The Inspiration

Imagine an autonomous AI agent tasked with building a web application. It searches the internet, finds the perfect machine learning API to complete its task, but hits a brick wall: a Stripe checkout page.

Modern APIs rely on human-driven subscriptions and credit card forms. This infrastructure completely breaks down in the emerging world of agentic commerce. Autonomous systems cannot hold credit cards or navigate SaaS login walls, leaving developers without a viable way to monetize machine-to-machine traffic. We realized the solution wasn't a new payment processor, but reviving the forgotten HTTP 402 (Payment Required) standard using the deterministic power of the Cardano blockchain.

What it does

C402 is an Agentic Payment Gateway. It acts as a decentralized proxy that sits quietly in front of any Web2 API.

When a client attempts to access a protected endpoint without authorization, C402 immediately intercepts the request. Instead of returning a standard error, it issues a cryptographic HTTP 402 challenge. This challenge provides the exact price in ADA, the merchant payout address, and a unique cryptographic reference UUID.

The client dynamically constructs a Cardano wallet transaction, binds the challenge reference into the transaction metadata, and submits the ADA payment on-chain. C402 verifies the ledger settlement, permanently blocks replay attacks, and releases the requested API payload accompanied by a verifiable cryptographic receipt.

The Logic of Fees

Unlike Ethereum, where gas fees fluctuate wildly, Cardano’s model ensures that a transaction fee is known exactly before it is broadcast. C402 relies on the deterministic fee formula:

$$ \text{Fee}(tx) = a \cdot size(tx) + b $$

This predictability makes Cardano the ultimate settlement layer for agents managing finite budgets.

How we built it

We engineered C402 using a blend of Web2 proxy routing and Web3 cryptography, keeping developer integration incredibly lightweight.

  • Frontend: Built with React 18 and Vite. We utilized custom WebGL shaders to create a procedural, glassmorphic visual identity.
  • Wallet Protocol: We implemented @emurgo/cardano-serialization-lib-asmjs to programmatically build, sign, and submit real CIP-30 transactions directly from the browser.
  • Backend: An Express middleware intercepts target endpoints. It queries the Blockfrost ledger API to audit transaction UTxOs in real-time, ensuring the exact ADA amounts were settled.
// C402 drops into any existing Express backend
const paymentGate = c402Middleware({
  blockfrostProjectId: process.env.BLOCKFROST_KEY,
  developerAddress: process.env.PAYOUT_ADDRESS,
  priceLovelaces: 1000000 // 1 ADA
});

app.get('/api/v1/ai-agent', paymentGate, (req, res) => {
  res.json({ 
    payload: "API unlocked.", 
    receipt: res.locals.receipt 
  });
});

**Challenges we ran into**
Building a true pay-per-call system on a blockchain requires defending against malicious clients trying to game the network.

The Replay Attack: A client could pay 1 ADA and then reuse the exact same transaction hash for 10,000 requests. We engineered an atomic double-spend cache that marks hashes "spent" immediately upon verification.
Ledger Indexing Delays: A submitted Cardano transaction is not instantly available to Blockfrost. We implemented an intelligent frontend polling mechanism that handles HTTP 425 "Too Early" errors, waiting gracefully for the block to be indexed before retrying.
Cryptographic Size Limits: Cardano strictly limits transaction metadata string payloads to 64 bytes. We aggressively optimized our JSON challenge mapping to fit within the BasicConversions standard so the wallet doesn't crash during signing.

**The Vision**
The future of commerce isn't subscriptions; it's streaming payments. C402 is the bridge that allows autonomous agents to operate in a real economy, paying for the services they need, and enabling developers to monetize their creations at scale.

Built With

Share this project:

Updates

Submission history