⬡ OpenChainGraph · x402 Protocol · Workflows and verification nodes listed below
OpenChainGraph · x402 Protocol

x402 · Verifiable Workflow Guide

Free, browser-based workflows for teams building agent payments on x402, the protocol that turns HTTP 402 Payment Required into a machine-native rail. Each one handles a specific job: decoding and linting an x402 payment payload, recomputing the EIP-3009 or Permit2 signature evidence behind a payment, validating an A2A or AP2 payment mandate, reconciling a batch of agent micropayments, or picking the settlement rail for an agentic checkout. Everything runs locally in your browser. There is no backend, no signup, and no data leaves your machine. Every result carries a hash, so a counterparty can rerun the same workflow on the same inputs and confirm they get the same answer.

Written for engineers wiring agents to pay and be paid, and for the platform, payments, and risk reviewers on the other side of their integrations: facilitator and merchant teams accepting agent traffic, agent-framework builders, and settlement-ops desks that have to answer for the batches. This is an independent project by Post Oak Labs, not an x402 product.

HTTP 402 · x402 v2 EIP-3009 · Permit2 · EIP-712 AP2 · A2A · ACP · MCP Client-side · Zero PII
Not sure where to start? The spend-evidence pipeline is the protocol's core proof: it takes an x402 payment signed with EIP-3009 and recomputes every trust signal behind it, offline. The other workflows build on the same verification posture.
⬡ Run the spend-evidence pipeline →
Background
What is x402?

x402 is a protocol for native payments over HTTP, built around the long-unassigned 402 Payment Required status code. A server that wants payment answers with a 402 carrying payment details; the paying agent returns with signed payment credentials in the PAYMENT-SIGNATURE header; the server (or its facilitator) verifies and settles, then serves the response with a PAYMENT-RESPONSE receipt. Version 2 of the spec defines the settlement field shapes this page's workflows check.

Two authorization primitives carry the crypto. EIP-3009 TransferWithAuthorization lets a payer sign an EIP-712 typed-data authorization that a token contract executes, which is the rail underneath the exact scheme. Permit2 is the sibling path: the payer signs a Permit2 typed-data message (witnessed or unwitnessed) that binds the destination, and a spender contract moves the funds. Permit2 carries both the exact and the upto scheme, because its signed amount is a ceiling the settlement can stay under. Both produce signatures an independent party can verify by recomputation, which is exactly what the evidence workflows on this page do: recompute the digest, recover the signer, and check the domain, nonce, and validity window against expectations, entirely offline.

Settlement evidence is the third leg. An onchain event proves occurrence; the workflows here produce the hash-bound artifacts (a spend-evidence pack, a reconciled batch, a Merkle-root receipt) that let a reviewer say what occurred, by which rail, with which finality expectation.

Wire format
HTTP 402 · PAYMENT-REQUIRED / SIGNATURE / RESPONSE headers · x402 v2
Authorization: exact
EIP-3009 TransferWithAuthorization · EIP-712 typed data
Authorization: exact or upto
Witnessed and unwitnessed Permit2 signatures · gas-sponsor extension
Signature check
ECDSA signer recovery · domain, nonce, and validity-window checks
Deferred scheme
Cloudflare deferred handshake · RFC 9421 HTTP Message Signatures
Mandate layer
AP2 x402 extension inside an A2A agent card · ACP checkout · MCP
OpenChainGraph
The crypto-core verification nodes

Four nodes recompute, from caller-supplied fields only, the cryptography an x402 payment stands on. Each one runs offline: no chain contact, no facilitator, no network. What each recomputes:

art-590-x402-eip712-digest-recomputer
EIP-712 digest

Recomputes the EIP-712 typed-data digest for an EIP-3009 TransferWithAuthorization struct from the caller's domain and struct fields: the domain separator, the struct hash, and the resulting digest to compare against the payment payload.

art-591-x402-signer-recovery-verifier
Signer recovery

Recovers the ECDSA signer address from an EIP-712 digest and a signature supplied in (r,s,v) or (r,s,yParity) form, normalizing the recovery id across signature forms, so a reviewer can confirm which address authorized the payment.

art-592-x402-domain-nonce-window-checker
Domain and window

Checks an EIP-3009 authorization's domain separation and replay-defense fields against caller-supplied expectations: the expected chain id and verifying contract as separate mandatory policy parameters, plus the nonce and the validity window.

art-699-x402-permit2-evidence-recomputer
Permit2 digest

Recomputes the Permit2 typed-data digest a payer's wallet signs for an x402 payment, across the single-item message shapes the exact and upto schemes use, including the witnessed transfer that binds the destination.

OpenChainGraph
The protocol and mandate nodes

Six nodes cover the protocol surface around the signatures: the wire payloads, the mandates that authorize an agent to pay, the settlement economics, and the batch arithmetic.

art-26-x402-payload-decoder-flow-simulator
Payload and flow

Decodes base64 PAYMENT-REQUIRED, PAYMENT-SIGNATURE, and PAYMENT-RESPONSE headers, lints an exact-scheme PaymentPayload with EIP-3009-style authorization fields, and walks the HTTP 402 request, verify, and settle flow across the scheme and network matrix.

art-31-a2a-x402-extension-mandate-validator
Mandate validation

Validates the A2A x402 extension that carries crypto-payment authority inside an AP2 mandate: the extension declaration in the A2A agent card, the payment-authority scope, the settlement-rail binding, and the exact-scheme fields.

art-394-x402-deferred-handshake-validator
Deferred handshake

Validates the shape of a Cloudflare deferred x402 scheme handshake: the 402 offer fields (scheme, id, termsUrl), the RFC 9421 HTTP Message Signature covered-component coverage, and the settlement-reference id.

art-596-ap2-x402-cart-correlation
Cart correlation

Correlates a built AP2 CartMandate against an x402_spend_evidence pack: whether the cart total matches the x402 authorization's value, and whether the cart's merchant matches the evidence.

art-03-x402-settlement-modeler
Rail selection

Recommends a settlement rail and finality expectation across x402 (HTTP 402), Stripe USDC, card, ACH, and SWIFT, with per-transaction cost, eligibility scoring, and micropayment support.

art-61-x402-batch-settlement-reconciler
Batch reconciliation

Reconciles an x402 V2 batch settlement of off-chain payment vouchers against the onchain batch total: the recon verdict, per-voucher amounts, the settlement-risk window of unredeemed vouchers, and an educational Merkle root.

OpenChainGraph
The workflows across the x402 rail

Each workflow composes the nodes above into one decision. Seven of them had no hub page before this one; they are listed in full here. Four more touch x402 on their way somewhere else and are cross-linked to the hubs that own them, so nothing moved.

Start here · Evidence
x402 Spend Evidence Pack
Recomputes the trust signals behind an x402 payment signed with EIP-3009 TransferWithAuthorization: the EIP-712 digest, the ECDSA signer recovery, and the domain, nonce, and validity-window checks. Each step's fields compose into an x402_spend_evidence pack a downstream agent or human reviewer can check. Also lives on the Arc hub.
ART-590 + ART-591 + ART-592
→ Open this workflow
Settlement ops
x402 V2 Batch-Settlement Reconciliation
Reconciles a batch of x402 V2 payment vouchers against the onchain batch total, reports the settlement-risk window of unredeemed vouchers, re-verifies the Merkle root independently, and closes with one Merkle-root settlement receipt. The runtime question it answers: did this batch of agent micropayments settle correctly?
ART-61 + CRY-04 + CRY-05
→ Open this workflow
Mandates
Agentic Payment Mandate Lint
A verify-then-build lint for caller-supplied agentic payment mandates: validates the calling agent's A2A card, checks its x402 payment-extension mandate, then builds the AP2 verifiable credential form of the mandate.
ART-25 + ART-31 + ART-16
→ Open this workflow
Cart correlation
AP2 x402 Cart Correlation
Builds an illustrative AP2 CartMandate with a deterministic hash-chain over its cart line items, then checks whether that mandate's total and merchant plausibly correlate with a caller-supplied x402_spend_evidence pack from the spend-evidence pipeline. Output is a correlation verdict.
ART-595 + ART-596
→ Open this workflow
Economics
Agent-Service Metering and Marketplace Economics
Meters agent-service usage, runs the marketplace unit economics, models x402 settlement cost and finality, and screens the usage stream for billing anomalies. An educational estimator for pricing an agent-service micropayment marketplace.
ART-63 + ART-03 + ML-03
→ Open this workflow
Protocol selection
Agentic Rail Chain
Compares the agentic payment protocols, then routes: an AP2 mandate with Visa TAP signature inspection and Mastercard agentic token scope on the card branch, an A2A agent card validation with x402 payload decode and settlement modeling on the A2A branch, closing on an MCP developer readiness scorecard.
x402 legs ART-26 + ART-03
→ Open this workflow
Conformance
Agent Commerce Cross-Protocol Conformance
Validates the AP2 v0.2 mandate chain, checks ACP checkout conformance, models x402 settlement, and returns one unified cross-protocol conformance verdict for an agent commerce integration.
ART-01 + ART-12 + ART-03 + ART-30
→ Open this workflow
End to end
Agentic Commerce Checkout Chain
The full agentic checkout sequence: protocol selection, ACP conformance and fraud risk, agent identity attestation and A2A trust, spend-policy simulation and traffic acceptance, then x402 settlement modeling, batch reconciliation, receipt verification, and a cross-protocol conformance verdict.
x402 legs ART-03 + ART-61
→ Open this workflow
Cross-linked · Permit2
x402 Permit2 Spend Evidence Pack
The Permit2 sibling of the spend-evidence pipeline: recomputes the Permit2 typed-data digest the payer signed for an exact or upto x402 payment, then recovers the signer. The Token Standards hub owns this workflow; it is cross-linked here because it verifies the same payment rail.
ART-699 + ART-591
→ Open this workflow
Cross-linked · Permit2 · Sponsored
x402 Permit2 Sponsored Spend Evidence Pack
Extends the Permit2 evidence pipeline to the gas-sponsoring approval extension, where the payer signs a second message approving the transfer contract and a facilitator pays the gas to submit it. Also owned by the Token Standards hub.
ART-699 + ART-591 + ART-612
→ Open this workflow
Cross-linked · Tempo
Tempo Agentic Checkout
Decodes an x402 or MPP payment, then maps the settlement onto Tempo's TIP-20 token standard. The Tempo hub owns this workflow; it is cross-linked here because its first leg is the x402 decoder.
ART-26 + ART-40
→ Open this workflow
OpenChainGraph
How verification works on this page

Every workflow above composes nodes that emit OpenChainGraph artifacts with the following properties.

  • Offline recompute The crypto-core nodes take caller-supplied domain and struct fields only and recompute the EIP-712 and Permit2 digests, the signer recovery, and the domain and window checks in the browser. Nothing on this page contacts a chain, a facilitator, or any network endpoint.
  • execution_hash Every promoted node emits an execution_hash over its inputs, processing parameters, and outputs. Either party in a bilateral workflow can rerun verify_execution_hash to confirm the node was run as claimed, without sharing internal policy or configuration.
  • Evidence packs The evidence pipelines compose their step outputs into a named pack (x402_spend_evidence for the EIP-3009 rail and its Permit2 siblings) that a downstream agent or human reviewer can check step by step.
  • Conformance fixtures The nodes carry conformance fixtures with published digests, so the recomputation you run in the browser is the same computation the estate tests in CI.
Estate
Where x402 sits in the wider estate

For the vendor side of this protocol, the AgentCore x402 page maps the field names of the OpenAI Cookbook example for AWS AgentCore Payments onto these same verifiers, field by field; this page stays protocol-level and links that mapping rather than repeating it. The Arc hub carries the x402-native evidence workflow alongside Arc's own rails, the Token Standards hub owns both Permit2 evidence pipelines, and the Tempo hub owns the Tempo checkout.