Walkthrough · selling per call (x402) · checked 2026-10-03
Walkthrough: sell one narrow service per call over x402
Expose one HTTP endpoint that returns a finished work product, such as a website audit or a written brief. Protect it with x402 middleware, test it on Base Sepolia with the free x402.org facilitator, then move to Base mainnet with the Coinbase CDP facilitator and a receiving wallet whose keys you, the owner, hold. Discovery in the CDP Bazaar is automatic after the first settled payment.
Demand is the gap, and raw buyer counts mislead. Of the 27 x402 sellers with at least $1,000 and 5 buyers in the 30 days to 3 October 2026, at most 1 sells agent work (AX1, $6,116, partly), and its top 5 buyers share one funder. Most agent-work-like sellers take $100 to $350 a month. Tracing showed that published buyer counts for the largest sellers lead back to the seller or to one funder. The buyer trace.
Seller KYC on the CDP facilitator: no requirement found, not ruled out. The CDP FAQ says the API key ID and secret are "enough to run a seller" with an address you control; the CDP Terms reserve identity checks, and that page returned HTTP 403 on 3 October.
Before you start
- A narrow service the agent can do reliably and that you can describe in <=500 characters (Bazaar rejects longer descriptions).
- If the service calls a model: a provider API key under commercial/API terms in the owner's name (never a consumer chat subscription or Claude/ChatGPT/Gemini/Copilot login).
- A public HTTPS host on a dedicated domain (tunnels such as ngrok are ranked lower).
- An EVM receiving address whose keys the owner holds (and optionally a Solana address).
- A Coinbase Developer Platform account and API key (mainnet only).
- Node.js 22+ or Python 3.10+.
Who acts, step by step
Each square is a step; select one to jump to it. Orange steps are the owner’s, and they include every account, identity, wallet and payment action.
- Owner
- Agent
- Owner or agent
- Platform
The steps
Step 1. Owner via UI
Choose one narrow, finished work product and a fixed price. Reference prices captured 2026-10-03: website audit bundle $0.15 (hubvibe-io), deep person research dossier $0.05 (OneShot, Bazaar listing), AI-written token verdict $0.02 (AX1, Bazaar), web-search tool $0.005 (Agent402), chat completion $0.002 (BlockRun), Frantic bounty funding $2.00, on-page audit $3.00 (SCVD). Prefer a work product (audit, brief, monitored change summary) over a raw model call.
- Example
- https://shaduf.ai/p/agentic-freelance/assets/data/x402_population.json -> probes.live_402_captures
- Cost
- none
- What can go wrong
- Pricing below your model+hosting cost per call; choosing a commodity (search, chat) where large resellers already sell at $0.002-$0.01.
- Source
- https://www.x402scan.com/
Step 2. Owner via UI Rules gate: stop here if it fails
If the endpoint wraps a model, decide which credential runs it. Reselling model access or intermediating someone else's usage is forbidden at Anthropic (incl. Claude Code), OpenAI, Google and GitHub Copilot; consumer-plan/OAuth automation is restricted. Safe reading: (a) the endpoint sells YOUR work product built with a model, not access to the model; (b) it runs on an API key under commercial terms in the owner's name; (c) never on a consumer subscription, a Claude Code/Codex/Gemini CLI login, or a shared/bought key; (d) do not offer an OpenAI-compatible pass-through (/v1/chat/completions) of a closed provider. Selling raw per-call inference of a closed provider (as several x402 sellers do) is the case these rows forbid unless the provider expressly approves. Not legal advice.
- Example
- https://shaduf.ai/p/agentic-freelance/assets/data/rules.json rows listed in rule_refs
- Cost
- provider API usage at list price
- What can go wrong
- Account termination at the provider; buyer chargeback impossible but provider ban ends the business; output terms may still restrict certain uses.
- Rule rows
- anthropic-resale_sharing-4anthropic-resale_sharing-3anthropic-resale_sharing-2openai-resale_sharing-4openai-resale_sharing-5openai-resale_sharing-3google-resale_sharing-2github-copilot-resale_sharing-2anthropic-automation_ai-1anthropic-automation_ai-2anthropic-output_use-2openai-output_use-1google-output_use-1github-copilot-output_use-1google-automation_ai-1
- Source
- https://code.claude.com/docs/en/legal-and-compliance
Step 3. Owner via UI
Prepare the receiving wallet (payTo) whose keys you hold, separate from any wallet the agent can sign with. One EVM address covers Base and other EVM networks; Solana needs its own address. Self-custody is allowed; Coinbase Business/Prime/retail deposit addresses are optional and bring their own account verification.
- Example
- https://docs.cdp.coinbase.com/x402/seller/quickstart#pay-to-address
- Cost
- none
- What can go wrong
- payTo flagged by OFAC/KYT screening (payments decline with kyt_risk_detected); agent given signing keys to the payTo wallet.
- Rule rows
- x402-cdp-kyc_payout_eligibility-5x402-cdp-kyc_payout_eligibility-4
- ID and payout gate
- x402-per-call-endpoints
- Source
- https://docs.cdp.coinbase.com/x402/seller/quickstart
Step 4. Owner via CLI
Build and test on Base Sepolia with the public x402.org facilitator (no account, no API key, testnet only). Use the official middleware example; set the route, price, testnet network (eip155:84532) and your payTo. Fund a separate test buyer wallet from a testnet faucet and make one paid test call from your own client.
- Example
- https://docs.x402.org/getting-started/quickstart-for-sellers (facilitator URL https://x402.org/facilitator; network eip155:84532)
- Cost
- $0 (testnet USDC)
- What can go wrong
- Testing against mainnet by mistake; facilitator mismatch between test and production.
- Rule rows
- x402-org-account_identity-1
- Source
- https://docs.x402.org/getting-started/quickstart-for-sellers
Step 5. Owner via UI
Open a CDP account and create an API key for the CDP Facilitator (mainnet). The documented seller credential is the API key ID and secret; a wallet secret is needed only if CDP should provision the payTo wallet. Carry-over finding: no CDP text found requires identity KYC of a seller using an owner-held payTo; the CDP API overview requires a verified business account only for custodial API groups, which do not list x402; the CDP Terms reserve the right to require identity checks (quote from 2 October; the page returned 403 on 3 October, and on 4 October it returned 200 with the quote still present). Treat KYC as possible but not documented.
- Example
- https://portal.cdp.coinbase.com/api-keys/secret (owner action; store the secret in a secrets manager, never in the repo)
- Cost
- Facilitator: first 1,000 on-chain tx/month free, then $0.001 each
- What can go wrong
- Coinbase requests identity or blocks a jurisdiction (not documented, cannot be ruled out); API key leaked by the agent.
- Rule rows
- x402-cdp-account_identity-1x402-cdp-account_identity-2x402-cdp-kyc_payout_eligibility-3x402-cdp-kyc_payout_eligibility-2
- ID and payout gate
- x402-per-call-endpoints
- Source
- https://docs.cdp.coinbase.com/x402/support/faq
Step 6. Owner via CLI
Add the middleware from the official CDP quickstart (TypeScript createX402Server + paymentMiddlewareFromHTTPServer, or Python x402ResourceServer + PaymentMiddlewareASGI). Keep environment 'development' until tests pass. Note: 'production' is the default if the option is omitted, which means real funds.
- Example
- https://docs.cdp.coinbase.com/x402/seller/quickstart (section 2. Price a route) - copy code from the docs, not from third parties
- Cost
- hosting
- What can go wrong
- Omitting environment and going live unintentionally; description >500 chars rejected by facilitator.
- Rule rows
- x402-cdp-account_identity-2
- Source
- https://docs.cdp.coinbase.com/x402/seller/quickstart
Step 7. Owner via API
Read-only check of your own endpoint: one unauthenticated GET (or the method you protect) should return HTTP 402 with a PAYMENT-REQUIRED header whose payTo, network, asset and amount are what you intended. Optionally call Coinbase's validate endpoint (no API key).
- Example
curl -i https://your-domain.example/report # expect HTTP 402; decode the base64 PAYMENT-REQUIRED header. Validator: POST https://api.cdp.coinbase.com/platform/v2/x402/validate {"resource":..., "method":"GET"}- Cost
- none
- What can go wrong
- Endpoint answers 401/405 to GET (several live sellers did), so discovery tools cannot read the price.
- Source
- https://docs.cdp.coinbase.com/x402/seller/get-discovered
Step 8. Owner via CLI
Switch to mainnet: environment 'production' (TypeScript) or eip155:8453 (Python), confirm the payTo can receive on mainnet, serve over public HTTPS, move the API key to secret storage.
- Example
- https://docs.cdp.coinbase.com/x402/seller/quickstart (section 5. Move to production)
- Cost
- $0.001 per on-chain settlement above 1,000/month
- What can go wrong
- Testnet payTo left in config; secrets in plain files.
- Rule rows
- x402-cdp-kyc_payout_eligibility-1x402-cdp-kyc_payout_eligibility-4
- ID and payout gate
- x402-per-call-endpoints
- Source
- https://docs.cdp.coinbase.com/x402/support/faq
Step 9. Owner or agent via API
Get discovered: there is no form. The CDP Bazaar indexes the resource 10-15 minutes after the first successful settled payment through the CDP Facilitator, using the metadata your 402 returns; ranking uses buyer reach, volume and recency over 30 days; there is no delisting. x402scan has an 'Add API' page (https://www.x402scan.com/resources/register; requirements not read, page is client-rendered).
- Example
- Check your listing read-only: GET https://api.cdp.coinbase.com/platform/v2/x402/discovery/resources (public, no auth) and search for your payTo
- Cost
- one real paid call (owner pays own endpoint once)
- What can go wrong
- Owner self-pays to trigger listing: that payment is operator-class revenue and must not be counted as demand. Ranking rewards transaction volume, an incentive for wash traffic.
- Rule rows
- x402-cdp-account_identity-3
- Source
- https://docs.cdp.coinbase.com/x402/seller/get-discovered
Step 10. Owner via on-chain
Judge demand by distinct paying wallets and their funding, not by transactions. Count your own test/listing payments as operator; check whether top buyers are funded by you or by each other within two hops; report top-1 and top-5 buyer shares. x402scan shows unique buyers per payTo; buyer tracing needs an explorer.
- Example
- https://www.x402scan.com/recipient/<your payTo> (read-only)
- Cost
- none
- What can go wrong
- Mistaking 1-2 high-volume wallets (often the seller's own or a partner's) for a market; the population scan found sellers with 4,800 buyers and 1 tx each (one-off sale pattern) and six payTos with exactly 5 buyers each.
- Source
- https://www.x402scan.com/
Step 11. Owner via CLI
Safety controls: run the agent behind the endpoint in a sandbox or separate machine user with no access to the payTo keys, CDP secret or browser profiles; treat request bodies as untrusted input (task-text injection); pin and review any skills/MCP servers the agent uses; never let the agent follow remotely updated instruction files; patch the agent runtime.
- Example
- https://shaduf.ai/p/agentic-freelance/assets/data/security.json owner_control fields for the incidents listed in rule_refs
- Cost
- none to low
- What can go wrong
- Buyer-supplied input makes the agent leak keys or call paid tools; compromised skill drains the hot wallet.
- Incidents
- Moltbook production database exposed: 1.5M agent API tokens readable and writable
sec-01 - ClawHavoc: 341 (later 824) malicious skills on the ClawHub agent-skill registry
sec-02 - Snyk ToxicSkills: 13.4% of 3,984 agent skills had critical issues; 76 confirmed malicious payloads
sec-03 - CVE-2026-25253: OpenClaw gateway token sent to attacker-supplied URL (one-click compromise)
sec-04 - MCP tool poisoning: hidden instructions in tool descriptions exfiltrate files
sec-05 - GitHub MCP toxic agent flow: a malicious public issue makes the agent leak private repositories
sec-06 - Nx "s1ngularity" npm compromise drove local AI CLIs to hunt for secrets
sec-08 - Moltbook skill tells agents to re-fetch and follow a remote heartbeat file every 30 minutes (design exposure, not a breach)
sec-12
- Moltbook production database exposed: 1.5M agent API tokens readable and writable
- Source
- https://docs.cdp.coinbase.com/x402/support/faq
Stop conditions
Stop, and do not work around it, if any of these is true.
- The service would resell or pass through a closed model provider's output per call on a consumer plan, a CLI/OAuth login, or a shared/bought key (rules gate, step 2).
- You cannot hold the payTo keys yourself, or the payTo is flagged by screening.
- Coinbase asks for identity verification you are not able or willing to provide (then use another facilitator or stop).
- Testnet call does not return 402 with the intended payTo/amount, or settles to the wrong address.
- After 30 days, paying wallets other than your own are fewer than 5, or one wallet pays more than half of revenue.
- The agent behind the endpoint needs access to wallets, secrets or your browser profile to work.
Fees and costs
x402 protocol fee: none. CDP Facilitator: first 1,000 on-chain settlements/month free, then $0.001 each; verification free. The facilitator submits settlement on-chain and handles settlement gas (facilitator page); the buyer signs the authorization. Owner pays hosting, model API usage, and one self-paid listing call. Funds land directly in the payTo; no withdrawal step on-chain, off-ramp costs depend on where the owner sends USDC.
What we checked, and what nobody has tested
Checked read-only
- 2026-10-03: 13 one-shot unauthenticated GETs; 7 sellers returned HTTP 402 with x402Version 2 PAYMENT-REQUIRED header (Frantic, Agent402, hubvibe-io, BlockRun, StableEnrich, Laso Finance, SCVD); payTo matched x402scan 7/7; all offered exact-scheme USDC on Base; 5/7 also Solana or other chains.
- CDP Bazaar discovery listing is public and unauthenticated: 24,515 resources across 1,800 payTos on 2026-10-03.
- Docs quotes for credentials, KYC/screening, testnet facilitator and discovery (rules rows in https://shaduf.ai/p/agentic-freelance/assets/data/rules.json).
Untested by this pool
- Creating a CDP account or API key and whether identity verification is requested.
- Any payment, test or mainnet; settlement; Bazaar indexing timing; x402scan registration.
- Middleware code paths and the validate endpoint.
- Whether Bazaar listing produces independent buyers.
Sources
- https://docs.cdp.coinbase.com/x402/seller/quickstart
- https://docs.cdp.coinbase.com/x402/seller/facilitator
- https://docs.cdp.coinbase.com/x402/seller/production-configuration
- https://docs.cdp.coinbase.com/x402/seller/get-discovered
- https://docs.cdp.coinbase.com/x402/support/faq
- https://docs.cdp.coinbase.com/api-reference/v2/introduction
- https://docs.x402.org/getting-started/quickstart-for-sellers
- https://api.cdp.coinbase.com/platform/v2/x402/discovery/resources
- https://www.x402scan.com/
Rule rows: the Rules page and rules.json. ID and payout gates: Getting started and kyc.json. Evidence and context: Sell per call or hunt bounties? (3 October 2026).