---
title: "x402 payments · Sitebulb Labs"
description: "The x402 standard uses HTTP 402 to let agents pay for resources programmatically."
url: https://labs.sitebulb.com/docs/checks/commerce/x402/
---

# x402 payments

The x402 standard uses HTTP 402 to let agents pay for resources programmatically.

- Category

  [Commerce](https://labs.sitebulb.com/docs/checks/commerce)

- Standard

  - Emerging checkEmerging
  - Off by default, turn on in settings

## What it checks

x402 revives the long-unused HTTP `402 Payment Required` status. A paid endpoint answers an unpaid request with 402 and the payment terms; the agent pays and retries with proof of payment.

The extension requests `/.well-known/x402` and `/.well-known/x402.json`, in that order, and passes on the first one that returns a non-empty JSON document. If neither is there, it checks whether the homepage response carries an `X-402` or `WWW-Authenticate` header. Any `WWW-Authenticate` header counts, so a page behind HTTP authentication also passes.

Commerce protocols are new, and most sites have no reason to support them, so absence is **N/A** rather than a failure.

## Results

| Status   | When                                                                                         |
| -------- | -------------------------------------------------------------------------------------------- |
| **Pass** | One of the paths returns a non-empty JSON document, or the homepage sends one of the headers |
| **N/A**  | Nothing was found                                                                            |

## How to fix

Implement the x402 flow on the endpoints you charge for, and publish a descriptor at `/.well-known/x402` so agents can find out before they hit a 402. Serve it as JSON (`Content-Type: application/json`); the extension only confirms a JSON document is there and does not validate its contents.

These standards are still settling, so follow the protocol’s own documentation for what the descriptor should contain.
