Initialize in Sandbox
Declare each protected method, canonical path, and USDC price from the application root:
npx -y @access402/cli@0.4.0 init --mode sandbox \
--route "GET /api/report 0.02" \
--route "POST /api/analyze 0.05" \
--json
The CLI detects FastAPI when a native integration is available, detects Wrangler projects as Cloudflare Workers, and otherwise selects the Node HTTP Gateway. It writes repository-owned policy to access402.yaml, writes the scoped installation credential to .env.access402, and ensures that secret file is ignored by Git. Node and Cloudflare use separate runtime packages backed by the same payment and discovery core.
Approve in the browser
Initialization opens an Access402 device-authorization page. Sign in or create an account, choose the project, review the adapter and authorized URLs, and approve the request.
The agent never receives your dashboard JWT, Coinbase credential, wallet private key, seed phrase, or facilitator credential. The CLI receives only a short-lived agent authorization and a scoped installation credential.
Authorize a public deployment
When a local Gateway receives its public hostname, rerun initialization with that URL:
npx -y @access402/cli@0.4.0 init \
--public-url https://api.example.com \
--authorized-url http://localhost:8787 \
--authorized-url https://api.example.com \
--json
CLI 0.4.0 updates the existing installation's authorized URLs and preserves its current credential. It does not create a second installation simply because the public URL changed. Use a separate installation only when you need a genuinely separate security boundary, credential, project, or independently changing route catalog.
Diagnose and test
npx -y @access402/cli@0.4.0 doctor --json
npx -y @access402/cli@0.4.0 test https://api.example.com/api/report \
--method GET \
--json
doctor checks credentials, signed configuration, route policy, network, receiving wallet, and origin-bypass protection. test validates the complete x402 v2 challenge. A full Sandbox settlement still requires a funded buyer wallet and its signature; fund the buyer with Base Sepolia test USDC, not the project receiving wallet.
Sync and export discovery
Synchronize route schemas, pricing, and discovery metadata before deployment:
npx -y @access402/cli@0.4.0 sync --json
In Live mode, both Gateway runtimes automatically serve discovery-enabled
routes at /.well-known/ard.json, /openapi.json, and /llms.txt from the
cached signed configuration. No discovery generation call is added to a paid
resource request.
To commit inspectable static copies, export from local policy or export the signed result during sync:
npx -y @access402/cli@0.4.0 export --output-dir public
npx -y @access402/cli@0.4.0 sync \
--export-openapi --export-llms --output-dir public
Use optional input_schema, output_schema, input_example, and tags on a
route to enrich OpenAPI. The runtime HTTP 402 challenge remains authoritative
for current payment parameters.
Optional MCP tools
MCP exposes read-only detection, planning, status, doctor, and faucet guidance. It does not create installations, rotate credentials, settle payments, or replace the runtime Gateway.
codex mcp add access402 -- npx -y @access402/cli@0.4.0 mcp
