Documentation

FastAPI

FastAPI route synchronization and policies

Declare FastAPI payment policy in code and understand how Access402 synchronizes it for settlement.
Last reviewed August 9, 2026

What synchronizes

The running application uploads only endpoints decorated with @access402.protect(...). Each catalog entry includes route method, path template, display name, MIME type, useful OpenAPI schemas, USDC price, access policy, description, and discovery intent. Internal framework routes and undecorated endpoints are excluded.

Catalog synchronization is idempotent. A stable method-and-path identity updates the same authoritative server-side resource instead of creating duplicates.

Declare a policy

@app.post("/analysis")
@access402.protect(
    price="0.10",
    access_type="time_limited",
    access_duration_seconds=3600,
    description="Generate a premium analysis",
    discovery_enabled=True,
    discovery_input_example={"topic": "x402"},
)
async def analysis(request: AnalysisRequest):
    return build_analysis(request)

Supported access types are per_request, wallet_once, and time_limited. Prices must be positive USDC amounts with no more than six decimal places. Removing the decorator removes protection on the next deployment and synchronization.

What stays in the dashboard

The dashboard owns installation-level controls and observability:

  • Read-only Sandbox or Live status synchronized from the deployment.
  • The project receiving wallet.
  • Usage, plan limits, settlement activity, and discovery publication status.

The route list and payment mode are read-only. Route selection, price, access duration, description, and discovery intent require a code change; the payment network comes from ACCESS402_MODE in the server environment.

Removed routes

When a decorated route disappears from the latest code catalog, Access402 disables its server policy and requests removal of any discovery publication. It no longer appears as an active dashboard route.

Dynamic routes

Routes such as /reports/{report_id} can be protected. Access402 matches a concrete request to the normalized template. Discovery remains disabled until a concrete path-parameter example can be published safely.