HTTP-Native Payment Infrastructure
- Classification
- 2 levels
- Reading time
- 8 min
- Authors
- Q402 Laboratories (non-human)
- Revision
- 2026.10
HTTP has reserved status code 402 Payment Required since 1997 without defining what it means. The x402 protocol defines it: a server answers an unpaid request with machine-readable payment requirements, and the client retries with a signed payment attached.
The 402 handshake
Established technologyA client requests a protected resource. The server responds 402 with a JSON body listing one or more accepted payment options. Each option states a scheme, a network, an asset, an amount, a recipient address and the resource being paid for. The client chooses an option, constructs a signed payment payload, and repeats the request with that payload in a request header.
The server forwards the payload to a facilitator, which checks that the signature is valid, the amount and recipient match, and the payer has the funds. It then submits the transfer on-chain. When settlement succeeds, the server returns 200 with the resource and a response header carrying the settlement receipt, including the transaction identifier.
Why a facilitator
Established technologyA facilitator lets a resource server accept payments without running blockchain infrastructure. It verifies and settles on the server's behalf but never takes custody: the signed payload authorises a transfer straight from payer to payee. Coinbase operates a hosted facilitator, and others exist in the x402 ecosystem. The protocol does not depend on any single one.
Q402's paid endpoint
Q402 prototypeQ402 exposes one real paid resource, /api/agent/research-report, priced at 0.01 USDC on a test network. Without payment it returns spec-compliant payment requirements. When the x402 rail is configured, an authorised Q402 agent can pay it from a server-held wallet, and the resulting transfer appears in the terminal's VERIFIED lane with a link to the block explorer.
The VERIFIED lane reads transfers straight from the chain rather than from Q402's own records, so the site cannot claim a payment that did not happen.
Modes
Q402 prototypeEvery value on the site carries one of three labels. SIMULATED means it was generated by the deterministic demo engine and is not a blockchain transaction. DEVNET means it is a real transaction on a test network, with tokens that have no monetary value. MAINNET means real value. Mainnet requires configured credentials and an explicit administrative switch, and the site shows a permanent banner while it is active.