Open source · Apache-2.0 · Whitechain Sepolia eip155:1874
Whitechain x402 Facilitator
Accept x402 payments on Whitechain. Point any standard x402 server at this facilitator and AI agents can pay your API per request, in EIP-3009 tokens, on WhiteBIT's L2. The payer pays you directly; the facilitator verifies, settles and covers the gas.
Public facilitator URL https://x402-facilitator-production-ff5f.up.railway.app free on testnet, no sign-up
- Network
- Whitechain Sepolia · eip155:1874
- Scheme
- exact · EIP-3009
- Custody
- None, payer pays merchant
- Gas
- Paid by the facilitator in WBT
- Compatible with
- @x402/express, hono, next, fetch, axios
- Testnet price
- Free, with limits
What is x402?
x402 is an open payment protocol built on the HTTP status code 402 Payment Required. A server answers an unpaid request with 402 and a machine-readable price. The client, typically an AI agent or another API, signs a payment for exactly that amount and retries the request with a PAYMENT-SIGNATURE header. The server asks a facilitator to verify the signature and, once the response has been produced, to settle it on chain. No accounts, no API keys, no invoices: one HTTP round trip, one on-chain transfer.
The facilitator is the only piece of infrastructure in that loop. This project is that piece for Whitechain: a standard x402 v2 facilitator with /verify, /settle and /supported endpoints, so the official x402 middleware and clients work on Whitechain without modification.
Why Whitechain for agent payments
WhiteBIT ecosystem
Whitechain is the EVM network of the WhiteBIT exchange. Merchants and agents that already hold WBT or stablecoins in that ecosystem can use them for pay-per-request APIs without leaving it.
OP Stack L2, 1-second blocks
Whitechain runs the OP Stack. Blocks arrive about every second, so an x402 settlement is confirmed within the same HTTP request instead of making the client wait.
Low fees, gas in WBT
A settlement is one transferWithAuthorization call. Gas is paid in WBT by the facilitator, so micropayments of a fraction of a cent stay economical and the payer needs no gas at all.
USDC.e via the Portal
Bridged USDC.e on Whitechain mainnet follows Circle's FiatToken interface, including EIP-3009, which is exactly what x402's exact scheme signs. Testnet uses the Inferit Test Credit (ITC), an EIP-3009 faucet token.
How a paid request works
- Agent calls your APIYour x402 middleware answers
402with the price: token, amount, yourpayTo, networkeip155:1874. - Agent signs, retriesThe client signs an EIP-3009 authorization for exactly that amount, valid for a short window, and resends the request with
PAYMENT-SIGNATURE. - Facilitator verifiesYour middleware POSTs to
/verify. The facilitator checks the signature, balance, nonce and expiry, then your handler runs. - Facilitator settlesAfter a successful response,
/settlesubmits the authorization on chain. Tokens move from payer to you; the facilitator pays the gas.
Quickstart
Two sides, no contracts to deploy. The merchant adds the official x402 middleware with this facilitator's URL; the agent wraps fetch. Full, runnable versions live in the examples directory.
Merchant: sell an endpoint with Express
npm install @x402/express @x402/core @x402/evm expressimport express from "express";
import { paymentMiddleware, x402ResourceServer } from "@x402/express";
import { HTTPFacilitatorClient } from "@x402/core/server";
import { ExactEvmScheme } from "@x402/evm/exact/server";
const facilitator = new HTTPFacilitatorClient({ url: "https://x402-facilitator-production-ff5f.up.railway.app" });
const server = new x402ResourceServer(facilitator).register("eip155:1874", new ExactEvmScheme());
const app = express();
app.use(paymentMiddleware({
"GET /weather": {
accepts: {
scheme: "exact",
network: "eip155:1874", // Whitechain Sepolia
payTo: "0xYourMerchantAddress",
price: { // 0.01 ITC (6 decimals)
asset: "0x2E672dFE33EA977FD064E01aDe7d8c73B3Be7fBB",
amount: "10000",
extra: { name: "Inferit Test Credit", version: "1" },
},
},
description: "Current weather, paid per request on Whitechain",
},
}, server));
app.get("/weather", (_req, res) => res.json({ city: "Lisbon", temperatureC: 24 }));
app.listen(4021);
Hono is the same four lines with @x402/hono; Next.js uses @x402/next. Prices on Whitechain name the token explicitly (address, atomic amount, EIP-712 domain) because the x402 SDK has no "$" default asset for this chain yet.
Agent: pay with fetch
npm install @x402/fetch @x402/evm viemimport { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const account = privateKeyToAccount(process.env.AGENT_PRIVATE_KEY as `0x${string}`);
const fetchWithPayment = wrapFetchWithPaymentFromConfig(fetch, {
schemes: [{ network: "eip155:1874", client: new ExactEvmScheme(account) }],
spendControls: { // allow the Whitechain token, cap each payment
allowedAssets: [{ network: "eip155:1874", asset: "0x2E672dFE33EA977FD064E01aDe7d8c73B3Be7fBB", maxAmountPerPayment: "100000" }],
},
});
const res = await fetchWithPayment("https://api.example.com/weather");
console.log(await res.json()); // paid: 402 -> signed -> 200
The agent needs ITC, not WBT: the facilitator pays the gas. Get test ITC from the token's public faucet and test WBT from the Whitechain faucet only if you run your own facilitator.
Supported networks and tokens
| Network | CAIP-2 | Scheme | Tokens | Status |
|---|---|---|---|---|
| Whitechain Sepolia (testnet) | eip155:1874 | exact (EIP-3009) | Inferit Test Credit (ITC), faucet token, 6 decimals; any EIP-3009 token | Live, free |
| Whitechain mainnet | eip155:<chain id> | exact (EIP-3009) | USDC.e via the Whitechain Portal; any EIP-3009 token | Config entry, not yet public |
| Any network | via NETWORKS | exact via Permit2, upto | Any ERC-20, once the x402 Permit2 proxies exist on that chain | Roadmap |
RPC https://rpc.testnet.whitechain.io · Explorer https://explorer.testnet.whitechain.io · Gas token WBT. Networks are configuration, not code: the mainnet entry is a JSON object with the chain id Whitechain publishes, its RPC and its explorer.
HTTP API
The wire format is x402 v2 exactly as @x402/core's HTTPFacilitatorClient sends it. You normally never call these yourself; the middleware does.
| Endpoint | Purpose |
|---|---|
GET /supported | Schemes, networks and facilitator signer addresses. Middleware calls it on start. |
POST /verify | Checks a paymentPayload against paymentRequirements: signature, EIP-712 domain, amount, expiry, nonce, balance. Returns isValid and a reason. |
POST /settle | Re-verifies and submits transferWithAuthorization. Returns success, transaction, network, payer. |
GET /health | Status, facilitator wallet gas balance and settlement runway per network. |
GET /metrics | JSON counters: verifies, settles, failures by reason, gas spent. |
Policy refusals keep the x402 body shape with a non-2xx status, so HTTPFacilitatorClient surfaces them as typed errors: unsupported_scheme_network (400), invalid_api_key (401), address_denylisted (403), duplicate_settlement (409), rate_limit_exceeded and gas_budget_exceeded (429, with Retry-After), rpc_unavailable (503). Full request and response examples and the complete reason-code table are in the API reference.
Testnet policy: free, within limits
The public facilitator sponsors every settlement on Whitechain Sepolia. To keep that sustainable it enforces:
- Rate limits per client IP, per payer address and per
payToaddress (token buckets; defaults 120, 30 and 120 requests per minute), plus a facilitator-wide ceiling of 1,200 per minute. - A daily gas budget per
payToand a global one, checked on verify as well as settle; a payment beyond the budget is refused withgas_budget_exceededand aRetry-Afterthat points at the 00:00 UTC reset. - Optional merchant API keys (
X-API-Key) with higher limits and their own budget. - A sanctions denylist of addresses, sourced from the public OFAC SDN list, checked on both payer and payee.
Nothing is stored about you beyond counters and short-lived rate-limit keys. Signatures are never logged.
Security model
No custody
Funds move payer to payTo in one transfer the payer signed. The facilitator cannot change the recipient or the amount; the signature covers both.
Signature first
Verification uses the official @x402/evm facilitator scheme: EIP-712 domain, EIP-1271 and ERC-6492 smart-wallet signatures, nonce replay checks and balance reads, with an on-chain simulation before broadcasting.
Blast radius: gas
The signer key only holds WBT for gas. Leaking it costs at most that balance. It is read from FACILITATOR_PRIVATE_KEY, never written to logs or responses.
Sanctions hook
A denylist file (OFAC SDN crypto addresses) is reloaded on a schedule and applied to /verify and /settle. Operators can extend it.
Found a vulnerability? See the security policy.
Roadmap
- Whitechain mainnet: enable the mainnet network entry with USDC.e once Whitechain publishes the chain id and the token is bridged.
- Permit2 and
upto: Uniswap Permit2 is already deployed on Whitechain; the x402 Permit2 proxy contracts are not. The repo includes the deterministic-deployment check and script so they can land at their canonical addresses, which unlocks any ERC-20 and theupto(pay-what-you-use) scheme. - Fees: the fee hook (basis points or flat, in the payment token) is implemented and off by default; mainnet operators can turn it on or run sponsored.
- Bazaar listing and discovery extensions once the ecosystem settles on them.
Frequently asked questions
How do I accept x402 payments on Whitechain?
Run a standard x402 resource server (@x402/express, @x402/hono or @x402/next) and point its HTTPFacilitatorClient at this facilitator's URL. In the route config use scheme exact, network eip155:1874, your wallet as payTo, and a price that names an EIP-3009 token (address, atomic amount, and the token's EIP-712 name and version). No contract deployment is needed.
Does Whitechain support x402?
Yes. x402 is chain-agnostic: it needs an EVM chain, a token with EIP-3009 transferWithAuthorization, and a facilitator that verifies and settles. Whitechain is an EVM OP Stack L2 with 1-second blocks, so the x402 exact scheme works there unchanged. This project is the facilitator; on Whitechain Sepolia the Inferit Test Credit (ITC) is the EIP-3009 test asset.
Is there an x402 facilitator for WhiteBIT's Whitechain?
Yes: this is the first public x402 facilitator for Whitechain. It is an independent open-source project (Apache-2.0) built by Sahil Massey at Inferit, not an official WhiteBIT or Whitechain service. Anyone can use the hosted endpoint on testnet or self-host it.
Do AI agents need WBT for gas to pay on Whitechain?
No. The agent signs an EIP-3009 authorization off-chain and sends it in the PAYMENT-SIGNATURE header. The facilitator submits transferWithAuthorization and pays the WBT gas. The agent only needs a balance of the token being charged, such as ITC on Whitechain Sepolia.
Which tokens can be used for x402 payments on Whitechain?
Any ERC-20 that implements EIP-3009 with a FiatToken-style EIP-712 domain: ITC on Whitechain Sepolia, and bridged USDC.e on mainnet once configured. Other ERC-20s can be charged through Uniswap Permit2 where the x402 Permit2 proxy contracts exist on the network.
How much does the Whitechain x402 Facilitator cost?
The public testnet facilitator is free: it sponsors the gas for every settlement within per-IP, per-payer and per-merchant rate limits and a daily gas budget. For mainnet the software has a fee hook (percentage or flat, in the payment token) that is off by default, so an operator can run it sponsored or fee-funded.
Does the facilitator hold my funds?
No. An x402 exact payment is a single on-chain transfer from the payer directly to the merchant's payTo address. The facilitator checks the signature and balance, submits the signed authorization and pays gas. It cannot redirect, hold or reverse funds, and it never sees the payer's private key.
Can I self-host the Whitechain x402 Facilitator?
Yes. It is Apache-2.0 licensed, ships a Dockerfile, and is configured through environment variables: FACILITATOR_PRIVATE_KEY for the gas wallet, NETWORKS as JSON for chain id, RPC and explorer, plus rate limits, gas budgets, API keys and a denylist file. See self-hosting.
How do I pay a Whitechain x402 API from an AI agent?
Wrap fetch with @x402/fetch, register ExactEvmScheme for eip155:1874 with a viem account, and allow the Whitechain token in spendControls.allowedAssets with a per-payment cap. The wrapper reads the 402, signs the EIP-3009 authorization and retries with the payment header automatically.
Is this an official Whitechain or WhiteBIT product?
No. It is an independent community project. Whitechain and WhiteBIT are trademarks of their owners, used here only to describe compatibility. The project is not affiliated with, sponsored by or endorsed by Whitechain, WhiteBIT, Coinbase, Circle or the x402 Foundation.
Built by
Sahil Massey at Inferit, where x402 on Whitechain already pays for open-weight LLM inference per request. The facilitator was split out so any merchant and any agent can use it. Contributions are welcome: see CONTRIBUTING.md.