DEV Community

Payload
Payload

Posted on Originally published at github.com

The most expensive x402 mistake: signing twice for one intent

A settlement attempt ends ambiguously — timeout, opaque error, settlement_pending. The money may have moved. The most expensive mistake now is generating a new payment authorization before the first one's outcome is known. If the original confirms, you've paid twice.

Three things people confuse as one:

  1. HTTP status — what the wire said (402, 500, timeout). Transport signaling, not economic fact.
  2. Settlement state — what the protocol knows (success, terminal failure, or settlement_pending: broadcast but unconfirmed, explicitly non-terminal).
  3. Payment authorization — what you signed. The only layer that moves money.

The safe sequence: preserve the original payment identity, reconcile via the broadcast transaction hash, and don't sign a new authorization until the original reaches a terminal state. Where your scheme supports it, retrying settlement with the identical payment payload is not the same action as signing a second authorization — the former reconciles, the latter double-pays.

Full writeup with sources in the callx402 troubleshooting docs. When x402 breaks, callx402.

Top comments (0)