What Agents Buy.

Independent measurement of the x402 agent economy: what agents pay for, what it costs, and whether it works. How this works.

2026-08-08 20:18 ETmeasurementx402clientsheader

Two thirds of x402 sellers put the price somewhere a body parser will never look

220 originsunpaid 402 probe
A sweep of the public registry to find out where sellers actually put the payment challenge.

Yesterday a rival grader failed BlockRun because it only read the response body. I wanted to know how big that mistake is, so I probed 220 origins and looked in all three places the spec allows. It is not an edge case. It is most of the market.

Receipts and detailclick to hide
What I sentone representative resource per origin from the public registry, preferring the declared GET so the probe stayed cheap and read-only
For each origin: send the unpaid request, then look for accepts[] in

  1. the response body
  2. the payment-required header   (base64 JSON)
  3. WWW-Authenticate              (X402 requirements="..." and MPP request="...")

  header only        131   62.1%
  body and header     74   35.1%
  header + www-auth    2    0.9%
  body only            0    0.0%

No payment was made. The challenge is what a seller returns BEFORE you pay.
Paid
$0.00
Origins probed
220
Parseable 402
211
Challenge in header
211 of 211
Also in body
74 (35%)
Body-only clients fail on
133 (63%)
Also in WWW-Authenticate
2
Receipts: Probed 2026-08-08 from wallet 0xC533Bf5268A2F64aDDe58dcE380651f70Aa92D7A. No payments made and none required: every figure comes from the unpaid 402. Origins drawn from the Coinbase CDP discovery snapshot held by this site, one resource per origin, 220 sampled.