Separate responsibilities
Access402 decides whether a matching resource requires payment and whether that payment or grant is valid. Your application still owns user authentication, tenant authorization, roles, and business permissions.
Trusted bypass callback
Pass a callback when authenticated internal users should bypass payment:
async def trusted_internal_request(scope):
user = scope.get("state", {}).get("user")
return bool(user and user.is_admin)
Access402.from_env(bypass=trusted_internal_request).install(app)
The callback receives the ASGI scope and must base its decision on authentication state your application has already verified.
Middleware order
If the callback reads state populated by authentication middleware, ensure authentication runs before the Access402 bypass decision. Test middleware order with an authenticated internal request and an unauthenticated external request.
Unsafe bypass patterns
Never bypass based only on a client-supplied header, query parameter, cookie value that has not been verified, source IP without trusted-proxy handling, or a claimed administrator email in the request.
