x402 payments
The x402 standard uses HTTP 402 to let agents pay for resources programmatically.
- Category
- Commerce
- Standard
- Emerging checkEmerging
- Off by default, turn on in settings
What it checks
x402 revives the long-unused HTTP 402 Payment Required status. A paid endpoint answers an unpaid request with 402 and the payment terms; the agent pays and retries with proof of payment.
The extension requests /.well-known/x402 and /.well-known/x402.json, in that order, and passes on the first one that
returns a non-empty JSON document. If neither is there, it checks whether the homepage response carries an X-402 or WWW-Authenticate header.
Any WWW-Authenticate header counts, so a page behind HTTP authentication
also passes.
Commerce protocols are new, and most sites have no reason to support them, so absence is N/A rather than a failure.
Results
| Status | When |
|---|---|
| Pass | One of the paths returns a non-empty JSON document, or the homepage sends one of the headers |
| N/A | Nothing was found |
How to fix
Implement the x402 flow on the endpoints you charge for, and publish a descriptor at /.well-known/x402 so agents can find out before they hit a 402. Serve it as JSON (Content-Type: application/json); the extension only
confirms a JSON document is there and does not validate its contents.
These standards are still settling, so follow the protocol’s own documentation for what the descriptor should contain.