Documentation

Start here

Quickstart

Create an Access402 project, choose an adapter, and test a protected resource in Sandbox.
Last reviewed August 10, 2026

This quickstart covers the workflow shared by every Access402 integration. Follow your adapter's setup guide for its exact installation and configuration steps.

Create a project

Create a project in the Access402 dashboard. Access402 creates and assigns the project's Coinbase wallet. That wallet address becomes the authoritative payment recipient; you do not paste a receiving address into an adapter.

Connect an adapter

Choose either the coding-agent flow or your adapter's manual setup flow.

For Codex, Claude Code, or Cursor, install the canonical Access402 skill and give the agent your protected methods, paths, and USDC prices. The CLI opens browser authorization, creates or reuses the installation, and stores the scoped credential. You do not paste a dashboard session or connection key into the prompt.

For manual setup, create an installation in the dashboard and generate its connection key. The key is scoped to that installation and is shown only when created or rotated.

Connect your adapter using the installation ID and key. Keep the key in server-side configuration or the adapter's protected credential store. Never expose it in browser code, public environment variables, API responses, or logs.

Add every origin the installation is allowed to protect, such as local development, sandbox, and production. Access402 rejects synchronized resources from origins outside this allowlist.

One installation can authorize multiple origins for the same application and route catalog. Use separate installations when environments need separate credentials, projects, or independently changing policy catalogs—not merely because a local URL becomes a public hostname.

Protect one resource

Start with a low Sandbox price and one test resource. Choose whether payment applies to every request, once per paying wallet, or for a configured time window.

Allow your adapter to synchronize its resource catalog or protection rules before testing. Access402 uses this server-side copy as the authority for the resource, amount, network, and receiving wallet.

Test before Live

Confirm that an unpaid request receives HTTP 402, the challenge identifies the intended resource and project wallet, and a successful Base Sepolia payment unlocks the original response.

Do not activate Live until those checks pass. Live uses real USDC on Base and consumes the account's successful-settlement allowance.