Before you let an agent pay an API
25 checks, in the order you hit them. Every one comes from getting it wrong with real money on this site, and every line links to the receipt. If you only read one page here, read this one.
Before you call
- 1There is no single catalog. Two public registries exist and neither is the whole market. why
- 2Ignore registry usage counters. One credited 4,201 calls where the chain showed 131,803 in a day. why
- 3Call it the way the schema says. A GET to a POST-only endpoint reads as a dead service, not a mistake. why
- 4Check the declared method twice. Some paywalls charge before they route, so a wrong verb costs money and returns HTML. why
Reading the price
- 5Read the live 402 for the price. Never the docs, never the registry listing. why
- 6Look in three places. 63% of sellers put the challenge only in a header, so a body-only parser sees nothing. why
- 7Check the asset's decimals. USDC is 6; BNB-chain tokens are 18. Assuming 6 turned one cent into ten billion dollars here. why
- 8One endpoint can quote several prices. Compare the options before picking one. why
- 9Price does not always scale with the request. Some sellers charge the same for a tenth of the work. why
- 10Quotes expire, sometimes in 30 seconds. Do not think for a minute and then pay. why
Before you pay
- 11Call the free endpoint first. Several sellers answer the same question for nothing on another path. why
- 12Check whether the cheap action needs state you can only buy. A three cent call can have a nine dollar entry fee. why
- 13A published quote is not a promise. Some sellers only accept their own client. why
- 14Ask for a route that cannot exist. Anything that quotes you a price for it is billing on nothing. why
- 15A changing payment address is usually fine. Some sellers mint a fresh one per request; probe twice before accusing. why
After you pay
- 16Reconcile against the chain. Your client reporting no payment is not proof that no payment was made. why
- 17Check the goods against the promise. Reputation scores cannot see a service that is reachable, well-formed and simply does not deliver. why
- 18Keep the block number, not the clock. A timestamp cannot be reproduced; a block height can. why
- 19Confirm you got what you paid for. Two differently named models returned the same weights on one router. why
- 20A ticker is not an asset. Asking for BTC returned 13 candidates; taking the first is how you get the wrong one. why
- 21Read payTo from the challenge every time. 89 counterfeit addresses now sit in one buyer's history, all rendering identically to the real one. why
Reading the market
- 22Money arriving is not a sale. Several top earners pay almost all of it straight back out. why
- 23Many storefronts, one operator. Wallet addresses collapse brands that look independent. why
- 24A catalog fetch that stops early looks exactly like a complete one. Floor-check every pull against the last. why
- 25Never read a registry call counter as demand. One service sells the number outright, $190 a year to pay your own endpoint twice a month. why
The long version of each is in the field notes. How the protocol itself works is in how to pay an x402 endpoint. What happened when I paid these services is in the ratings.