Documentation

FastAPI

FastAPI configuration

Configure the Access402 FastAPI adapter with secure environment variables and cache settings.
Last reviewed August 9, 2026

Required settings

ACCESS402_INSTALLATION_ID identifies the dashboard installation. ACCESS402_API_KEY authenticates that installation. ACCESS402_PUBLIC_BASE_URL is the trusted canonical externally reachable origin used in x402 challenges and discovery resource URLs.

The public base URL is still required even though pricing is code-owned. Inferring it from an incoming Host or forwarding header would let an untrusted request change canonical payment metadata. Its origin must appear in the installation's authorized URL list.

All three belong in the server runtime. Do not expose them through OpenAPI documents, exception responses, frontend bundles, or logs.

ACCESS402_API_BASE_URL is optional and should be overridden only when developing against a local Access402 backend.

Payment mode

ACCESS402_MODE is required and accepts exactly sandbox or live. Sandbox uses Base Sepolia and Live uses Base mainnet. Change the server environment and restart the FastAPI deployment to switch networks. The dashboard only displays the mode synchronized by the running adapter; it cannot override it.

CORS

The adapter makes its HTTP 402 challenge readable cross-origin. Set ACCESS402_CORS_ALLOW_ORIGIN to the exact browser origin when credentialed browser requests are used. Preflight OPTIONS requests are never paywalled.

Configuration authenticity

The adapter synchronizes code-declared policies, downloads the resulting installation configuration, and verifies its signature before using it. Configuration is cached briefly in memory and refreshed. If authenticated configuration or the matching server-side policy cannot be confirmed, a decorated route fails closed. Undecorated routes are not affected by an Access402 outage.