x402 Explained: How AI Agents Pay for Things Online
x402 is an open payment standard that revives the unused HTTP 402 Payment Required status code so software can pay for a web request without an account, a card or a human. A client requests a resource, the server answers 402 with payment instructions, the client signs a stablecoin payment and retries, and the server returns the content. It originated at Coinbase, and a foundation formed with Cloudflare in 2025 to standardise it. The adoption figures circulating are large and misleading. TRM Labs examined activity from May 2025 onward across Base, Solana and Polygon and found $52.7 million settled across 198.9 million x402 transactions, of which USDC accounted for 99.6 percent. After filtering out activity that was not commerce, about $25.62 million looked like genuine payments, and only 0.6 to 7.5 percent of that remaining value appeared to be agentic. The plumbing works. The story that autonomous agents are already transacting at scale does not survive the data, because an automated script and an AI agent leave identical traces onchain.
This article is for educational and informational purposes only and does not constitute financial, investment, or trading advice. Cryptocurrency and DeFi investments carry significant risk, including the potential loss of all invested capital. Always conduct your own research (DYOR) and consult a qualified financial advisor before making any investment decisions. Past performance does not guarantee future results.
A status code nobody used
The HTTP specification reserved status code 402 for "Payment Required" and then left it empty for about thirty years. Every other code found a job. This one waited for a use case that did not exist yet: a machine that needs to buy something, immediately, for a fraction of a cent, without a person in the loop.
x402 is the standard that finally uses it. Whether the machines doing the buying are actually AI agents is a separate question, and the honest answer is mostly not yet.
How the flow works
The mechanism is deliberately small. There is no new transport, no session and no account.
- A client requests a resource: an API endpoint, a dataset, an article, a model inference.
- The server responds 402 Payment Required, with instructions attached: the amount, the asset, the chain and where to send it.
- The client signs a stablecoin payment for that amount and repeats the request with the proof attached.
- The server verifies the payment and returns the content.
The entire cycle completes in seconds, and nothing about it requires the client to have registered, stored a card, or been a human being. For a server, it converts an audience of subscribers into an audience of anyone who can pay 30 cents, including software.
Most implementations put a facilitator between the server and the chain to verify and settle, so the origin server does not have to run blockchain infrastructure to accept a payment.
Who is behind it
x402 originated at Coinbase, and a foundation formed with Cloudflare in 2025 to push it as a shared standard rather than a single company's protocol. Stripe, Google and Cloudflare have all built support into their own services, which is the part that matters: a payment standard with one implementer is a product, and a payment standard with several is infrastructure.
The specification itself is public, and Coinbase publishes the developer documentation for implementing it on both the server and client side.
It is not the only proposal. Tempo, the payments chain incubated by Stripe and Paradigm, shipped a machine payments protocol alongside its mainnet launch in March 2026. Expect a standards fight rather than a coronation.
The numbers everyone quotes
Here is where the category gets interesting, and where most coverage stops reading.
Blockchain intelligence firm TRM Labs examined x402 activity from May 2025 onward across Base, Solana and Polygon. The analysis reported by PYMNTS found:
| Measure | Figure |
|---|---|
| --- | --- |
| Total settled value examined | $52.7 million |
| x402 settlement transactions | 198.9 million |
| Share settled in USDC | 99.6% ($52.47M of $52.68M) |
| Value that looked like genuine commerce after filtering | $25.62 million |
| Share of that commerce value appearing to be agentic | 0.6% to 7.5% |
Two things fall out of that table immediately.
The average transaction is about 26 cents. Divide $52.7 million by 198.9 million transactions and you get the shape of the traffic: enormous numbers of tiny payments, which is exactly what the standard was designed for and exactly what no card network could process economically.
Less than half the value looked like commerce at all, and of what remained, the agent share was somewhere between one payment in a hundred and one in thirteen. That is the number to remember the next time you read that agents are already transacting at scale.
Why is the agent share a range rather than a number?
This is the most important methodological point in the whole category, and it is not a criticism of TRM's work. It is a limit on what chain analysis can do.
An AI agent deciding to buy a dataset, and a cron job that buys the same dataset every hour, produce identical records onchain. Same wallet, same signature, same call. There is no field in the transaction that says "a model chose this". Any estimate of agentic share therefore relies on heuristics about timing, variety and behaviour, and those heuristics have wide error bars by construction.
So when a vendor tells you that agentic commerce is growing at some precise percentage, ask how they separated agents from scripts. If the answer is onchain data alone, the precision is decorative.
What this is actually good for today
Strip out the agent narrative and a real product remains.
- Paid APIs without contracts. A data provider can price per call and serve anyone, with no sales cycle, no minimum and no invoice.
- Metered access to content and models. Inference, transcription, search results and archives can all be sold by the request rather than the month.
- Machine-to-machine settlement inside one company. Teams already use it to meter internal services without building a billing system.
- The groundwork for agent commerce, which is the bet everyone is actually making. The rail needs to exist before the traffic arrives, and it now does.
If you are building the agents that would eventually use this, our guides to autonomous AI agents and agent interoperability cover the layers above the payment, and our comparison of agent sandboxes covers where that code runs.
What to watch before you build on it
Refunds and disputes. A card payment can be reversed; a settled stablecoin payment cannot. If your agent buys the wrong thing, recovery is a commercial conversation, not a chargeback.
Spending limits. An agent with a funded wallet and a bug is a budget with no floor. Whatever you build, the limit belongs outside the agent, enforced by the wallet or the facilitator rather than by a prompt instruction the model can talk itself out of.
Security research is active. Academic work has already examined free-riding and data-leakage risks in x402 flows. Treat the standard as young, because it is.
Jurisdiction and reporting. Thousands of micro-payments a day are still payments. If your business needs to account for them, build that in from the start rather than reconstructing it from chain data later.
Conclusion
x402 is a genuinely good piece of engineering: a dormant status code, a stablecoin, one retry, and suddenly software can buy things. The standard works, the volume is real, and the major infrastructure companies are behind it.
The agent story attached to it is running well ahead of the evidence. Nearly 200 million transactions have settled, most of the value is not identifiable as commerce, and the portion that looks autonomous is a single-digit percentage at best. Both of those things can be true at once: the rail is being built now, and the traffic it was built for has not arrived yet.
If you sell data or inference, it is worth implementing today for the human-directed automation that is already paying. If you are waiting for agents to pay you, watch the share rather than the headline.
This explainer is an editorial synthesis of protocol documentation and published analysis read on 29 September 2026 and linked inline. The transaction and agentic-share figures come from TRM Labs research as reported by PYMNTS; we did not independently reproduce them. We did not implement or test x402 in production, and we hold no position in any asset mentioned. This is not investment or legal advice.
Key Takeaways
- x402 uses the HTTP 402 status code, reserved in the original HTTP specification and unused for decades, to let a server quote a price to a machine and get paid in the same request cycle.
- The flow is a single retry: request, 402 with payment details, signed stablecoin payment attached, request again, content returned. No account, no card and no redirect to a checkout page.
- TRM Labs examined x402 activity from May 2025 across Base, Solana and Polygon and found $52.7 million settled across 198.9 million transactions, with USDC representing 99.6 percent of settled value.
- The same analysis found that after filtering non-commerce activity, about $25.62 million looked like genuine commerce, and only 0.6 to 7.5 percent of that value appeared to come from AI agents.
- The reason the agent share is a range rather than a number is that a scheduled script and an autonomous agent produce identical onchain records, so no amount of chain analysis can separate them cleanly.
- Tempo, the Stripe and Paradigm chain, launched a machine payments protocol alongside its mainnet in March 2026, so x402 is a leading standard rather than the only one.
- Average transaction size on this rail is tiny: $52.7 million across 198.9 million transactions is about 26 cents each, which tells you what it is actually being used for today.
Frequently Asked Questions
What is x402 in one sentence?
It is an open standard that lets a server respond to a web request with a price instead of a login prompt, and lets the client pay that price in stablecoins and retry, so software can buy access to data or an API without a human or an account.
Why use HTTP 402 rather than a normal checkout?
Because a checkout assumes a person. It needs an account, a card on file, a redirect and usually a session. A machine making one request for a fraction of a cent cannot do any of that economically, and the 402 status code was reserved for exactly this purpose and never used.
Are AI agents really paying for things with x402?
Some are, but far fewer than the headline numbers imply. TRM Labs estimated that only 0.6 to 7.5 percent of the genuine commerce value it identified appeared to be agentic. Most of the volume comes from automated scripts and testing, which look the same onchain.
Which stablecoin does x402 use?
Overwhelmingly USDC. In the TRM Labs analysis, $52.47 million of $52.68 million in settled value, or 99.6 percent, was settled in USDC. The standard itself is not tied to any single asset or chain, but practice so far has converged almost entirely on one stablecoin.
Do I need a blockchain wallet to accept x402 payments?
Yes, in the sense that settlement happens onchain and you need somewhere for the funds to arrive. Facilitator services handle the verification and settlement steps for servers that would rather not run blockchain infrastructure themselves, which is how most production implementations work in practice today.
Is x402 the only standard for machine payments?
No. Tempo launched a machine payments protocol with its mainnet in March 2026, built with Stripe, and other proposals exist in academic and industry work. x402 currently has the most visible adoption, helped by support from Coinbase, Cloudflare and Stripe.
About the Author
Elena Rodriguez
Developer Experience Editorial Desk
Developer Experience Editorial Desk · Web3AIBlog
Elena Rodriguez is a pen name for our developer-experience editorial desk. Posts under this byline are written and reviewed by working engineers covering full-stack development, Web3 dApp architecture, deployment workflows, build tooling, and developer productivity. The desk specializes in turning real production debugging — failed deploys, flaky tests, memory leaks, broken migrations — into reproducible field manuals. Code samples in our tutorials are built from and verified against the official SDKs and documentation, with library versions pinned, before publication.