Skip to content
SpendTheBits

x402 · agentic payments

x402 payments: get paid by AI agents

The next customers of your API won’t have a credit card. They’ll have a wallet. Your SpendTheBits @handle is an x402-payable endpoint: AI agents pay you in USDC over plain HTTP — no invoices, no accounts, no custodian. Price a resource once; get paid every time a machine wants it.

How a payment happens

One HTTP round trip, one on-chain settlement

402

The agent asks, you quote

An agent requests your resource and receives HTTP 402 Payment Required with a machine-readable price: amount, asset (USDC), and where to pay — your @handle's endpoint.

✍️

The agent signs, gas-free

It signs an EIP-3009 USDC transfer authorization off-chain — no gas token needed — and retries the same request with the payment attached.

✓

Verified, served, settled

The payment verifies and settles on-chain to addresses only your keys control. The agent gets the resource; you got paid, machine-to-machine, with no invoice and no custodian.

GET /@stbclaudeprod/proof/ HTTP/1.1
Host: x402.spendthebits.com

HTTP/1.1 402 Payment Required
PAYMENT-REQUIRED: <base64 JSON>
  { "x402Version": 2, "accepts": [
      { "scheme": "exact", "network": "eip155:8453", "amount": "10000",
        "asset": "0x8335…2913" /* USDC on Base */, "payTo": "0xBe5c…9D30" },
      { "scheme": "exact", "network": "eip155:137",   … },   /* Polygon  */
      { "scheme": "exact", "network": "eip155:42161", … },   /* Arbitrum */
      { "scheme": "exact", "network": "solana:5eyk…vdp", … } /* Solana   */ ] }

GET /@stbclaudeprod/proof/ HTTP/1.1
Host: x402.spendthebits.com
PAYMENT-SIGNATURE: <base64 JSON: accepted + signed EIP-3009 authorization>

HTTP/1.1 200 OK                          — 1.4 s after the first request
PAYMENT-RESPONSE: { "success": true, "network": "eip155:8453",
  "transaction": "0x71f4c1dc…f10b3" }    — 0.01 USDC settled on Base, 2 Sep 2026

For client developers

Pay a handle with a stock x402 client

A regular x402 client can pay any SpendTheBits handle, and it needs no lookup first. A handle URL is a standard x402 resource: the unpaid request returns the price, token, network and seller address, the client signs a USDC authorization, and the retry returns the resource with a settlement receipt. We ran the stock @x402/fetch and Python x402 clients against a live handle, and neither needed a line of SpendTheBits-specific code.

TypeScript

npm install @x402/fetch @x402/evm viem
import { wrapFetchWithPaymentFromConfig, decodePaymentResponseHeader } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

const account = privateKeyToAccount(process.env.BUYER_KEY);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  // the network you hold USDC on — eip155:8453 is Base
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://x402.spendthebits.com/@stbclaudeprod/proof/");
console.log(res.status, await res.text());
console.log(decodePaymentResponseHeader(res.headers.get("PAYMENT-RESPONSE")));

Python

pip install "x402[evm,requests]"
import os
from eth_account import Account
from x402.client import x402ClientSync
from x402.http.clients.requests import x402_requests
from x402.mechanisms.evm import EthAccountSigner
from x402.mechanisms.evm.exact.register import register_exact_evm_client

client = x402ClientSync()
signer = EthAccountSigner(Account.from_key(os.environ["BUYER_KEY"]))
register_exact_evm_client(client, signer, networks="eip155:8453")  # Base

r = x402_requests(client).get("https://x402.spendthebits.com/@stbclaudeprod/proof/")
print(r.status_code, r.text, r.headers.get("PAYMENT-RESPONSE"))

curl (read the quote)

no wallet needed
curl -s -D - -o /dev/null https://x402.spendthebits.com/@stbclaudeprod/proof/ \
  | awk 'tolower($1)=="payment-required:" {print $2}' | tr -d '\r' | base64 -d
Lookup or API key
None. The 402 carries everything a client needs.
Gas
None. The payment is a signed EIP-3009 authorization.
Network
Register the one you hold USDC on. A handle quotes several and a stock client signs the first it supports.
Browsers
Supported. The endpoints send CORS headers and expose the payment headers.

For buying agents

Buy a gift card over x402

Every gift card in the SpendTheBits store is an x402 resource. An agent that holds USDC on Base can buy a real Amazon, Tim Hortons or Starbucks card with a stock x402 client, and the card lands in its owner’s app, in the owner’s name. The money goes from the agent to a per-order contract that can only forward it to the card provider or refund the agent. We never hold it.

https://x402.spendthebits.com/@stb/cards/<country>/<brand>/<amount>/
                                          usa      amazon-com  25

GET /@stb/cards/usa/amazon-com/25/          → 402  quote fee (a few cents)
    PAYMENT-SIGNATURE: <signed>             → 201  { order_id, total_usdc, pay_url, status_url, claim_token }
POST <pay_url>  PAYMENT-SIGNATURE: <signed> → 200  the order, paid to its forwarder contract
GET  <status_url>  X-Claim-Token: <token>   → awaiting_payment → processing → completed (about 5 minutes)
1

Lock the price

Request the card URL. The 402 quotes a small fee; paying it creates the order at the provider's exact price and returns the total, a pay link, a status link and a claim token. The total includes the card, a small service fee and the bridge fee ceiling.

2

Pay the order

Pay the total to the order's forwarder contract on Base. Its terms are fixed in its address: forward to the card provider before the deadline, pay the quoted fee, or refund the agent. A second payment is refunded, never burned.

3

Poll, then it is in the app

Poll the status link with the claim token. The USDC is bridged to the provider in about a minute and the card is issued a few minutes later. It appears in the owner's orders, tagged with the agent's name, code behind the device unlock.

Who can buy
Any agent key registered under Agent budgets in the app, with gift cards switched on by its owner. An unknown key is refused before any payment.
Limits
The owner sets a per-card and a monthly limit. Over a limit, the store asks the owner instead: one tap on the phone approves it. The store itself caps agent orders per card.
Client cap
Stock clients refuse payments above about a dollar by default. Set your client's per-payment cap above the card's total, e.g. spendControls: { maxAmountPerPayment: "$30" } in @x402/fetch.
Referrals
Add ?ref=@handle to the card URL. The referrer's share of the service fee goes to an ownerless, immutable split contract on Base, which pays it out on-chain once about $0.50 has built up there, or 24 hours after the oldest unpaid share, whichever comes first. It is not paid in the purchase transaction itself.
Card codes
Never in the HTTP response by default. If the owner allows it for one agent, the code is served once, from a separate reveal link, and never again.
Gifting
Coming: a card sent to another SpendTheBits @handle, issued in the recipient's name. Not live yet; the store refuses a recipient today.
Still non-custodial. Agent payments settle on-chain to addresses only your keys control. We facilitate the protocol handshake; we never hold the money. See the security model →

Built in the open

Proven on Circle’s Arc

We built and demonstrated these agentic payment flows on Arc, Circle’s stablecoin-native blockchain, as part of Circle’s developer program — end to end, from the 402 challenge to on-chain USDC settlement.

Read the Arc build write-up (PDF)

Why an @handle beats an API key

An API key gates access; an @handle gets you paid. It’s human-readable, it resolves to addresses your device derived, it doubles as a Lightning address for Bitcoin — and every payment to it is final, on-chain, and yours.

Further reading

Insights on agent payments

Questions & answers

Agent payments: common questions

What is the x402 protocol?+

x402 is an open payment protocol built on HTTP's 402 Payment Required status code. A server quotes a price in a machine-readable header; the client — typically an AI agent — signs a stablecoin payment authorization and retries the request with it attached. Once the payment verifies, the resource is served. It turns any URL into something an agent can pay.

Can AI agents pay me on SpendTheBits?+

Yes. Your @handle doubles as a public x402-payable endpoint. You attach a USDC price to a resource — an API route, a dataset, a report — and any x402-capable agent can pay it and get the resource in one round trip, with settlement verified on-chain.

Can a regular x402 client pay a SpendTheBits handle?+

Yes, and no lookup is needed first. A handle URL is a standard x402 resource: an unpaid request answers 402 Payment Required with the price, the token, the network and the seller's address as one x402 v2 quote in the standard PAYMENT-REQUIRED header, repeated identically in the body. Stock clients such as @x402/fetch and the Python x402 package read that quote, sign and retry with no SpendTheBits-specific code. Runnable examples are on GitHub at github.com/jkambo1986-collab/x402-handle-examples.

Do agents pay gas fees when they pay me?+

No. Payments use EIP-3009 transfer authorizations: the agent signs an off-chain authorization and the settlement layer submits it, so the paying agent needs USDC but not native gas tokens.

What is USDC on Arc?+

Arc is Circle's purpose-built blockchain for stablecoin finance, where USDC acts as the native asset. SpendTheBits built and demonstrated x402 payment flows on Arc during Circle's developer program — see our hackathon write-up linked on this page.

Can an AI agent buy a gift card over x402?+

Yes. Every gift card in the SpendTheBits store is an x402 resource with a URL of the form x402.spendthebits.com/@stb/cards/<country>/<brand>/<amount>/. The agent pays a small quote fee to lock the provider's exact price, then pays the order to a per-order contract that can only forward the money to the card provider or refund the agent. The card is issued in the agent owner's name and appears in their SpendTheBits orders; the agent never receives the card code unless the owner allows it.

Does SpendTheBits hold the money agents pay me?+

Never. Settlements pay on-chain addresses that only your device's keys control — the same fully non-custodial model as the rest of the app. A small service fee, under 1%, applies on settled payments and is disclosed up front.

Claim your @handle before the agents come knocking.