of 30). Only the deposited Gateway balance can be spent, and a client hook can abort a payment above a limit. No limit is set by default and none is enforced by the service (12 of 20). The amount comes from the seller's 402 response, which is untrusted. The docs show the spending-limit hook and give no other guidance. Circle's Gateway skill file says to ask the user before moving funds on mainnet (8 of 15). Transfers can be searched by address, nonce and date and each carries its batch transaction hash. No separate operator log was found (11 of 15). Audit reports by ChainSecurity and OtterSec are linked, one of them on batching, and a repository security policy names a HackerOne bug bounty programme. security.txt answered 404 and no certification was found on the pages read (15 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 80,
          "points": 10,
          "reason": "Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Circle's own API is not paid over x402. Sellers accept x402 through Circle's middleware and facilitator, so the merchant step (25 of 40). The fee page is public with no login, 0.005% on crosschain withdrawals plus a gas fee by chain, and the docs say a nanopayment costs neither party a fee. No price list states the nanopayment fee as a figure, and the terms say fees are communicated through the API and may change (15 of 20). Testnets run on faucet USDC with no account or card, and mainnet has no subscription (20). An agent holding an EOA key and USDC can deposit and pay with no signup, and a seller needs only an address (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "reason": "`@circle-fin/x402-batching` 3.5.0 was published on 16 September 2026, 23 days before this check, and the Gateway release notes have an entry the same day (30). Three SDK versions fall in the last 90 days, 3.3.0 on 4 August, 3.4.0 on 24 August and 3.5.0 (20). The SDK has no public repository or issue tracker that we found. Support is a Discord server and a help centre ticket form, neither tested, next to dated release notes (10 of 25). The SDK is official and current, in TypeScript only (12 of 15). The package declares tests and lint scripts and current peer dependencies. No public CI for it was found. The contracts repository runs a pipeline and its last commit is 29 September 2026 (5 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "note": "editorial 59, provenance 84",
          "reason": "The SDK is Apache-2.0 on npm and the Gateway contracts are Apache-2.0 on GitHub. The API service and the enclave code are closed, under clear developer terms (22 of 30). The privacy policy of 16 September 2026 lists transaction and blockchain data among what is collected and keeps data as long as necessary, with no periods. The service terms link a DPA dated 2022. Nothing found says what the Gateway API logs about a payment (17 of 30). The developer terms promise reasonable efforts to announce the end of support for a version and also let Circle modify or discontinue Gateway without prior notice. The one breaking change found was noted on the day it took effect (6 of 20). A sub-processor list, last updated 22 December 2025, names each processor with its purpose and country (14 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The API is five operations and the buyer path is one `pay(url)` call. Transfer search takes `pageSize` (20 of 25). Cursor pagination with `pageAfter` and `pageBefore`, and filters by sender, recipient, nonce, network, status and date. A status filter needs a second filter since 26 August 2026 (17 of 20). Sixteen error codes with recovery steps, and typed SDK error messages (17 of 20). The nonce stops one authorisation being settled twice and a `completed` or `failed` state tells a caller when to stop. No idempotency key was found, and a failed payment needs a newly signed authorisation (13 of 20). The seller middleware needs one address and a price, and the buyer client a chain and a key. The only official SDK is TypeScript (8 of 15).",
          "maintenance": "`@circle-fin/x402-batching` 3.5.0 was published on 16 September 2026, 23 days before this check, and the Gateway release notes have an entry the same day (30). Three SDK versions fall in the last 90 days, 3.3.0 on 4 August, 3.4.0 on 24 August and 3.5.0 (20). The SDK has no public repository or issue tracker that we found. Support is a Discord server and a help centre ticket form, neither tested, next to dated release notes (10 of 25). The SDK is official and current, in TypeScript only (12 of 15). The package declares tests and lint scripts and current peer dependencies. No public CI for it was found. The contracts repository runs a pipeline and its last commit is 29 September 2026 (5 of 10).",
          "payments": "Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Circle's own API is not paid over x402. Sellers accept x402 through Circle's middleware and facilitator, so the merchant step (25 of 40). The fee page is public with no login, 0.005% on crosschain withdrawals plus a gas fee by chain, and the docs say a nanopayment costs neither party a fee. No price list states the nanopayment fee as a figure, and the terms say fees are communicated through the API and may change (15 of 20). Testnets run on faucet USDC with no account or card, and mainnet has no subscription (20). An agent holding an EOA key and USDC can deposit and pay with no signup, and a seller needs only an address (20).",
          "reliability": "Graded as a hosted service on gateway-api.circle.com. status.circle.com is a Statuspage with Circle Gateway components for each chain, mainnet and testnet (20). The page's history feed runs from 2 September to 9 October 2026 and names no Gateway incident. The 90-day component record is drawn by script and was not read, so the record takes 20 of 30. No rate limit with numbers was found for the Gateway API (0). No 429 or `Retry-After` guidance was found. Each authorisation carries a unique nonce, a repeat returns `nonce_already_used`, and the error reference says to retry `unexpected_error` (6 of 15). No SLA was found, and the developer terms allow changes without prior notice (0). The release notes record the mainnet launch on 29 April 2026 and the pages read carry no beta label (10).",
          "schema": "A public OpenAPI 3.0.3 file covers the five operations. It gives the 400 responses no body schema and attaches its Bearer scheme to no operation (23 of 25). llms.txt and a Markdown twin of every docs page (10). The docs say when to use this facilitator and when Circle's other one, and to call `settle` without `verify` in production (15 of 20). Transfer status and settle error reasons are enums and required fields are marked. `payload`, `extra` and `extensions` are open objects, and `pageSize` has no maximum (10 of 15). Every SDK method has a typed signature and an example, and 16 API error codes have a cause and a recovery step. The error reference says the validity window must be 3 days where the quickstart and SDK say 7 (11 of 15). Paths are under `/v1`, the SDK follows semver and the release notes are dated. The npm package ships no changelog (11 of 15).",
          "security": "No API key. The buyer's EOA private key signs each payment, and each authorisation is bound to one amount, recipient, validity window and nonce. The same key controls the whole wallet, the SDK takes it as a plain config value, and smart contract accounts with their own policies are not supported (18 of 30). Only the deposited Gateway balance can be spent, and a client hook can abort a payment above a limit. No limit is set by default and none is enforced by the service (12 of 20). The amount comes from the seller's 402 response, which is untrusted. The docs show the spending-limit hook and give no other guidance. Circle's Gateway skill file says to ask the user before moving funds on mainnet (8 of 15). Transfers can be searched by address, nonce and date and each carries its batch transaction hash. No separate operator log was found (11 of 15). Audit reports by ChainSecurity and OtterSec are linked, one of them on batching, and a repository security policy names a HackerOne bug bounty programme. security.txt answered 404 and no certification was found on the pages read (15 of 20).",
          "transparency": "The SDK is Apache-2.0 on npm and the Gateway contracts are Apache-2.0 on GitHub. The API service and the enclave code are closed, under clear developer terms (22 of 30). The privacy policy of 16 September 2026 lists transaction and blockchain data among what is collected and keeps data as long as necessary, with no periods. The service terms link a DPA dated 2022. Nothing found says what the Gateway API logs about a payment (17 of 30). The developer terms promise reasonable efforts to announce the end of support for a version and also let Circle modify or discontinue Gateway without prior notice. The one breaking change found was noted on the day it took effect (6 of 20). A sub-processor list, last updated 22 December 2025, names each processor with its purpose and country (14 of 20)."
        },
        "sources": [
          {
            "what": "product overview",
            "url": "https://developers.circle.com/gateway-nanopayments.md",
            "seen": "2026-10-09"
          },
          {
            "what": "batched settlement and security model",
            "url": "https://developers.circle.com/gateway-nanopayments/concepts/batched-settlement.md",
            "seen": "2026-10-09"
          },
          {
            "what": "supported networks",
            "url": "https://developers.circle.com/gateway-nanopayments/supported-networks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "buyer quickstart",
            "url": "https://developers.circle.com/gateway-nanopayments/quickstarts/buyer.md",
            "seen": "2026-10-09"
          },
          {
            "what": "seller quickstart",
            "url": "https://developers.circle.com/gateway-nanopayments/quickstarts/seller.md",
            "seen": "2026-10-09"
          },
          {
            "what": "facilitator integration guide",
            "url": "https://developers.circle.com/gateway-nanopayments/howtos/facilitator-integration.md",
            "seen": "2026-10-09"
          },
          {
            "what": "seller reconciliation guide",
            "url": "https://developers.circle.com/gateway-nanopayments/howtos/x402-seller-reconciliation.md",
            "seen": "2026-10-09"
          },
          {
            "what": "SDK reference and error reference",
            "url": "https://developers.circle.com/sdks/gateway-nanopayments-sdk.md",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI description, read as the file and not the rendered reference pages",
            "url": "https://developers.circle.com/openapi/gateway-nanopayments.yaml",
            "seen": "2026-10-09"
          },
          {
            "what": "Gateway release notes, 2026",
            "url": "https://developers.circle.com/release-notes/gateway-2026.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Gateway fees",
            "url": "https://developers.circle.com/gateway/references/fees.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Gateway supported blockchains and confirmation times",
            "url": "https://developers.circle.com/gateway/references/supported-blockchains.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Gateway technical guide, withdrawal delay and audit reports",
            "url": "https://developers.circle.com/gateway/references/technical-guide.md",
            "seen": "2026-10-09"
          },
          {
            "what": "comparison of Circle's two x402 facilitators",
            "url": "https://developers.circle.com/x402-facilitators.md",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index for agents",
            "url": "https://developers.circle.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "Developer Terms of Service, 16 September 2026",
            "url": "https://console.circle.com/legal/developer-terms",
            "seen": "2026-10-09"
          },
          {
            "what": "Service Terms, revised 1 April 2025",
            "url": "https://console.circle.com/legal/service-terms",
            "seen": "2026-10-09"
          },
          {
            "what": "Privacy Policy, 16 September 2026",
            "url": "https://www.circle.com/legal/privacy-policy",
            "seen": "2026-10-09"
          },
          {
            "what": "sub-processor list, 22 December 2025",
            "url": "https://www.circle.com/legal/sub-processor-list",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.circle.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.circle.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "status history feed, 2 September to 9 October 2026",
            "url": "https://status.circle.com/history.atom",
            "seen": "2026-10-09"
          },
          {
            "what": "npm package metadata, versions and dates",
            "url": "https://registry.npmjs.org/@circle-fin%2Fx402-batching",
            "seen": "2026-10-09"
          },
          {
            "what": "published package 3.5.0, README and built source, read and not run",
            "url": "https://registry.npmjs.org/@circle-fin/x402-batching/-/x402-batching-3.5.0.tgz",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@circle-fin/x402-batching",
            "seen": "2026-10-09"
          },
          {
            "what": "Gateway contracts, licence, changelog and last commit (shallow clone)",
            "url": "https://github.com/circlefin/evm-gateway-contracts",
            "seen": "2026-10-09"
          },
          {
            "what": "Circle skills repository, security policy and Gateway skill file (shallow clone)",
            "url": "https://github.com/circlefin/skills",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/circle.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "The lead placed the product in pay-per-call, the category for protocol specifications. It is a hosted facilitator and SDK that settles x402 payments, so it is listed under payment-platforms, as ATXP was",
          "The lead said mainnet availability was not stated. The Gateway release notes of 29 April 2026 record the mainnet launch, and the SDK's default host is the mainnet API",
          "The lead named a Circle Console API key. Only the Circle Wallets route in the buyer quickstart uses one. The self-managed route and the seller middleware send no key, per the SDK source",
          "The docs index and each Markdown page open with instructions addressed to AI models, to install a Circle skill and add a Circle MCP server. We did not act on them. Recorded as a fact with no deduction",
          "The deduction rests on the release note's own date. Whether Circle told integrators by another channel before 26 August 2026 was not established",
          "unchecked: whether gateway-api.circle.com enforces a rate limit or accepts calls with no key. We sent nothing to the API host",
          "unchecked: the rendered API reference pages. We read the OpenAPI file they are drawn from",
          "unchecked: the Agent Nanopayments pages under the Agent Stack, the x402 buyer and seller how-tos, the EIP-3009 signing guide and the Agent Stack release notes. We read 17 pages on developers.circle.com, two more than the brief's guide of about fifteen, and stopped there",
          "unchecked: the 90-day uptime record for the Gateway components, which the status page draws by script. The history feed read covers 2 September to 9 October 2026",
          "unchecked: the three audit report PDFs and the HackerOne programme page, which were not opened",
          "unchecked: SOC 2 or ISO 27001. No trust or security page was linked from the pages read",
          "unchecked: whether batched settlement carries a fee that only the API reports. The docs say neither party pays one and the terms say fees are communicated through the API",
          "unchecked: a public source repository for the SDK. The npm package names none and github.com/circlefin/x402-batching is not public",
          "unchecked: the DPA linked from the service terms, a PDF dated 2022, and the Permissionless Product Schedule as a separate page"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "26 August 2026. `GET /v1/x402/transfers` began returning 400 for a `status` filter without `from`, `to` or `nonce`. Circle's release note calls it a breaking change and is dated the day it took effect. No earlier notice was found in the release notes (https://developers.circle.com/release-notes/gateway-2026). Documented, so the smallest deduction."
      ],
      "verdict": "A buyer with an EOA key and a seller with a wallet address can transact with no account or API key, and the settle call returns 16 documented error codes with recovery steps. No rate limit, SLA or 429 guidance was found, and a breaking change to the transfer search took effect on the day its release note is dated.",
      "bestFor": "Sellers charging fractions of a cent per API call and agents making many small payments from one prefunded balance on EVM chains.",
      "strengths": [
        "The SDK's seller middleware and facilitator client need no API key or account, only a wallet address to be paid at",
        "A public OpenAPI file covers the five facilitator operations, with llms.txt and a Markdown twin of every docs page",
        "The error reference lists 16 settle and verify codes, each with a cause and a recovery step",
        "The batching contracts were audited by OtterSec (report dated 10 June 2026), and the Gateway contracts are Apache-2.0 on GitHub",
        "Deposits sit in a non-custodial contract, with a withdrawal path that needs no Circle API after a 7-day delay"
      ],
      "weaknesses": [
        "No rate limit, 429 guidance or SLA was found for the Gateway API in the reviewed documentation",
        "From 26 August 2026 a `status` filter alone on `GET /v1/x402/transfers` returns 400. The release note is dated the same day",
        "Only EOA signatures work. Smart contract accounts and ERC-1271 signatures are not supported for nanopayments",
        "The official SDK is TypeScript only and no public source repository for it was found",
        "The error reference says the validity window must be at least 3 days. The seller quickstart and the SDK source say 7 days",
        "The developer terms let Circle change or discontinue Gateway without prior notice and change its fees at its discretion"
      ],
      "agentNotes": [
        "Deposit on the chain you will pay from. `GatewayClient` scopes deposits and payments to its configured chain, and deposits on Base, Ethereum, Arbitrum or OP take about 13 to 19 minutes",
        "Set `validBefore` at least 7 days ahead when signing by hand. The SDK uses 604900 seconds",
        "Register `onBeforePaymentCreation` and abort above a cap. `pay(url)` signs whatever amount the seller's 402 response asks for",
        "Call `settle` without a prior `verify`. Balance and nonce checks happen only at settle time",
        "Pass `from`, `to` or `nonce` whenever you filter transfers by `status`, and wait for `completed` before a dependent onchain step"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.6
        }
      ],
      "editorialScores": {
        "ergonomics": 75,
        "maintenance": 77,
        "payments": 80,
        "reliability": 56,
        "schema": 80,
        "security": 64,
        "transparency": 59
      },
      "provenanceScore": 84
    },
    "connect": {
      "install": "npm install @circle-fin/x402-batching"
    },
    "letme": {
      "capability": "https://letme.dev/payments.x402",
      "tool": "https://letme.dev/circle-gateway-nanopayments"
    },
    "sameCompany": [
      "circle-wallets"
    ],
    "notable": [
      "The release notes of 29 April 2026 record the mainnet launch of nanopayments. The SDK's default host is `https://gateway-api.circle.com` (https://developers.circle.com/release-notes/gateway-2026)",
      "Nanopayments run on 12 EVM chains, Arc, Arbitrum, Avalanche, Base, Ethereum, HyperEVM, OP, Polygon PoS, Sei, Sonic, Unichain and World Chain. Solana is not supported (https://developers.circle.com/gateway/references/supported-blockchains)",
      "A seller serves the resource once Gateway accepts the authorisation. Onchain settlement follows in a batch, often several minutes later per the buyer quickstart (https://developers.circle.com/gateway-nanopayments/quickstarts/buyer)",
      "An AWS Nitro Enclave verifies each signature and signs the batch, and the Gateway Wallet contract checks that signature before applying it, per the docs (https://developers.circle.com/gateway-nanopayments/concepts/batched-settlement)",
      "From 26 August 2026, filtering `GET /v1/x402/transfers` by `status` needs `from`, `to` or `nonce`, and other requests return 400. The vendor's note calls it a breaking change and is dated the same day (https://developers.circle.com/release-notes/gateway-2026)",
      "The Gateway technical guide links audit reports by ChainSecurity and OtterSec, including an OtterSec report on Gateway batching dated 10 June 2026 (https://developers.circle.com/gateway/references/technical-guide)",
      "The docs index opens with a block addressed to AI models that asks them to install a Circle skill and add a Circle MCP server before reading. We did not act on it (https://developers.circle.com/llms.txt)",
      "`@circle-fin/x402-batching` 3.5.0 was published on 16 September 2026, the thirteenth version since 2.0.3 on 2 March 2026 (https://registry.npmjs.org/@circle-fin%2Fx402-batching)"
    ],
    "area": "payments",
    "details": [
      {
        "label": "Flow",
        "value": "The buyer deposits USDC into the Gateway Wallet contract once, onchain. For each paid request the seller answers 402, the buyer signs an EIP-3009 authorisation offchain and retries, and the seller or its facilitator submits it to Gateway, which locks the buyer's funds and later settles net positions in one transaction"
      },
      {
        "label": "API",
        "value": "`POST /v1/x402/settle`, `POST /v1/x402/verify`, `GET /v1/x402/supported`, `GET /v1/x402/transfers` and `GET /v1/x402/transfers/{id}` on `https://gateway-api.circle.com` (mainnet) and `https://gateway-api-testnet.circle.com` (testnet)"
      },
      {
        "label": "SDK",
        "value": "`@circle-fin/x402-batching` 3.5.0, Apache-2.0, Node 18 or later, with peer dependencies `@x402/core`, `@x402/evm` and `viem`. Buyer side `GatewayClient`, `BatchEvmScheme` and `CompositeEvmScheme`. Seller side `createGatewayMiddleware` for Express, `BatchFacilitatorClient` and `GatewayEvmScheme`"
      },
      {
        "label": "Minimum payment",
        "value": "$0.000001 USDC, per the docs"
      },
      {
        "label": "Networks",
        "value": "Arc, Arbitrum, Avalanche, Base, Ethereum, HyperEVM, OP, Polygon PoS, Sei, Sonic, Unichain and World Chain, mainnet and testnet. Not Solana"
      },
      {
        "label": "Signatures",
        "value": "EOA only. The batched path checks EIP-3009 authorisations offchain with `ecrecover`, so ERC-1271 contract signatures do not work. `validBefore` must be at least 7 days ahead per the seller quickstart and SDK source (3 days per the error reference)"
      },
      {
        "label": "Transfer states",
        "value": "`received`, `batched`, `confirmed`, `completed` and `failed`. `txHash` is the batch transaction and stays null until the batch has one"
      },
      {
        "label": "Deposit time",
        "value": "About 0.5 seconds on Arc, 5 to 8 seconds on Avalanche, HyperEVM, Polygon PoS, Sei and Sonic, and 13 to 19 minutes on Arbitrum, Base, Ethereum, OP, Unichain and World Chain, per the docs"
      },
      {
        "label": "Withdrawal",
        "value": "`GatewayClient.withdraw` to the same chain or another supported chain. Without Circle's API, a withdrawal can be started onchain and completed after a 7-day delay"
      },
      {
        "label": "Buyer controls",
        "value": "`onBeforePaymentCreation`, `onAfterPaymentCreation` and `onPaymentResponse` hooks on `GatewayClient`. The first can abort a payment above a limit. No limit is set by default"
      },
      {
        "label": "Reconciliation",
        "value": "Sellers record the EIP-3009 nonce in `onAfterSettle` and look transfers up by nonce, recipient and date range with cursor pagination"
      },
      {
        "label": "Terms",
        "value": "Circle Developer Terms of Service, last updated 16 September 2026, from Circle Technology Services, LLC. Gateway is a Permissionless Product under them. Privacy Policy last updated 16 September 2026 from Circle Internet Group, Inc."
      }
    ],
    "unitPrices": [
      {
        "item": "Batched nanopayment",
        "unit": "tx",
        "usd": 0,
        "note": "no per-payment fee or gas for buyer or seller, per the docs. The deposit costs chain gas once"
      },
      {
        "item": "Crosschain withdrawal transfer fee",
        "unit": "pct",
        "usd": 0.005,
        "note": "0.5 basis points. Not charged on same-chain withdrawals"
      },
      {
        "item": "Gateway gas fee, Base as source chain",
        "unit": "tx",
        "usd": 0.01,
        "note": "by source chain, from $0.001 on Sei and Unichain to $1.00 on Ethereum"
      },
      {
        "item": "Forwarding Service fee",
        "unit": "tx",
        "usd": 0.05,
        "note": "optional, plus a forwarding gas fee"
      }
    ],
    "provenance": {
      "legalEntity": "Circle Technology Services, LLC",
      "domain": "circle.com",
      "domainRegistered": "1999-04-09",
      "endpointOnVendorDomain": true,
      "terms": "https://console.circle.com/legal/developer-terms",
      "privacy": "https://www.circle.com/legal/privacy-policy",
      "statusPage": "https://status.circle.com",
      "changelog": "https://developers.circle.com/release-notes/gateway-2026",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Developer Terms of Service (last updated 16 September 2026) are a contract with Circle Technology Services, LLC and name Gateway as a Permissionless Product. They say committed USDC stays the user's property and that Circle may modify or discontinue Permissionless Products without prior notice.",
        "The Privacy Policy (last updated 16 September 2026) is from Circle Internet Group, Inc. and its subsidiaries and links a sub-processor list last updated 22 December 2025.",
        "The API hosts are gateway-api.circle.com and gateway-api-testnet.circle.com, on the vendor's domain.",
        "status.circle.com is an Atlassian Statuspage with Circle Gateway components for each chain. It has no component named for nanopayments or x402.",
        "www.circle.com/.well-known/security.txt answered 404. The SECURITY.md in github.com/circlefin/skills names a bug bounty programme at hackerone.com/circle-bbp.",
        "RDAP for circle.com gives a registration date of 1999-04-09."
      ],
      "score": 84,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Circle Technology Services, LLC",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "circle.com, registered 1999-04-09 (27 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "gateway-api.circle.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.circle.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://console.circle.com/legal/developer-terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-16",
          "words": 10239,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 16, 2026",
              "says": "Last updated 2026-09-16"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "Each party agrees that state or federal courts in Boston, Massachusetts, referenced below, may enter injunctive relief to enforce the pre-filing requirements of this paragraph, including an injunction to stay an arbitration that has been commenced in violation of this paragraph.",
              "says": "Disputes go to the courts of Boston, Massachusetts"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, THE TOTAL LIABILITY OF CIRCLE IS LIMITED TO THE GREATER OF (A) THE AMOUNT OF FEES EARNED BY US IN CONNECTION WITH YOUR USE OF THE DEVELOPER TOOLS AND/OR SERVICES DURING THE THREE (3) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM FOR LIABILITY O…",
              "says": "Capped at $250"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Circle may terminate, suspend, or restrict access to any API key or client key if you violate any Additional Terms or Schedule applicable to any product or service accessible through that key, irrespective of whether the violation relates to all products or services for which that key is configured."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Relationship with Circle Entities We may amend these Terms or modify the Developer Tools and Services, including any applicable accompanying documentation and guidelines, at any time with notice that we deem to be reasonable in the circumstances, by posting the revised version on our website or communicating it to you…",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Unless otherwise permitted by us in writing, you may only possess one Circle Developer Account and you may not assign or otherwise transfer your account to any other person or entity."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "create a service that functions substantially the same as the Developer Tools or Services;",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Circle reserves the right to modify or discontinue, temporarily or permanently, any of its Permissionless Products or any features or portions thereof without prior notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may terminate these Terms or suspend or terminate your use of the Developer Tools or the Services (or any portion thereof) at any time for any reason."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "THESE TERMS CONTAIN A MANDATORY ARBITRATION PROVISION THAT, AS FURTHER SET FORTH BELOW, REQUIRES THE USE OF ARBITRATION ON AN INDIVIDUAL BASIS TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR ANY OTHER COURT PROCEEDINGS, OR CLASS ACTIONS OF ANY KIND"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Circle's total liability is capped at the greater of three months of fees it earned from the developer's use or 250 US dollars.",
              "quote": "THE EVENT GIVING RISE TO THE CLAIM FOR LIABILITY OR (B) $250."
            },
            {
              "date": "2026-10-08",
              "text": "Content submitted through the Developer Tools or Services is licensed to Circle on a perpetual and irrevocable basis.",
              "quote": "through Your Service, you give Circle a perpetual, irrevocable, worldwide, royalty-free, and non-exclusive"
            },
            {
              "date": "2026-10-08",
              "text": "On termination or suspension Circle may delete the developer's information and account data and accepts no liability for that deletion.",
              "quote": "delete your information and account data stored on our servers, and (c) Circle shall not be liable to you"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.circle.com/legal/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 7625,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We know how important privacy is to our users, which is why this Privacy Policy explains how we collect and use data."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We may collect, use, store and transfer different kinds of personal data over the preceding 12 months about you which we have grouped together as follows:",
              "says": "Names a period of 12 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Clicking on those links or enabling those connections may allow third parties to collect or share data about you."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell or share personal information of consumers we actually know are under 16 years of age.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to withdraw consent to marketing at any time by contacting Support."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Circle has appointed a data protection officer (“DPO”) who is responsible for overseeing questions in relation to this Privacy Policy.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…Cayman Islands, the European Economic Area (“EEA”), the UK, Singapore or Switzerland, we rely on the Standard Contractual Clauses (SCCs) to provide an adequate level of data protection for the transfer of your Personal Data from Cayman Islands, EEA, UK, or Switzerland, where the country of import is not deemed adequat…",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "These disclosures may be considered “selling” and/or “sharing” of personal information."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Circle may share personal information with AI service providers to the extent needed to run its services.",
              "quote": "Your information will only be shared with these AI service providers to the extent necessary to provide you with Circle Services."
            },
            {
              "date": "2026-10-08",
              "text": "Blockchain data may be broadcast on public blockchain networks, where records cannot be altered or removed.",
              "quote": "Due to the way these networks are structured and operated, records cannot be altered or removed once they have been recorded."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/circle-gateway-nanopayments.json",
    "live": {
      "slug": "circle-gateway-nanopayments",
      "probe": {
        "target": "https://gateway-api.circle.com",
        "method": "get",
        "lastAt": "2026-10-10T03:53:23.545853009Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 119,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 145,
        "p95ms24h": 1147,
        "samples24h": 125,
        "samples30d": 125,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 40,
            "ok": 40
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.circle.com",
        "indicator": "major",
        "summary": "Partial System Outage",
        "checkedAt": "2026-10-10T03:58:02.638879871Z"
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@circle-fin/x402-batching",
          "version": "3.5.0",
          "seenAt": "2026-10-09T16:45:07.952774661Z"
        }
      ],
      "githubStars": 10,
      "npmWeekly": 16895,
      "pages": [
        {
          "url": "https://developers.circle.com/release-notes/gateway-2026",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:35:33.753415397Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "6ef7c495e029"
        },
        {
          "url": "https://www.circle.com/legal/privacy-policy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:49:03.821925211Z",
          "changedAt": "2026-10-09T18:49:03.821925211Z",
          "fingerprint": "0b638ffd6762"
        },
        {
          "url": "https://console.circle.com/legal/developer-terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:34:17.88745813Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "06bed5753aaf"
        }
      ],
      "updatedAt": "2026-10-10T03:58:02.638879871Z"
    }
  }
}
