A settlement attempt ends ambiguously — timeout, opaque error, settlement_pending. The money may have moved. The most expensive mistake now is generating a new payment authorization before the first one's outcome is known. If the original confirms, you've paid twice.
Three things people confuse as one:
- HTTP status — what the wire said (402, 500, timeout). Transport signaling, not economic fact.
-
Settlement state — what the protocol knows (
success, terminal failure, orsettlement_pending: broadcast but unconfirmed, explicitly non-terminal). - Payment authorization — what you signed. The only layer that moves money.
The safe sequence: preserve the original payment identity, reconcile via the broadcast transaction hash, and don't sign a new authorization until the original reaches a terminal state. Where your scheme supports it, retrying settlement with the identical payment payload is not the same action as signing a second authorization — the former reconciles, the latter double-pays.
Full writeup with sources in the callx402 troubleshooting docs. When x402 breaks, callx402.
Top comments (0)