Security and trust

Understand the controls—and the risks—before enabling live payments.

Access402 is early-stage payment infrastructure. This page documents the current operating boundary so you can make a proportionate decision instead of treating a new product as established financial infrastructure.

Settlement

Hosted x402 v2 verification and settlement using Coinbase facilitator infrastructure.

Asset and network

Test USDC on Base Sepolia in Sandbox; USDC on Base for explicitly enabled Live deployments.

Assurance stage

No public independent security audit or long operating history is available yet. Test accordingly.

Wallet boundary

Where successful payments go.

Access402 creates a dedicated Coinbase-powered EVM wallet for each project and uses its public address as the authoritative payment recipient. A successful live payment settles directly to that project wallet; it is not credited to a pooled Access402 merchant balance for a later payout batch.

Access402 does not ask for a seed phrase or private key. Customers currently access and manage settled funds through Coinbase. Integrated Access402 bank payout and cash offboarding are not available today.

This still creates provider and access dependency. Before routing meaningful volume, complete a low-value live payment and confirm that you can access, transfer, convert, or withdraw the funds through the Coinbase flow available to your account and jurisdiction.

Wallet and settlement documentation

Implemented controls

How the settlement path is constrained.

  • Installation credentials are scoped to one installation; the database stores a cryptographic hash rather than recoverable plaintext.
  • The settlement service reloads authoritative server-side policy and validates the resource, network, USDC asset, amount, and receiving wallet.
  • Usage is reserved atomically before verification and released on failure. Idempotency keys prevent the same request from being settled twice.
  • Coinbase facilitator credentials remain in server-side Supabase Edge Function secrets and are not sent to adapters, browsers, Cloudflare frontend variables, API responses, or logs.
  • Payment and adapter paths fail closed when authentication, policy synchronization, verification, settlement, or quota enforcement cannot be confirmed.

Current limitations

What customers should not assume.

No revenue guarantee

AI-agent payment demand and x402 discovery are emerging. Access402 can expose a payable resource; it cannot guarantee buyers, traffic, discovery placement, or revenue.

No integrated bank payout

Funds settle as USDC to the project wallet. Any present conversion, transfer, or off-ramp happens through Coinbase or another supported external service.

No published independent audit yet

Internal testing and architecture controls are not substitutes for an independent audit. A public third-party assessment will be linked here only after one is completed.

No zero-risk custody claim

Access402 does not pool customer revenue, but wallet and account access still depend on the current Coinbase-powered implementation and the security of your accounts.

Report a vulnerability

Send security reports to support@access402.com. Do not include private keys, seed phrases, passwords, or live installation credentials. A machine-readable policy is available at /.well-known/security.txt.

Evaluate Access402

Review the public skill, documentation, terms, privacy policy, and founder profile. Start in Sandbox, use a low live amount, verify the transaction onchain, and test fund access before increasing exposure.