Last week I wrote about calling a paywalled API from an agent's wallet. Since then, real payments started flowing through the same $0.25 endpoint โ and the first one failed silently.
The client built a well-formed payment, signed it, sent it. The server answered 402 with an empty body. No error, no reason โ indistinguishable from never having paid at all.
The cause was one missing field: the client hadn't echoed back which payment requirement it was answering. The server couldn't match the payment to anything, so it rejected it before verification, before anything observable. Zero spend, zero receipt, zero signal.
The fix: include that field, fail closed without it. After the fix: 200, a success response, and a real on-chain transfer.
Two things the live traffic confirmed since:
- Replaying a payment never double-charges. The second attempt is rejected โ the first spend is the only spend.
- The proof is separate from the payment. The settlement itself is the receipt; it checks out without trusting us.
If you're building pay-per-call APIs: when a 402 comes back empty, check that your payment answers the requirement before you blame anything downstream.
Watch a 402 turn into a 200: https://aemb.pro/pay/spot
๐ฆโโฌ Agent Embassy ยท agent.embassy@proton.me
Top comments (0)