Payments · x402 v2 · USDC on Base and Solana

x402 at Anchor Terminal

HTTP has had a 402 status code since 1997 and nothing to put in it. x402 fills it. The server says what it costs, the agent signs a stablecoin transfer, a facilitator settles it, and the request goes through. No account, no card, no human. We rank tools that support it higher, and paying per call through letme will run on it.

Why it matters for agents

An agent that finds the perfect tool and then needs a human to create an account, enter a card and paste a key hasn't found a tool. It has found a ticket for someone's backlog. Most of the friction in agent autonomy today isn't intelligence, it's onboarding. x402 removes it for anything priced per call. The agent holds a wallet with a spend limit, reads the price from the response, and pays for what it uses.

That's why the benchmark gives machine payment 40 of the 100 points in the payments category, more than any other single signal. x402 is the one we see most, but MPP and L402 earn the same points once a canary payment settles through them. It isn't a crypto preference (we've had our fill of those). x402 is the most widely deployed way for software to pay software over plain HTTP right now, it has an open specification under the Linux Foundation, and the buyers and sellers we care about already use it. Coinbase, Cloudflare, Stripe and AWS sit on or support the protocol, and market-data vendors, search APIs and scraping marketplaces sell through it.

The flow, precisely

x402 v2 (published December 2025) carries everything in headers. The body of a 402 is free for a human-readable paywall.

StepDirectionHeaderContent
1client to servernoneOrdinary request, no payment
2server to clientPAYMENT-REQUIREDbase64 JSON with x402Version 2, a resource object (url, description, mimeType), an accepts array of {scheme, network, amount, asset, payTo, maxTimeoutSeconds, extra}, and optional extensions
3client to serverPAYMENT-SIGNATUREbase64 JSON {x402Version, resource, accepted, payload} where payload is a signed EIP-3009 transferWithAuthorization (EVM) or an SPL transfer (Solana)
4server to facilitatorPOST /verify, then POST /settleThe facilitator checks the signature and balance, then submits the transfer and pays the gas
5server to clientPAYMENT-RESPONSEbase64 JSON {success, transaction, network, payer} on the 200

Amounts are atomic units of the asset ("10000" is $0.01 for six-decimal USDC). Networks are CAIP-2 identifiers (eip155:8453 is Base, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp is Solana mainnet). The exact scheme is a fixed price and upto authorises a maximum for metered use. Legacy v1 clients used X-PAYMENT and a JSON body with maxAmountRequired, and sellers still accept both.

GET /search?q=x402+facilitators HTTP/1.1
Host: api.example.com

HTTP/1.1 402 Payment Required
PAYMENT-REQUIRED: eyJ4NDAyVmVyc2lvbiI6MiwicmVzb3VyY2UiOnsidXJsIjoiaHR0cHM6Ly9hcGkuZXhhbXBsZS5jb20vc2VhcmNoIn0sImFjY2VwdHMiOlt7InNjaGVtZSI6ImV4YWN0IiwibmV0d29yayI6ImVpcDE1NTo4NDUzIiwiYW1vdW50IjoiNzAwMCIsImFzc2V0IjoiMHg4MzM1ODlmQ0Q2ZURiNkUwOGY0YzdDMzJENGY3MWI1NGJkQTAyOTEzIiwicGF5VG8iOiIweC4uLiIsIm1heFRpbWVvdXRTZWNvbmRzIjo2MH1dfQ==

GET /search?q=x402+facilitators HTTP/1.1
Host: api.example.com
PAYMENT-SIGNATURE: eyJ4NDAyVmVyc2lvbiI6MiwiYWNjZXB0ZWQiOnsic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoiZWlwMTU1Ojg0NTMiLCJhbW91bnQiOiI3MDAwIn0sInBheWxvYWQiOnsic2lnbmF0dXJlIjoiMHguLi4iLCJhdXRob3JpemF0aW9uIjp7ImZyb20iOiIweC4uLiIsInRvIjoiMHguLi4iLCJ2YWx1ZSI6IjcwMDAifX19

HTTP/1.1 200 OK
PAYMENT-RESPONSE: eyJzdWNjZXNzIjp0cnVlLCJ0cmFuc2FjdGlvbiI6IjB4YWJjLi4uIiwibmV0d29yayI6ImVpcDE1NTo4NDUzIiwicGF5ZXIiOiIweC4uLiJ9
Content-Type: application/json

Tools that accept x402 today

Detected on the endpoint, corroborated in the x402 Bazaar, listed with the price read from the 402. Prices change. The live value is always the one in the response.

ToolGrade What you can pay forPriceNetwork
Apify MCP ServerAhttps://agi.apify.com/protocols/x402/prepaid-tokens?amount=1&currency=usd$1eip155:8453
https://mcp.apify.com?payment=x402$1eip155:8453
BrowserbaseBBhttps://x402.browserbase.com/browser/session/createper token
https://x402.browserbase.com/browser/session/:id/statusper token
https://x402.browserbase.com/browser/session/:id/extendper token
https://x402.browserbase.com/browser/session/:id/terminateper token
AgentMail API + MCPBBhttps://x402.api.agentmail.to/v0/inboxes$2eip155:8453
SpiderBBhttps://api.spider.cloud/scrape$0.0005eip155:8453
https://api.spider.cloud/crawl$0.005eip155:8453
https://api.spider.cloud/search$0.002eip155:8453
https://api.spider.cloud/links$0.0002eip155:8453
BlockRun.AIBBhttps://blockrun.ai/api/v1/chat/completionsper tokeneip155:8453
CoinGecko x402 APIBBhttps://pro-api.coingecko.com/api/v3/x402/simple/price$0.01eip155:8453
https://pro-api.coingecko.com/api/v3/x402/onchain/simple/networks/{id}/token_price/{address}$0.01eip155:8453
https://pro-api.coingecko.com/api/v3/x402/onchain/search/pools$0.01eip155:8453
https://pro-api.coingecko.com/api/v3/x402/onchain/networks/{id}/trending_pools$0.01eip155:8453
https://pro-api.coingecko.com/api/v3/x402/onchain/networks/{network}/tokens/{address}$0.01eip155:8453
Massive (formerly Polygon.io)BBhttps://agent.massive.com/v2/aggs/ticker/{stocksTicker}/range/{multiplier}/{timespan}/{from}/{to}$0.01eip155:8453
https://agent.massive.com/v2/snapshot/locale/us/markets/stocks/tickers/{stocksTicker}$0.01eip155:8453
https://agent.massive.com/v3/reference/tickers$0.01eip155:8453
https://agent.massive.com/v2/reference/news$0.01eip155:8453
https://agent.massive.com/stocks/filings/vX/index$0.01eip155:8453
LinkupBhttps://api.linkup.so/v1/search$0.01eip155:8453
https://api.linkup.so/v1/fetch$0.01eip155:8453
CoinMarketCap x402 APIBhttps://pro-api.coinmarketcap.com/x402/v3/cryptocurrency/quotes/latest$0.01eip155:8453
https://pro-api.coinmarketcap.com/x402/v3/cryptocurrency/listings/latest$0.01eip155:8453
https://pro-api.coinmarketcap.com/x402/v1/dex/search$0.01eip155:8453
https://pro-api.coinmarketcap.com/x402/v4/dex/pairs/quotes/latest$0.01eip155:8453
Nansen x402 APIBhttps://api.nansen.ai/api/v1/profiler/address/current-balance$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/address/historical-balances$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/perp-positions$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/address/transactions$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/perp-trades$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/address/related-wallets$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/address/pnl-summary$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/address/pnl$0.01eip155:8453
https://api.nansen.ai/api/v1/token-screener$0.01eip155:8453
https://api.nansen.ai/api/v1/perp-screener$0.01eip155:8453
https://api.nansen.ai/api/v1/tgm/transfers$0.01eip155:8453
https://api.nansen.ai/api/v1/tgm/jup-dca$0.01eip155:8453
https://api.nansen.ai/api/v1/tgm/flow-intelligence$0.01eip155:8453
https://api.nansen.ai/api/v1/tgm/who-bought-sold$0.01eip155:8453
https://api.nansen.ai/api/v1/tgm/dex-trades$0.01eip155:8453
https://api.nansen.ai/api/v1/portfolio/defi-holdings$0.01eip155:8453
https://api.nansen.ai/api/v1/tgm/flows$0.01eip155:8453
https://api.nansen.ai/api/v1/profiler/address/counterparties$0.05eip155:8453
https://api.nansen.ai/api/v1/tgm/holders$0.05eip155:8453
https://api.nansen.ai/api/v1/tgm/pnl-leaderboard$0.05eip155:8453
https://api.nansen.ai/api/v1/tgm/perp-pnl-leaderboard$0.05eip155:8453
https://api.nansen.ai/api/v1/perp-leaderboard$0.05eip155:8453
https://api.nansen.ai/api/v1/smart-money/netflow$0.05eip155:8453
https://api.nansen.ai/api/v1/smart-money/holdings$0.05eip155:8453
https://api.nansen.ai/api/v1/smart-money/dex-trades$0.05eip155:8453
Exa API + MCPBhttps://api.exa.ai/search$0.007eip155:8453
https://api.exa.ai/contents$0.001eip155:8453
HonchoBhttps://agentcash.honcho.dev/api/honcho/messages$0.001eip155:8453
https://agentcash.honcho.dev/api/honcho/chat$0.001eip155:8453

The same list as JSON is at /api/v1/x402.json.

How the payments category is scored

SignalPointsHow it's checked
x402 (or another agent-native payment protocol) on the tool's own endpoints40An unpaid request returns 402 with a valid PAYMENT-REQUIRED header or v1 body, and a weekly canary micropayment settles with the transaction hash published. Payer-side tooling without payable endpoints scores 25.
Per-call pricing with units, published without a login20Pricing page or 402 response readable by an anonymous fetch
Free tier or trial without a card20Documented, and verified by signing up with a throwaway identity where the terms allow it
Autonomous onboarding, meaning an agent can get access with no human step20Anonymous access, x402, or programmatic key issuance

So a free open-source local tool scores 60 (no x402, but nothing to pay and nothing to sign up for). A hosted tool behind OAuth with a published price and a card-free trial lands around 40. A tool that wants a card before any use scores 20. A tool that accepts x402 with published prices scores 90 or above.

Paying per call

Reading is free and stays free. The directory, the benchmark, the reviews, the API, the Markdown twins. Paying per call for the tools in the directory will go through letme, with top-ups by x402 (USDC on Base or Solana), when calling through letme opens. Today letme picks the tool and the agent pays it direct. Readiness reports and audits are payable by x402 or by invoice, see for builders.

Detecting x402 support automatically

For builders wondering how the probe sees them, and for agents that want to check a tool before trusting our listing.

  1. Send the request without payment (GET, then POST {} for body endpoints).
  2. Strong signal, HTTP 402 plus a PAYMENT-REQUIRED header that base64-decodes to JSON with x402Version: 2 and a non-empty accepts array whose entries each carry scheme, network, amount, asset and payTo.
  3. Legacy signal, 402 with a JSON body {"x402Version": 1, "accepts": [...]}. Still x402, recorded as v1.
  4. Related but not x402, WWW-Authenticate: Payment ... is the Machine Payments Protocol (Stripe and Tempo), WWW-Authenticate: L402 ... is Lightning's L402, and a crawler-price header is Cloudflare pay-per-crawl. We record these too. They earn partial credit today and full credit once a canary settlement works through them.
  5. Corroboration, presence in the CDP Bazaar (/platform/v2/x402/discovery/search), PayAI's /discovery/resources, x402scan, or the origin's own /.well-known/x402.
  6. Proof, one paid call from a canary wallet, PAYMENT-RESPONSE.success == true, transaction hash checked on-chain. Re-verified weekly. Origins that stop settling get demoted, with the date shown.

Accepting x402 in Go

For builders who want the 40 points. This is the whole integration with the official module (github.com/x402-foundation/x402/go/v2, Apache-2.0). The middleware answers 402, verifies with the facilitator, runs your handler, settles, and sets PAYMENT-RESPONSE.

package main

import (
	"net/http"
	"os"
	"time"

	x402http "github.com/x402-foundation/x402/go/v2/http"
	nethttpmw "github.com/x402-foundation/x402/go/v2/http/nethttp"
	"github.com/x402-foundation/x402/go/v2/mechanisms/evm"
)

func main() {
	payTo := os.Getenv("PAY_TO") // your Base address; USDC is the default asset for "$0.005"
	facilitator := x402http.NewHTTPFacilitatorClient(&x402http.FacilitatorConfig{
		URL: os.Getenv("FACILITATOR_URL"), // https://x402.org/facilitator on testnet
	})
	routes := x402http.RoutesConfig{
		"GET /v1/lookup": {
			Accepts: x402http.PaymentOptions{{
				Scheme: "exact", Price: "$0.005", Network: "eip155:8453", PayTo: payTo,
			}},
			Description: "Lookup", MimeType: "application/json",
		},
	}
	mux := http.NewServeMux()
	mux.HandleFunc("GET /v1/lookup", func(w http.ResponseWriter, r *http.Request) {
		w.Header().Set("Content-Type", "application/json")
		w.Write([]byte(`{"ok":true}`))
	})
	paid := nethttpmw.X402Payment(nethttpmw.Config{
		Routes:      routes,
		Facilitator: facilitator,
		Schemes:     []nethttpmw.SchemeConfig{{Network: "eip155:8453", Server: evm.NewExactEvmScheme()}},
		Timeout:     30 * time.Second,
	})(mux)
	http.ListenAndServe(":8080", paid)
}

Add "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp" with svm.NewExactSvmScheme() to take Solana USDC as well, declare the bazaar extension so the endpoint gets indexed, and expose PAYMENT-REQUIRED and PAYMENT-RESPONSE through Access-Control-Expose-Headers if browsers will call it. We haven't shipped our own paid endpoints yet, so take the snippet as the plan rather than a war story.

The five protocols below are graded side by side, with fees, rails, governance and the security research on each. x402, MPP and L402 are on the pay-per-call protocols page, and AP2 and ACP, which are about an agent buying on a person's behalf, on the agent checkout protocols page. They're graded but not ranked against tools, since you use whichever one the seller speaks.

Google's AP2 (Agent Payments Protocol, September 2025) is about authorisation. Signed intent, cart and payment mandates prove a human allowed a purchase. It uses A2A as transport and has an x402 extension for settlement, so the two are complementary. Stripe and OpenAI's Agentic Commerce Protocol (September 2025) is merchant checkout for ChatGPT with Shared Payment Tokens, card-centric and human-in-the-loop, no 402. MPP (the Machine Payments Protocol from Stripe and Tempo, March 2026, IETF draft httpauth-payment) is an HTTP auth scheme, WWW-Authenticate: Payment ... and Authorization: Payment ..., and its charge intent maps directly onto x402's exact flow, so one endpoint can serve both. Visa's Trusted Agent Protocol and Mastercard's Agent Pay bring card rails and agent identity via Web Bot Auth signatures, and Mastercard's June 2026 Agent Pay for Machines supports x402 and MPP explicitly. L402 is Lightning's macaroon-plus-invoice scheme, and x402 has an exact binding for Lightning BTC. Cloudflare's pay-per-crawl started as a fiat 402 with crawler-price headers and now maps onto x402's credit-backed batch-settlement scheme on the network id cloudflare:402.

What we're unsure about

Whether 40 points is too much. A tool with x402 and a bad schema can outscore a better tool that only takes cards, and we've decided that's the right outcome for autonomous agents but not for every reader. The counter-argument (payments are the operator's problem, not the tool's) has a point. We'll revisit the weight after the first run with probes, when we can see how many tools it moves and by how much. In the October 2026 research run, with two categories pending, payments carries 12.5 of the 100 points rather than 10, which makes the question sharper.

Does an agent need to hold crypto to use x402-ready tools?

It needs a wallet holding USDC on the network the seller accepts, and nothing else. The facilitator pays gas. Client SDKs default to a $1 per-payment cap on recognised stablecoins, and a harness can fund a wallet with $5 and run for a long time at a cent a call.

Is x402 a Coinbase product?

It started at Coinbase in May 2025 and was contributed to the Linux Foundation's x402 Foundation in April 2026, with Coinbase, Cloudflare and Stripe on the technical steering committee and 40-plus member organisations. Anyone can run a facilitator. Coinbase's is one of several.

What if a tool supports MPP or L402 instead?

It gets recorded and partial credit now, and full credit once our canary can settle through that protocol. The benchmark rewards machine-payable, not one vendor.

Will Anchor Terminal take a cut of payments to tools?

No. Payments to a tool go to the tool, through letme or not, at the vendor's own price. Partner vendors pay Anchor Terminal Ltd 15% of what they bill through letme at the end of the month, and that number is never an input to a grade. The terms are on the letme page.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.