Access402 can be added to an existing application by Codex, Claude Code, or Cursor. All three use the same public, auditable integration workflow instead of generating a new x402 implementation from scratch.
What is available
- The canonical Access402 skill, published as
skill-v1.4.0. @access402/clifor skill installation, browser authorization, runtime detection, initialization, synchronization, diagnostics, route tests, and optional MCP diagnostics.@access402/nodeand@access402/cloudflareas runtime-specific HTTP Gateways backed by the same@access402/corepayment and ARD, OpenAPI, andllms.txtdiscovery behavior.- Native WordPress and FastAPI adapters.
- A Node HTTP Gateway and a Cloudflare Worker-native Gateway for other HTTP applications.
The npm release contains the canonical skill files pinned to an immutable public commit and SHA-256 checksums. Installing the skill copies those packaged files locally; it does not download instructions dynamically during customer setup.
How the pieces fit
The skill tells the coding agent what decisions to make and which security checks are mandatory. The CLI performs deterministic account and repository operations. Browser device authorization lets the user sign in, choose a project, and approve the requested installation scope without exposing a dashboard session to the agent.
At runtime, a native adapter or the Universal HTTP Gateway requests signed configuration from Access402 and enforces payment before the protected handler or origin receives the request. The optional MCP server is read-only and is not in the payment path.
Supported paths
| Application | Integration path | Policy source |
|---|---|---|
| WordPress | Official plugin | WordPress protection rules synchronized to Access402 |
| FastAPI | access402-fastapi | Python route decorators |
| Node or another HTTP application | Universal HTTP Gateway | access402.yaml |
| Cloudflare Workers or Sites | Worker-native Gateway export | access402.yaml, loaded as a build-time text module |
Security boundary
The coding agent and customer deployment receive only a scoped installation credential. Coinbase facilitator credentials, Supabase service credentials, wallet signing infrastructure, account limits, and global settlement limits remain inside Access402.
Protected routes fail closed when signed configuration or settlement cannot be confirmed. Live mode is enabled only through the deployment's ACCESS402_MODE=live; it is not inferred from a dashboard setting, hostname, or branch.
