xSHADE

x402 · private payTo

Private x402 payments for AI agents.

A new one-time address for every payment. Agents pay the way they already do. Nobody can add up what your API earns, and your server never holds a key that can spend it.

protocol
x402 v2
settles in
USDC, EIP-3009
server holds
public key only

Live x402 call

runs in this tab
The API's xSHADE Keypublic

…

→ GET /v1/weather
← 402 Payment Required
    payTo  … new
    price  0.01 USDC
→ PAYMENT-SIGNATURE (signed USDC)
← 200 OK

Each press is one paid call. Same key, a new payTo.

    0 paid calls0 payTo0 spend keys on server

    Network

    live
    network
    Robinhood Chain
    chain id
    4663
    block
    …
    shielded addresses
    …

    One paid call, four steps

    A normal x402 payment, except the address changes every time and the spend key never touches your server.
    1. 01agentCalls your APIAny x402 client. No SDK, no plugin, nothing new to learn.
    2. 02your serverAnswers 402 with a new payToMade from your public xSHADE Key. A different address for every call.
    3. 03facilitatorSettles the USDCThe agent signs, the facilitator settles, your API returns the data.
    4. 04you, offlineScan and sweepYour xSHADE Secret finds every payment. USDC moves out with no ETH needed.Scan in the browser

    Add it to your API

    One hook on your x402 server. xshade-x402 swaps your fixed payTo for a new shielded address and publishes the scan data in batches.

    Seller · your API

    import { Announcer, shieldedPayTo } from 'xshade-x402' const announcer = new Announcer({ contract, wallet, publicClient })const shield = shieldedPayTo({  xshadeKey: process.env.XSHADE_KEY, // public key only  onPaid: announcer.add,}) server.onAfterSettle(shield.onAfterSettle) app.use(paymentMiddleware({  'GET /v1/weather': {    accepts: { scheme: 'exact', network, price: '$0.01',               payTo: shield.payTo },   // new address per call  },}, server))

    Buyer · any agent

    import { wrapFetchWithPaymentFromConfig } from '@x402/fetch'import { ExactEvmScheme } from '@x402/evm' // A plain x402 client. It does not know xSHADE exists.const pay = wrapFetchWithPaymentFromConfig(fetch, {  schemes: [{ network, client: new ExactEvmScheme(account) }],}) const res = await pay('https://your-api.com/v1/weather')

    Nothing changes for the buyer. It sees a normal 402 with a payTo, pays it, and gets the data.

    Non-custodial by design.

    Funds settle directly to addresses controlled by cryptographic credentials held by the recipient.

    The recipient retains control of its xSHADE Secret and the resulting spending authority.

    Public, on chain

    • Your xSHADE Keyshareable
    • Each payment and its payTovisible, unlinked
    • Ephemeral point E, tagbatched, delayed

    Never on your server

    • xSHADE Secretstays offline
    • Which payTo addresses are yoursfound by scanning
    • Spend keysbuilt when you sweep

    Identity and reputation.

    xSHADE can operate alongside persistent agent identity standards, including ERC-8004.

    An agent may maintain a public identity for discovery and reputation while using independent addresses for settlement.

    Payment receipts can provide authorization for subsequent actions, such as submitting a review, without requiring the receiving address to become part of the public identity record.

    A separation between

    1. 01

      Identity

      Who the agent is.

    2. 02

      Reputation

      How counterparties evaluate it.

    3. 03

      Settlement

      Where individual payments are received.

    In the receipt

    • agentIdwhich agent was paid
    • reviewerthe one address that may use it
    • receiptIdrandom, so it counts once
    • issuedDaythe day, not the second

    Signed with EIP-712 by the receipt signer named in the agent's ERC-8004 profile.

    Left out on purpose

    • payTo addressnot included
    • tx hashnot included
    • amountnot included
    • exact timenot included

    Any of these would let someone match the review to a transfer. Copied, forged and missing receipts are rejected.

    Cryptographic architecture.

    xSHADE uses elliptic-curve key derivation to establish one-time receiving addresses from a recipient's public key.

    A sender generates ephemeral key material for each payment. The recipient can independently derive the corresponding shared secret using its xSHADE Secret.

    Both parties arrive at the information required to derive the same receiving address without publishing the recipient's private credentials.

    Derivation · secp256k1

    1. senderS = e · Kone-time key e per payment, recipient public key K
    2. recipientS = k · Ethe same secret, from the xSHADE Secret k and E = e · G
    3. bothh = keccak256(S)first 2 bytes of S become the scan tag
    4. bothP = K + h · Gthe one-time public key
    5. bothpayTo = addr(P)the receiving address
    6. recipientp = k + h mod nthe recipient spending key

    Curve secp256k1. Source: xshade-x402/src/keys.ts and XShade-Main.sol.

    On chain now

    Robinhood Chain
    Shielded addresses announced…

    No announcements yet. The first private payment on this contract shows up here.

    This is everything the contract stores: an ephemeral point and a 2-byte tag. No receiver.

    Infrastructure for autonomous economic activity.

    As software increasingly participates directly in economic transactions, payment infrastructure will need to support machine-native requirements.

    1. 01

      Programmatic authorization.

    2. 02

      Open settlement.

    3. 03

      Persistent identity.

    4. 04

      Independent payment addresses.

    5. 05

      Non-custodial control.

    xSHADE is infrastructure for that environment.

    Or pay a person by hand

    The same shielded addresses work without an API. Send ETH or any token to someone's xSHADE Key from this app.
    1. Generate an addressCreate an xSHADE Key in your browser. Share the public key. Keep the secret file.Open wallets
    2. Send any token to itThe sender pastes your key. ETH or any ERC-20 lands on a fresh shielded address.Send privately
    3. Scan and withdrawYour secret finds every address that is yours. Withdraw to any wallet.Receive

    xSHADE

    Privacy infrastructure for the x402 economy.

    A non-custodial receiving layer designed for programmable payments and autonomous commerce.

    x402 compatible · Non-custodial · Open architecture

    xSHADE is non-custodial. Your xSHADE Secret never leaves this browser.chain 4663