Sign the quote behind every 402, or the retry pays a different price
The x402 exchange comes in two halves with an unbounded gap between them. A server answers an unpaid request with 402 and the terms it accepts; some time later the client repeats the request with an X-PAYMENT header built against those terms. If the gate only knows its current price, it checks the second half against state that may have moved since the first half went out. The client can pay a…
The x402 exchange system has two parts: a server providing terms and a client paying with an X-PAYMENT header. The server's response is based on current terms, but if a client repeats the request later, the server may have changed its terms. This creates issues when the client is asked to pay a different price than it was originally quoted.
The solution is to have the client carry the price information instead of relying on server state. The paygate402 system implements this by signing the priced offer in the 402 response with a key, and sending it to the client. The client then includes this quote in its payment. The server checks three things before forwarding the payment: signature validity, quote expiration, and offer matching.
The quote is checked before forwarding to the facilitator, not after, to avoid unnecessary calls and improve performance. The system uses a canonical length-prefixed form for signing, rather than the JSON representation.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.