Documentation

Coding agents

Coding-agent overview

Understand the public Access402 skill, CLI, browser authorization, native adapters, and Universal HTTP Gateway.
Last reviewed September 30, 2026

Access402 can be added to an existing application by Codex, Claude Code, or Cursor. All three use the same public, auditable integration workflow instead of generating a new x402 implementation from scratch.

What is available

  • The canonical Access402 skill, published as skill-v1.4.0.
  • @access402/cli for skill installation, browser authorization, runtime detection, initialization, synchronization, diagnostics, route tests, and optional MCP diagnostics.
  • @access402/node and @access402/cloudflare as runtime-specific HTTP Gateways backed by the same @access402/core payment and ARD, OpenAPI, and llms.txt discovery behavior.
  • Native WordPress and FastAPI adapters.
  • A Node HTTP Gateway and a Cloudflare Worker-native Gateway for other HTTP applications.

The npm release contains the canonical skill files pinned to an immutable public commit and SHA-256 checksums. Installing the skill copies those packaged files locally; it does not download instructions dynamically during customer setup.

How the pieces fit

The skill tells the coding agent what decisions to make and which security checks are mandatory. The CLI performs deterministic account and repository operations. Browser device authorization lets the user sign in, choose a project, and approve the requested installation scope without exposing a dashboard session to the agent.

At runtime, a native adapter or the Universal HTTP Gateway requests signed configuration from Access402 and enforces payment before the protected handler or origin receives the request. The optional MCP server is read-only and is not in the payment path.

Supported paths

ApplicationIntegration pathPolicy source
WordPressOfficial pluginWordPress protection rules synchronized to Access402
FastAPIaccess402-fastapiPython route decorators
Node or another HTTP applicationUniversal HTTP Gatewayaccess402.yaml
Cloudflare Workers or SitesWorker-native Gateway exportaccess402.yaml, loaded as a build-time text module

Security boundary

The coding agent and customer deployment receive only a scoped installation credential. Coinbase facilitator credentials, Supabase service credentials, wallet signing infrastructure, account limits, and global settlement limits remain inside Access402.

Protected routes fail closed when signed configuration or settlement cannot be confirmed. Live mode is enabled only through the deployment's ACCESS402_MODE=live; it is not inferred from a dashboard setting, hostname, or branch.