Explicit paid routes
Only endpoints decorated with @access402.protect synchronize, even in applications with thousands of public routes.
Keep protected routes, prices, access policies, and schemas in Python. Access402 synchronizes those declarations, returns x402 v2 challenges, verifies and settles USDC payments, enforces plan limits, and records activity.
from fastapi import FastAPI
from access402_fastapi import Access402
app = FastAPI()
access402 = Access402.from_env()
@app.get("/premium-data")
@access402.protect(price="0.05", discovery_enabled=True)
async def premium_data():
return {"result": "paid data"}
access402.install(app)Designed for API teams
Route paths, prices, access behavior, discovery intent, and OpenAPI schemas stay versioned with the application. Access402 supplies the managed payment and observability layer.
Only endpoints decorated with @access402.protect synchronize, even in applications with thousands of public routes.
Price, access duration, description, and discovery intent ship with the endpoint code.
Every installation authenticates with its own revocable key; CDP credentials remain inside Access402.
Clients receive a machine-readable HTTP 402 challenge and retry the original resource after payment.
From project to protected route
One installation connects one deployment to an Access402 project. Use separate installations for local, staging, and production.
Choose FastAPI in the dashboard, enter the public API URL, generate the connection key, and copy it once.
ACCESS402_INSTALLATION_ID=...\nACCESS402_API_KEY=...Install the package and add @access402.protect with price and access policy only to endpoints that should require payment.
pip install access402-fastapi
@access402.protect(price="0.05")Set ACCESS402_MODE in the server environment and start the application. The dashboard shows the synchronized policy and mode as read-only.
ACCESS402_MODE=sandbox\n# or: ACCESS402_MODE=liveWhat happens on a protected request
The adapter normalizes the method and path and matches the code declaration to its authoritative server-side mirror.
The x402 v2 challenge specifies the exact resource, USDC amount, network, asset, and project receiving wallet.
The signed payment is checked against the server-side rule, limits, installation, and project before settlement.
After payment confirmation, the original FastAPI handler runs and returns its normal response.
FastAPI x402 FAQ
Yes. The @access402.protect decorator keeps route selection, USDC price, access policy, description, and discovery intent versioned with the endpoint. ACCESS402_MODE in the server environment selects Sandbox or Live, and the dashboard mirrors both policy and mode as read-only.
Only in the FastAPI server environment. Never expose it in frontend code, OpenAPI output, a VITE variable, logs, or a committed environment file.
No. Access402 handles payment requirements. Your application remains responsible for user identity, authorization, and application-specific permissions. A trusted bypass callback can use your real authentication state when internal users should not pay.
Yes. Set ACCESS402_MODE=sandbox for Base Sepolia or ACCESS402_MODE=live for Base mainnet. The server environment is authoritative and the dashboard shows the synchronized mode as read-only.
Static routes can opt into x402 v2 discovery with discovery_enabled=True in code. Dynamic path templates remain private until a concrete path example is supported, preventing broken Bazaar listings.
Access402 uses the project wallet configured in the dashboard as the receiving wallet and handles hosted verification and settlement. Coinbase facilitator credentials never enter your FastAPI deployment.