Projects and wallets
A project groups its receiving wallet, installations, activity, and usage. A successful live payment settles directly in USDC to the Coinbase wallet assigned to that project.
Installations and keys
An installation represents one connected deployment of your adapter. Its API key authenticates adapter-to-Access402 requests. Keys are revocable and rotatable and must never be exposed to browser code or public responses.
Each installation also has an authorized URL allowlist. Your adapter can synchronize and settle resources only for origins on that list, allowing one installation to cover local, sandbox, and production deployments without broadening access to unrelated domains.
The coding-agent CLI uses a stable repository identity when it creates an installation. Adding a public deployment URL updates that existing installation and preserves its credential instead of creating a duplicate.
Resources and policies
A resource is the exact page, file, or API route that may require payment. A policy supplies the USDC price, access type, environment, status, and optional discovery setting.
Access402 keeps an authoritative server-side copy of every synchronized policy. Payment requests are validated against that copy rather than trusting price or wallet values sent by an adapter.
Challenges and grants
An HTTP 402 challenge tells a compatible client what resource is being purchased, the amount, asset, network, payment recipient, and x402 version.
A successful payment may apply only to one request or create a wallet-bound reusable grant, depending on the policy. Time-limited grants expire at the configured boundary.
Discovery
Discovery is synchronized before deployment and is separate from payment protection: you can remove a resource from discovery without making it free or public.
For the Node and Cloudflare Gateways, Live routes marked for discovery are automatically described at /.well-known/ard.json, /openapi.json, and /llms.txt. The documents are generated from cached, signed route policy, so Access402 does not add discovery or metadata calls to the paid request path. OpenAPI can include the route's input and output schemas; the HTTP 402 response remains authoritative for current payment terms.
Access402 can also publish eligible resources to supported external x402 bazaars. Run access402 sync during deployment to register the current routes, schemas, pricing, and discovery intent before customer traffic arrives.
