Skip to main content
ForgeMeshProtocol watch ·

401 asks who you are. 402 asks you to pay. The agent web just got both.

Two interlocked glowing rings, one carrying an identity mark and one carrying a coin, joined like a handshake

Since 1997, HTTP has carried two status codes that sat side by side doing almost nothing: 401 Unauthorized— “tell me who you are” — and 402 Payment Required— “pay me.” We’ve spent the past year building a business on the second one: our fleet answers hundreds of thousands of 402 challenges a month, selling data to AI agents for USDC micropayments. This summer, the first one finally got its job. Proof’s x401 protocol — launched June 25 with backing from Circle, OpenAI, Google, and Okta — gives every website and API a standard way to ask the question the agent economy has been dodging: which human is actually behind this agent?

What x401 actually is, in plain language

Today, when an AI agent shows up at a paid endpoint, the seller knows exactly one thing about it: whether its money is good. That’s what x402 proves, and for a $0.001 weather lookup it’s plenty. But the moment an agent wants to do something that matters — sign a contract, access age-restricted data, spend real money on someone’s behalf — “the money is good” stops being enough. x401 lets the service respond the way a bouncer would: prove it. The agent answers with a cryptographically signed credential — a Verifiable Credential, the same W3C standard behind digital driver’s licenses — attesting to exactly the claim requested: verified identity, age, company affiliation, signing authority, or simply “a real human authorized this.”

The clever part is what it doesn’treveal. Selective disclosure and zero-knowledge proofs mean the agent can prove “my principal is over 18” or “my principal is an employee of X” without handing over a name, a birthdate, or a passport scan. The service verifies the issuer and the claim, not the person’s whole identity. Circle’s VP of Product put the pairing in one sentence: “x402 answers how an agent pays, x401 answers who it is.”

Why sellers in this economy should care

It unlocks the expensive endpoints

Nobody needs identity to sell a $0.005 timezone lookup. But the endpoints the agent economy keeps NOT building — legal research, medical data, financial actions, anything regulated — are stuck precisely because sellers can’t know who’s buying. A standard way to require "verified human, verified org, verified authority" is the unlock for everything above the micropayment tier.

It’s an anti-fraud layer we felt the need for this week

Days ago we documented an address-poisoning attack on our own fleet — possible because on-chain, a wallet is just 40 anonymous characters. An identity layer that binds "this wallet acts for this verified principal" makes impersonation-by-lookalike dramatically harder. Payments without identity is exactly the gap that attack lives in.

The backers are the tell

Circle settles nearly all x402 volume; OpenAI and Google own the agents; Okta owns enterprise identity. The same institutional crowd that joined the x402 Foundation in July is assembling around the identity half. Proof says it will submit x401 to the FIDO Alliance’s agentic-authentication workgroup — the same body that took over Google’s AP2. The standards are consolidating fast.

The honest caveats

x401 launched with a spec, docs, sample apps, and one live implementation — Proof’s own digital ID. That’s a real start, not an ecosystem. “Issuer-neutral” is the promise, but today the flagship issuer is the company that wrote the protocol, and the value of any identity network is exactly as large as its slowest-moving verifier. We’ve also watched this movie before: x402 taught us that a protocol can be institutionally blessed and still have a quarter of its sellers unable to take a payment. Standards announcements are the easy part; interop is where economies are actually built — or quietly lost.

Our plan: we’ll prototype an x401 challenge on one of our own gated endpoints the same way we dogfood everything else — pay it, probe it, break it, and publish what we find. If the agent web is getting a second handshake, we want field notes from the first grip.

Selling to agents?

We run 500+ paid endpoints and publish everything we learn — including the incidents. The free scan checks whether stock agent clients can actually pay your endpoint today, on the rail that already works.

Related reading: the three rulebooks being written for how agents pay and the wallet-impersonation attack that identity would have blunted.

Filed under
  • protocol
  • identity
  • x401
  • news
From the archiveAll posts →
ShareXLinkedInRedditHN