Skip to main content
The x0 protocol implements the HTTP 402 Payment Required status code for machine-to-machine payment negotiation. This enables autonomous agents to discover, negotiate, pay for, and consume services without human intervention.

Protocol Flow

Payment Request (402 Response)

When a service requires payment, it returns HTTP 402 with an X-PAYMENT header:

Payment Proof (Subsequent Request)

After submitting the payment transaction on-chain, the agent includes proof in its next request:
The service verifies:
  1. Transaction exists on-chain and is confirmed
  2. Transfer amount matches requested amount
  3. Recipient matches service wallet
  4. Challenge hash in memo matches the nonce

Challenge Hash

To bind the payment to the specific request, a challenge hash is computed: h=SHA-256(recipientamountnonce)h = \text{SHA-256}(\text{recipient} \| \text{amount} \| \text{nonce}) This hash is included in the transaction memo, allowing the service to verify the payment was made for this specific request.

SDK Helpers

Security Properties

  1. Replay protection — Each request has a unique nonce; the challenge hash binds payment to the specific request
  2. Expiration — Payment requests expire, preventing agents from paying stale invoices
  3. Amount verification — The on-chain transfer amount is verified against the requested amount
  4. Policy enforcement — The agent’s x0-guard policy still applies to 402 payments, enforcing spend limits
Last modified on February 8, 2026