Documentation

Coding agents

CLI and authorization workflow

Initialize Access402, approve browser authorization, reuse installations, and verify protected routes.
Last reviewed September 30, 2026

Initialize in Sandbox

Declare each protected method, canonical path, and USDC price from the application root:

npx -y @access402/cli@0.4.0 init --mode sandbox \
  --route "GET /api/report 0.02" \
  --route "POST /api/analyze 0.05" \
  --json

The CLI detects FastAPI when a native integration is available, detects Wrangler projects as Cloudflare Workers, and otherwise selects the Node HTTP Gateway. It writes repository-owned policy to access402.yaml, writes the scoped installation credential to .env.access402, and ensures that secret file is ignored by Git. Node and Cloudflare use separate runtime packages backed by the same payment and discovery core.

Approve in the browser

Initialization opens an Access402 device-authorization page. Sign in or create an account, choose the project, review the adapter and authorized URLs, and approve the request.

The agent never receives your dashboard JWT, Coinbase credential, wallet private key, seed phrase, or facilitator credential. The CLI receives only a short-lived agent authorization and a scoped installation credential.

Authorize a public deployment

When a local Gateway receives its public hostname, rerun initialization with that URL:

npx -y @access402/cli@0.4.0 init \
  --public-url https://api.example.com \
  --authorized-url http://localhost:8787 \
  --authorized-url https://api.example.com \
  --json

CLI 0.4.0 updates the existing installation's authorized URLs and preserves its current credential. It does not create a second installation simply because the public URL changed. Use a separate installation only when you need a genuinely separate security boundary, credential, project, or independently changing route catalog.

Diagnose and test

npx -y @access402/cli@0.4.0 doctor --json
npx -y @access402/cli@0.4.0 test https://api.example.com/api/report \
  --method GET \
  --json

doctor checks credentials, signed configuration, route policy, network, receiving wallet, and origin-bypass protection. test validates the complete x402 v2 challenge. A full Sandbox settlement still requires a funded buyer wallet and its signature; fund the buyer with Base Sepolia test USDC, not the project receiving wallet.

Sync and export discovery

Synchronize route schemas, pricing, and discovery metadata before deployment:

npx -y @access402/cli@0.4.0 sync --json

In Live mode, both Gateway runtimes automatically serve discovery-enabled routes at /.well-known/ard.json, /openapi.json, and /llms.txt from the cached signed configuration. No discovery generation call is added to a paid resource request.

To commit inspectable static copies, export from local policy or export the signed result during sync:

npx -y @access402/cli@0.4.0 export --output-dir public
npx -y @access402/cli@0.4.0 sync \
  --export-openapi --export-llms --output-dir public

Use optional input_schema, output_schema, input_example, and tags on a route to enrich OpenAPI. The runtime HTTP 402 challenge remains authoritative for current payment parameters.

Optional MCP tools

MCP exposes read-only detection, planning, status, doctor, and faucet guidance. It does not create installations, rotate credentials, settle payments, or replace the runtime Gateway.

codex mcp add access402 -- npx -y @access402/cli@0.4.0 mcp