{
  "what": "x402 payment flows, honest and otherwise",
  "protocol": "x402 v2 (header PAYMENT-REQUIRED / PAYMENT-SIGNATURE / PAYMENT-RESPONSE) and x402 v1 (requirements in the 402 JSON body / X-PAYMENT / X-PAYMENT-RESPONSE) in the same responses; the wrong-network scenario is v2-only because v1 cannot name a chain outside its closed list",
  "default_network": "base-sepolia",
  "networks": {
    "base": {
      "caip2": "eip155:8453",
      "usdc": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "real_money": true
    },
    "base-sepolia": {
      "caip2": "eip155:84532",
      "usdc": "0x036CbD53842c5426634e7929541eC2318f3dCF7e",
      "real_money": false
    }
  },
  "pay_to": "0x2b14ad50d63c7fee5a33847f95153ac37a690170",
  "price": {
    "default_usd": 0.01,
    "min_usd": 0.001,
    "max_usd": 1,
    "param": "amount"
  },
  "facilitators": {
    "note": "/402/pay forwards your PAYMENT-SIGNATURE (or X-PAYMENT) to the first of these that answers, in order; the v1 lists differ because not every facilitator speaks x402 v1",
    "base": [
      "https://api.cdp.coinbase.com/platform/v2/x402",
      "https://facilitator.payai.network",
      "https://facilitator.xpay.sh",
      "https://v2.facilitator.mogami.tech",
      "https://facilitator.heurist.xyz"
    ],
    "base-sepolia": [
      "https://x402.org/facilitator",
      "https://facilitator.xpay.sh",
      "https://v2.facilitator.mogami.tech",
      "https://facilitator.payai.network"
    ],
    "v1": {
      "base": [
        "https://facilitator.payai.network",
        "https://facilitator.xpay.sh",
        "https://facilitator.heurist.xyz"
      ],
      "base-sepolia": [
        "https://x402.org/facilitator",
        "https://facilitator.xpay.sh",
        "https://facilitator.payai.network"
      ]
    }
  },
  "scenarios": {
    "/402/pay": "Returns 402 with x402 requirements in both generations at once: v2 in the PAYMENT-REQUIRED header, v1 in the JSON body (Base Sepolia unless you ask for mainnet with /402/pay/base or ?network=base). Send a valid PAYMENT-SIGNATURE (v2) or X-PAYMENT (v1) and the payment is verified and settled through a facilitator; you get a 200 with the transaction hash and a receipt in PAYMENT-RESPONSE (v2) or X-PAYMENT-RESPONSE (v1).",
    "/402/never": "Always 402, with perfectly valid requirements. Any PAYMENT-SIGNATURE (v2) or X-PAYMENT (v1) you send is ignored. Nothing is verified or settled. Does your client stop after one retry, or loop and re-sign forever?",
    "/402/reject": "Valid 402; then every payment is rejected with a 402 carrying an error (default insufficient_funds; pick another with ?reason=). Nothing is settled. A client should surface the reason and stop, not re-sign.",
    "/402/slow": "Valid 402; after you pay, the server sits on the request for ?seconds= (default 8, max 10) and then answers 504 with no receipt. In the real world you would not know whether you were charged. Here, nothing was.",
    "/402/crash": "Valid 402; after you pay, a 500 with no PAYMENT-RESPONSE. A real server might have settled before it crashed. This one never does. Does your client treat this as \"paid\" or \"unpaid\"?",
    "/402/bad-receipt": "Valid 402; after you pay, a 200 whose receipt headers — PAYMENT-RESPONSE (v2) and X-PAYMENT-RESPONSE (v1) — are both garbage, not valid base64 JSON. Nothing was settled. Does your client still hand you the body, or throw it away because the receipt is bad?",
    "/402/overpriced": "A valid 402 that asks for 1,000,000 USDC. A client with a spending limit should refuse to sign. If yours signs anyway, the response says so; the authorization is discarded and never settled. A less friendly server would have taken it.",
    "/402/wrong-network": "A valid-looking 402 whose only option is on eip155:424242, a chain nobody runs. A client should report \"no supported network\" and not sign. Nothing can be settled here by anyone.",
    "/402/broken": "GET /402/broken lists the flavors: not-base64, not-json, no-accepts, empty-accepts, no-extra, no-resource, version-99, decimal-amount, missing-header, v1-body. Each is a 402 that a sloppy client will mis-parse."
  },
  "only_this_one_settles": "/402/pay",
  "pay_urls": {
    "base": "/402/pay/base",
    "base-sepolia": "/402/pay/base-sepolia"
  },
  "verified": {
    "as_of": "2026-10-06",
    "first_external_payment": "On 2026-09-01 at 21:32:11 UTC a payer that is not this project settled /402/pay/base for the first time: 0.01 USDC on Base mainnet, tx 0x645b92cd93250785c5208821f22328087389803ed2178566e871f2edeed5686a, from 0x54e163e9b8edda194d83f46add921bfa5fc5f4e0 — the paying scout of nohumans.directory, whose registry probes listed x402 endpoints with real money (user agent nohumans-scout/1.0). Booked as revenue on /books with its tx hash; the first revenue this site has earned",
    "second_external_payer": "On 2026-09-24 between 19:23:41 and 22:17:01 UTC a second payer that is not this project settled /402/pay/base five times, 0.01 USDC each, from 0x556d8a86991b56646f98040c8c8298c5053d0484 (tx 0xfd6bbfa2…, 0x62d951ac…, 0xee38d4df…, 0x09fcc3e1…, 0xe3e7b9a4…; full hashes on /books). Zone analytics show five matching 200s from the US with an EMPTY user agent, and the same address paid dozens of other x402 endpoints in bursts the next day, so this reads as an automated buyer walking a registry rather than a person; which registry, and whether it paid with the v2 header or the v1 body, is not knowable here. nohumans.directory's scout also paid a second time on 2026-09-22 (tx 0x74276696…). All six are booked as revenue with their tx hashes",
    "third_external_payer": "On 2026-10-06 at 06:01:41 UTC a third payer that is not this project settled /402/pay/base: 0.01 USDC, tx 0xdfa8f4f39c769574f617d2a5b4a5960332f2ce5ee128e6f8d0e0e4253bedc379, from 0xc9c7b38c0942914fc8ea12063bc92dcd3b581670. Zone analytics show the one matching 200 that day, in the 06:00 UTC hour from the US, with user agent vet402-observatory-l1/1.0 — vet402's x402 observatory, whose L1 \"settle-through\" measurement buys once from every endpoint in the public discovery catalogue to see whether a real purchase settles; its public seller page for badhttp.dev records the same purchase (\"delivered\", bought by the census, next purchase not before 2026-10-12). It records the receipt in the PAYMENT-RESPONSE header, so this is the first external settlement whose generation is known: v2. Booked as revenue on /books with its tx hash",
    "first_external_testnet_payment": "On 2026-09-16 at 08:51:40 UTC a payer that is not this project settled /402/pay (Base Sepolia, test USDC, no dollar value) for the first time: 0.01 test USDC, tx 0x3c4d55346397bc2765f838f7a5741142d317df7156fd5867b1d756977e1e58b2, from 0x4f26bcacaf89aad3bb6b0c6858523b84a7ae7776 (the authorizer of the on-chain transfer; the time is the block timestamp). Cloudflare zone analytics show the matching 200 on /402/pay with user agent curl/8.21.0; they log path, status, time and user agent but no request headers or body, and this server keeps no request logs of its own, so whether the payment rode the v2 PAYMENT-SIGNATURE header or the v1 X-PAYMENT body is not known. Not revenue — testnet USDC has no value — and not booked; recorded because it is the first settlement anyone but this project or nohumans.directory has ever completed against this host",
    "second_external_testnet_payer": "On 2026-10-05 a second payer that is not this project settled /402/pay/base-sepolia fourteen times between 13:54:08 and 18:23:50 UTC (block timestamps), 0.01 test USDC each, from 0xb24854b51f81649a624e59e17ac2b950e911a5bc (the first three: tx 0x9459d40f…, 0xae8ae5a5…, 0x1e6c13c8…; the rest 17:07–18:23 UTC, all on Base Sepolia). Zone analytics show fourteen matching 200s on /402/pay/base-sepolia from Iraq with the user agent \"node\". Not revenue, not booked; recorded as the second stranger to complete a testnet settlement here",
    "exercised": "SETTLEMENT, end to end on BOTH networks, both client generations against production (2026-08-28). Base Sepolia (test USDC): v2 official @x402/fetch 2.23.0 — tx 0xf35d92c571e4af086b8cf01d87e242e94d6406fff46c5a3c15cbcf787ec31a0c; v1 legacy x402-fetch 1.2.0 via the body and X-PAYMENT — tx 0x0b6b47a003f84096bf59971d665509be2ba54ee467d70dec7c6e5450dffacd62 (both settled by x402.org). Base mainnet (real USDC, a self-test: the payer is project-controlled and the 0.02 USDC moved between our own addresses — booked on /books as working capital, not revenue): v2 tx 0x8a331a0a28a26d290984c34bd12ae03bdc31603856b4e46bace3d2045cddc089; v1 tx 0x629b1a478e88c8be043ee0e8ebac67169a386192fde388b9a616fc850b5010b8 (both settled by xpay). Receipts arrived in PAYMENT-RESPONSE (v2) and X-PAYMENT-RESPONSE (v1) and decoded success:true every time. 2026-10-05: PayAI moved to the front of the mainnet facilitator lists and settled a v2 self-test the same minute — tx 0x9eed7b72bdd445317b1a59e5c7cc12f9a44b857132dcc743121b366261e6ca75 (0.01 USDC between project addresses, booked as a labeled transfer, not revenue). 2026-10-05 16:36:01 UTC: the operator stored the CDP facilitator key, Coinbase's CDP facilitator took the front of the mainnet v2 chain, and settled a v2 self-test — tx 0x30e24c0a8d200180906adf54ba011fd26aa2c4fb070ad78c870debd2d286a748 (block 52214407; 0.01 USDC between project addresses, booked as a labeled transfer, not revenue)",
    "catalogues": "Listed in PayAI's public Bazaar (GET https://facilitator.payai.network/discovery/resources?payTo=<receive address>) since 2026-10-05T02:48:53Z, written by that facilitator when it settled the self-test above — its documented and only route in (\"there is no registration form, account, or manual submission\"). Listed in Coinbase's CDP Bazaar since 2026-10-05T16:36Z (GET https://api.cdp.coinbase.com/platform/v2/x402/discovery/merchant?payTo=<receive address>, public, no key), written by that facilitator when it settled the self-test above — the only route in; it stays listed while a settlement through that facilitator happens within its 30-day window. Also listed, by registration, on x402scan, nohumans.directory (paid-verified), x402-list.com and 402index.io. Why it matters: the anonymous buyer of 2026-09-24 paid 92 sellers in two days, 81 of them on x402scan, 66 in the CDP Bazaar, 23 in PayAI's",
    "not_yet_exercised": "a v1 (X-PAYMENT) payment known to be from anyone other than this project; a direct USDC transfer (a donation) rather than an x402 settlement; a payment for any amount other than the default 0.01 (every external settlement so far has been the default); a second purchase by the same observatory (vet402 says it re-buys a listing at most once every 6 days)"
  }
}
