402 Payment Required: a New Way for AI Agents to Pay, with Nemil Dalal, Dev Platform Lead @ Coinbase
Summary
Stablecoins are already a roughly $250 billion market, not a venture-subsidized experiment. Nemil Dalal says issuers can earn roughly 3%-4.5% on the dollars and short-dated government paper backing their tokens, implying more than $10 billion in annual economics: “These are already great businesses.” That yield creates economics for low-fee transfers, user rewards, compliance, market makers, and cash-out infrastructure; Nemil said these can remain attractive businesses even with less margin than traditional banks.
x402 turns the internet’s dormant “402 Payment Required” status into a native payments rail for humans and AI agents. A seller returns a price, network, asset, and payment destination; the buyer signs a stablecoin transaction, resubmits the request with that authorization, and receives the resource once the seller verifies and settles it. The core call is that agents cannot depend on subscriptions, credit-card forms, or advertising when they may buy one query each from many services: “The thing that’s missing is really just money.”
The protocol’s most compelling near-term market is machine-to-machine purchasing of inference, data, messaging, and specialist-agent work. An agent might pay 5 USDC for inference, buy financial data before trading, invoke a paid MCP tool, or hire a specialist model to plan part of a larger task. Coinbase has paired the open standard with Node.js middleware, wallet infrastructure, and optional conversion into bank-account dollars, aiming to make acceptance “basically one line of JavaScript.”
The timing rests on a recent collapse in blockchain costs, not merely renewed crypto enthusiasm. Stablecoins provide monetary stability, while layer-2 systems and cheaper chains brought fees down from historical spikes of $10-$200 to cents or less; Nemil said Base had recently approached 1,000 transactions per second and was targeting settlement below 500 milliseconds. His framing: blockchain transfers are cheap because of “the technology architecture,” not because Coinbase is paying to subsidize them.
Hard wallet controls may make crypto unusually well suited to agents that remain vulnerable to prompt injection and bad judgment. A small agent wallet can segregate risk, while a smart-contract wallet can permit transactions below $10 but require both the agent’s and human’s keys above that threshold—a “two-of-two multisig” that fails regardless of what the model was prompted to do. Nemil nevertheless expects agents eventually to control “millions, if not billions of dollars,” particularly for automated trading and wealth management.
Payments are only the base layer; reputation, collateral, and slashing could determine which agents are trusted with capital or credit. Nemil imagines an NFT-like identity accumulating attestations “like a passport where you’re getting stamps,” creating an “open-source credit bureau” for agents. Capital could then sit in escrow and be confiscated after misconduct, adapting proof-of-stake slashing to Tyler Cowen’s idea that agents may need financial skin in the game.
The largest unresolved issue is systemic control once cheap agents can cooperate, collude, and transact on infrastructure without a universal kill switch. Nathan Labenz pressed for flash-crash-style circuit breakers, citing experiments where Claude agents learned cooperation and punishment while GPT and Gemini did not; Nemil pointed instead to human approvals, reputation, and protocol-level transaction limits. The opportunity extends to AI arbitration and oracles, but only if evidence provenance and model manipulation are constrained: “It doesn’t start with the hardest problem on day one.”
Deep dive
1. Stablecoins add issuer trust in exchange for useful monetary stability
Nemil’s stablecoin primer begins with adoption: the market went from effectively zero to about $250 billion in a decade, with the supply “almost exclusively US dollar based.” Stablecoins combine the blockchain’s global availability, often rapid settlement, and often lower fees with a unit people already use to price everyday goods.
The basic reserve mechanism is deliberately legible. An issuer receives $10, holds those dollars in a bank account or short-dated government paper, and creates 10 USDC; when the holder redeems, the tokens are destroyed and the fiat is returned. The intended peg therefore depends on one-to-one reserves and the ability to redeem.
Nathan’s foundational pushback was that Bitcoin promised reduced dependence on trusted institutions. Nemil’s answer was categorical: “Unlike Bitcoin, you absolutely have to trust someone”—principally the stablecoin issuer, and specifically its claim that reserves exist where reported.
That trust has two technical and institutional components: transparency over the fiat reserves, and security around the smart-contract keys used to mint and burn tokens. Circle and Coinbase publish reserve information, while prospective legislation could add formal safeguards; neither transparency nor regulation removes the need to trust the custodian.
2. Reserve yield pays for an ecosystem that looks free at the surface
Nathan asked who absorbs the currency, compliance, and liquidity costs when he sends USDC abroad without an obvious fee. Nemil stressed that market makers, exchanges, cash-in providers, and cash-out providers all incur real expenses—bank movements, local branches, compliance systems, and inventory management—and must earn money somewhere.
“The secret of stable coins is that the money is often made on the yield itself.” At $250 billion of reserves earning roughly 3%-4.5%, issuers collectively generate more than $10 billion annually; that economics can support cheap or free services while remaining an attractive business.
A representative flow starts with a US user connecting a bank account, waiting two or three days for ACH, and receiving 10 USDC. An Indian recipient needs only a crypto wallet, not Coinbase; they can hold or invest the USDC, or sell it through a market maker for rupees, perhaps paying half a percent, 1%, or a small fixed fee.
3. Stablecoin economics improve as activity stays on-chain
Nemil expects more transactions to become closed-loop: recipients will retain on-chain dollars or rupees, spend them directly, or use decentralized financial services instead of repeatedly paying to enter and exit fiat systems. An on-chain currency is more portable because it can circulate globally and interact with trading, storage, and yield protocols.
Coinbase may share part of its reserve income with users who hold USDC on-platform because growth of the asset itself has strategic value. A holder who moves USDC to an off-platform wallet may receive no yield personally even though Coinbase and Circle continue earning on the underlying reserves.
Nathan compared today’s economics with Uber’s venture-funded subsidies. Nemil rejected the analogy: “This is already a big business.” The investment-relevant distinction is that low consumer pricing comes from a high-yielding reserve base and cheaper infrastructure, not necessarily from accepting losses to acquire users.
4. Blockchain scale comes from batching, more capacity, and explicit trade-offs
Nemil likened blockchain progress to Moore’s law for bandwidth: Bitcoin launched in 2009, leaving roughly 16 years for networks to improve throughput and storage efficiency. Base had recently reached almost 1,000 transactions per second; he expected capacity to keep growing as financial and even social activity migrates on-chain.
Ethereum transactions once competed directly for space on layer 1. Layer-2 and emerging layer-3 networks now execute many transfers, summarize them, and periodically write condensed results to the underlying chain—an arrangement Nemil compared, imperfectly, to banks settling net balances rather than every retail transaction independently.
Networks can also increase throughput by relaxing Bitcoin’s ambition that almost anyone should run a node on modest hardware. If thousands or tens of thousands of operators use cloud-grade infrastructure, each node can process substantially more, though the network accepts a different point on the decentralization spectrum.
Nathan summarized the mechanism as a mixture of raw efficiency improvements and design compromises. Nemil agreed but resisted applying one formula to the whole industry: different networks choose different combinations of block space, layering, hardware requirements, and decentralization.
5. Finality is both the blockchain’s advantage and its consumer-protection gap
Traditional payment fees partly buy fraud handling and recourse. Nemil conceded Nathan’s main point: blockchain payments are “not a reversible system by default.” Once a transaction settles, the sender cannot simply press a button and pull the funds back.
Stablecoins are not beyond legal enforcement. Exchanges conduct KYC and other checks, issuers must comply with sanctions, and USDC can be held when authorities present a legal case; that is meaningful recourse, but it is not equivalent to routine payment reversal.
Irreversibility is also why recipients can trust the payment within seconds rather than wait several days to access funds. “I can send a trillion dollars or 10 cents for less than a cent,” Nemil argued, versus perhaps $20-$30 for a wire whose infrastructure and protections are bundled together.
Additional layers could reintroduce delayed settlement or sender cancellation where users want those protections. Nemil expects such designs to become more common, with somewhat higher fees, while preserving a cheap and final foundational rail underneath.
6. x402 revives a web primitive that credit cards did not fulfill
The HTTP 402 status was reserved in the early internet for “Payment Required,” but implementing it would have required Visa, Mastercard, and other payment networks to cooperate. The web instead evolved around advertising, accounts, credit cards, and subscriptions, leaving the code effectively dormant.
Coinbase’s route back to 402 started with AgentKit, which gives AI agents wallets and on-chain capabilities. Thousands of developers adopted it, including teams building AI personalities that could receive tips and move money; users then asked why those same agents could not autonomously purchase goods, data, API calls, or text messages.
Credit cards are a poor fit for software that may buy one query from one vendor and another query elsewhere. They assume human account setup and recurring merchant relationships, while agents need programmable permissions and low-cost, one-off transactions across many unknown providers.
Human micropayments remain part of the vision: Nathan would rather pay 1-10 cents for an occasional CNN article than buy another $30 subscription. Nemil said this became plausible only recently, after stablecoins, cheaper chains, and better usability removed fees that had made a one-cent purchase irrational.
7. A successful x402 purchase is one request-response loop
Nemil’s canonical example is an agent buying its own inference. The agent requests a model call and receives a 402 specifying the charge, blockchain, and token—perhaps 5 USDC on Base—plus the destination and other information needed to authorize payment.
The agent’s wallet signs the proposed transaction but does not broadcast it. It repeats the original request with that signed payload attached, allowing the inference provider to confirm that the authorization is well formed and that the buyer is “good for the money.”
The provider may wait to submit the transaction until it knows the work can be performed and what it costs. After producing the inference, it broadcasts the payment, receives the funds, and returns the result; the seller, rather than the buyer, controls the moment of settlement.
Variable costs create edge cases rather than breaking the protocol. Overpayment might create a reusable credit resembling a prepaid card; underpayment can trigger another 402 requesting, say, $15 instead of $10, though the provider must manage the risk of having already consumed inference.
8. Middleware and MCP integration lower the adoption barrier
x402 is an open standard that anyone can implement, modify, or build upon, but Nemil said publishing a specification alone was insufficient. Coinbase therefore released Node.js middleware that can sit in front of an existing API and enforce payment with “basically one line of JavaScript.”
Coinbase’s developer platform can also create the receiving wallet, manage blockchain plumbing, and automatically convert incoming tokens into dollars in the seller’s bank account. A business can therefore accept on-chain agent payments without choosing to hold crypto operationally.
Nemil framed MCP as one part of “rewriting the web to make it easy for AI”: it helps agents discover tools and understand how to call them, but omits payment. His envisioned end state is that paid MCP servers expose x402 automatically, while other capabilities need not use it.
Discovery is still primitive. The initial x402 ecosystem page lists participating crypto-data and inference services; a future MCP-style directory could describe every endpoint, its capabilities, and its price, letting an agent compare competing providers before purchasing.
9. Machine commerce changes both API pricing and web monetization
Early use cases include a storefront accepting 20 USDC and shipping to an address supplied by an agent, a financial-data API selling inputs for trading, and a Twilio-like service charging per text. The common pattern is payment at the exact moment a capability is invoked, without a subscription relationship.
Nemil sees a particularly natural market between generalist and specialist agents. A general coding agent might pay a planning model, a crawler, or another specialist behind an MCP endpoint; what looks like one agent to the user may actually be several independently owned systems exchanging work and money.
Nathan’s Augment example exposed an unresolved boundary: if a coding agent relies on a smart third-party MCP for planning, it becomes unclear where “the agent” ends and who owns responsibility for a malicious or defective plan. Nemil did not offer a crisp boundary; he argued that value transfer at least makes the commercial dependencies explicit.
Advertising also weakens when the consumer is software: “A lot of times AI agents are not watching ads.” Nemil expects publishers, potentially even the New York Times, to charge crawlers directly for access, making x402 one candidate for a web whose monetization shifts from human attention to machine usage.
10. Reputation could become an agent’s identity, credit score, and collateral
KYC remains separate from x402: Anthropic, OpenAI, or any other provider can still require verified identities before exposing sensitive capabilities. Nemil described x402 as the lowest-level payment rail, upon which access controls and reputation systems can be layered.
A persistent blockchain identity might begin as an empty NFT and accumulate attestations “like a passport where you’re getting stamps.” If trusted evaluators repeatedly confirm that an agent supplied correct medical information, those entries could establish expertise without relying on one company’s private database.
Nemil’s metaphor was an “open-source credit bureau”: everyone can inspect the history and add information, while each reader decides whether to trust the attesters. An agent that was correct 999 times out of 1,000 might still deserve access or credit despite one recorded mistake.
Reputation could let an underfunded agent buy an API call on credit, gain privileged access, or prove it has not abused a publisher’s content. The hard problem is not recording claims immutably but deciding which identities, evaluators, and attestations deserve weight when agents themselves are cheap to create and discard.
11. Agent wallets need hard limits before they need larger balances
Nathan’s initial safety model was segregation: give an agent $10 or $100, never the owner’s primary wallet, and accept that prompt injection might lose the entire small balance. Nemil endorsed segregation but expects the relevant sums to rise dramatically as agents trade crypto, stocks, or portfolios.
“People are going to put millions, if not billions of dollars into AI agents over time.” Coinbase hackathons had already drawn hundreds of experiments resembling automated traders or wealth managers; Nemil’s analogy was that quantitative funds perform versions of this today, even if consumer agents still sound futuristic.
The stronger control is a smart-contract wallet with explicit permissions. An agent might spend up to $10 alone, but any larger transaction fails unless a human separately signs with another key; the two-of-two multisig resembles a safe-deposit box that requires both the customer and bank.
Prompting the model to request approval remains useful for the interface, but it is not the security boundary. Hallucination or manipulation may prevent the notification, whereas the wallet contract cannot release the money without the second signature.
12. Slashing, circuit breakers, and AI arbitration remain unfinished infrastructure
Tyler Cowen’s proposal that agents be capitalized maps, in Nemil’s view, to proof-of-stake slashing. An agent could escrow funds to gain transaction rights or credibility, earn a return for posting the stake, and lose it after misconduct; adjudication might come from decentralized governors or one centralized party.
Nathan’s systemic objection was sharper: agents may cooperate beneficially or collude destructively. He cited a donor-game experiment where a prior Claude learned cooperation and punishment across generations while GPT and Gemini did not, then asked who pulls the breaker when autonomous agents run on infrastructure designed to resist shutdown.
Nemil did not propose a universal off-switch. He located controls at multiple layers: human approvals, durable reputation, slashing, and possible exchange-level limits such as blocking excessive transactions in one block on venues like Uniswap or Aerodrome. He also conceded that approval fatigue may push humans out as agents improve.
Nathan argued the danger may arrive before mass adoption catches up: Claude 4, Gemini 2.5, and o3 already seem capable enough to create a dynamic economy. Nemil’s response was that meaningful enforcement mechanisms will likely emerge only after transaction volume makes the failure modes concrete.
AI could also “put the smart in smart contracts.” Nemil suggested a two-of-three multisig in which two humans disagree and an AI reviews the evidence to cast the deciding signature; he knew of no existing system but said the components were already available.
His best concrete example was weather-index crop insurance from work with the Gates Foundation. Investors could place $1,000 in escrow; after the growing season, an AI reviews six months of precipitation and sends the money to investors if rainfall exceeded the threshold or to the farmer if it fell short.
That design reframes AI as a blockchain oracle: it interprets off-chain facts that deterministic contracts cannot access. Nathan’s pushback was evidence provenance—whether a roof photo is current, a field sensor is genuine, or a claimant fabricated inputs—plus the model’s own susceptibility to hallucination and “goading.”
Nemil has seen public-facing agents manipulated into giving away money, so his proposed starting point is narrow and controlled: satellite data, limited APIs, no open-ended public prompting, and simple decisions. “It doesn’t start with the hardest problem on day one”; it starts where trusted data and bounded judgment can safely meet.