Glossary · Commerce and payments
HTTP 402 Payment Required
The HTTP status code that RFC 9110 reserves for future use. The x402 protocol gives it concrete meaning: pay, then retry the same request.
HTTP 402 Payment Required is an HTTP status code that the HTTP standard reserves for future use, and that the x402 protocol uses to tell a client it must pay before the server will fulfil a request.
In the standard. RFC 9110, the current definition of HTTP semantics, lists 402 among the client error codes and says only that it is reserved for future use. No IETF standard defines what a 402 response must contain or how a client should pay, so a generic HTTP client cannot act on one.
In x402. The x402 v2 HTTP transport defines that missing behaviour with three headers, each carrying base64-encoded JSON:
- The server answers
402with aPAYMENT-REQUIREDheader holding aPaymentRequiredobject: the resource and the payment options it accepts. - The client picks an option, signs a payment payload, and retries the request with a
PAYMENT-SIGNATUREheader. - After verifying and settling the payment, the server answers
200with aPAYMENT-RESPONSEheader describing the settlement.
If verification or settlement fails, the server returns 402 again, and a PAYMENT-RESPONSE header can carry an error reason such as insufficient_funds. A malformed payment payload gets 400. The specification’s decoded PAYMENT-REQUIRED example:
{
"x402Version": 2,
"error": "PAYMENT-SIGNATURE header is required",
"resource": {
"url": "https://api.example.com/premium-data",
"description": "Access to premium market data",
"mimeType": "application/json"
},
"accepts": [
{
"scheme": "exact",
"network": "eip155:84532",
"amount": "10000",
"asset": "0x036CbD53842c5426634e7929541eC2318f3dCF7e",
"payTo": "0x209693Bc6afc0C5328bA36FaF03C514EF312287C",
"maxTimeoutSeconds": 60,
"extra": {"name": "USDC", "version": "2"}
}
]
}
Here eip155:84532 is a CAIP-2 network identifier, and the amount is in the asset’s smallest unit.
Outside HTTP. x402 also has transports where no status code exists. Over A2A, the server signals the same requirement by moving the task to input-required and placing the payment requirements in message metadata.
What 402 does not tell you. A 402 response alone says nothing about who authorized the agent to spend. That is the job of authorization evidence such as an AP2 Payment Mandate.
Sources
- RFC 9110: HTTP Semantics (June 2022), section 15.5.3: 402 Payment Required (accessed )
- x402 v2 transport: HTTP (accessed )
- x402 Protocol Specification v2 (accessed )
- x402 v2 transport: A2A (accessed )