x402 · private payTo
Private x402 payments for AI agents.
A new one-time address for every payment. Agents pay the way they already do. Nobody can add up what your API earns, and your server never holds a key that can spend it.
- protocol
- x402 v2
- settles in
- USDC, EIP-3009
- server holds
- public key only
Live x402 call
runs in this tab…
→ GET /v1/weather ← 402 Payment Required payTo … new price 0.01 USDC → PAYMENT-SIGNATURE (signed USDC) ← 200 OK
Each press is one paid call. Same key, a new payTo.
Network
live- network
- Robinhood Chain
- chain id
- 4663
- block
- …
- shielded addresses
- …
One paid call, four steps
- 01agentCalls your APIAny x402 client. No SDK, no plugin, nothing new to learn.
- 02your serverAnswers 402 with a new payToMade from your public xSHADE Key. A different address for every call.
- 03facilitatorSettles the USDCThe agent signs, the facilitator settles, your API returns the data.
- 04you, offlineScan and sweepYour xSHADE Secret finds every payment. USDC moves out with no ETH needed.Scan in the browser
Add it to your API
Seller · your API
import { Announcer, shieldedPayTo } from 'xshade-x402' const announcer = new Announcer({ contract, wallet, publicClient })const shield = shieldedPayTo({ xshadeKey: process.env.XSHADE_KEY, // public key only onPaid: announcer.add,}) server.onAfterSettle(shield.onAfterSettle) app.use(paymentMiddleware({ 'GET /v1/weather': { accepts: { scheme: 'exact', network, price: '$0.01', payTo: shield.payTo }, // new address per call },}, server))
Buyer · any agent
import { wrapFetchWithPaymentFromConfig } from '@x402/fetch'import { ExactEvmScheme } from '@x402/evm' // A plain x402 client. It does not know xSHADE exists.const pay = wrapFetchWithPaymentFromConfig(fetch, { schemes: [{ network, client: new ExactEvmScheme(account) }],}) const res = await pay('https://your-api.com/v1/weather')
Nothing changes for the buyer. It sees a normal 402 with a payTo, pays it, and gets the data.
Non-custodial by design.
Funds settle directly to addresses controlled by cryptographic credentials held by the recipient.
The recipient retains control of its xSHADE Secret and the resulting spending authority.
Public, on chain
- Your xSHADE Keyshareable
- Each payment and its payTovisible, unlinked
- Ephemeral point E, tagbatched, delayed
Never on your server
- xSHADE Secretstays offline
- Which payTo addresses are yoursfound by scanning
- Spend keysbuilt when you sweep
Identity and reputation.
xSHADE can operate alongside persistent agent identity standards, including ERC-8004.
An agent may maintain a public identity for discovery and reputation while using independent addresses for settlement.
Payment receipts can provide authorization for subsequent actions, such as submitting a review, without requiring the receiving address to become part of the public identity record.
A separation between
- 01
Identity
Who the agent is.
- 02
Reputation
How counterparties evaluate it.
- 03
Settlement
Where individual payments are received.
In the receipt
- agentIdwhich agent was paid
- reviewerthe one address that may use it
- receiptIdrandom, so it counts once
- issuedDaythe day, not the second
Signed with EIP-712 by the receipt signer named in the agent's ERC-8004 profile.
Left out on purpose
- payTo addressnot included
- tx hashnot included
- amountnot included
- exact timenot included
Any of these would let someone match the review to a transfer. Copied, forged and missing receipts are rejected.
Cryptographic architecture.
xSHADE uses elliptic-curve key derivation to establish one-time receiving addresses from a recipient's public key.
A sender generates ephemeral key material for each payment. The recipient can independently derive the corresponding shared secret using its xSHADE Secret.
Both parties arrive at the information required to derive the same receiving address without publishing the recipient's private credentials.
Derivation · secp256k1
- sender
S = e · Kone-time key e per payment, recipient public key K - recipient
S = k · Ethe same secret, from the xSHADE Secret k and E = e · G - both
h = keccak256(S)first 2 bytes of S become the scan tag - both
P = K + h · Gthe one-time public key - both
payTo = addr(P)the receiving address - recipient
p = k + h mod nthe recipient spending key
Curve secp256k1. Source: xshade-x402/src/keys.ts and XShade-Main.sol.
On chain now
Robinhood ChainNo announcements yet. The first private payment on this contract shows up here.
This is everything the contract stores: an ephemeral point and a 2-byte tag. No receiver.
Infrastructure for autonomous economic activity.
As software increasingly participates directly in economic transactions, payment infrastructure will need to support machine-native requirements.
- 01
Programmatic authorization.
- 02
Open settlement.
- 03
Persistent identity.
- 04
Independent payment addresses.
- 05
Non-custodial control.
xSHADE is infrastructure for that environment.
Or pay a person by hand
- Generate an addressCreate an xSHADE Key in your browser. Share the public key. Keep the secret file.Open wallets
- Send any token to itThe sender pastes your key. ETH or any ERC-20 lands on a fresh shielded address.Send privately
- Scan and withdrawYour secret finds every address that is yours. Withdraw to any wallet.Receive
xSHADE
Privacy infrastructure for the x402 economy.
A non-custodial receiving layer designed for programmable payments and autonomous commerce.
x402 compatible · Non-custodial · Open architecture