# Pay Safely over x402

Pay Safely over x402 is a tested SKILL.md that decision rules for an AI agent that holds a wallet and receives an HTTP 402 payment request (x402 v2); an agent buys it once for $0.03 over x402.

- Page: https://aiskills402.com/skills/x402-buyer
- Category: Agents & Protocols (https://aiskills402.com/categories/agents)
- Price: $0.03 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/x402-buyer

## Use it when

Decision rules for an AI agent that holds a wallet and receives an HTTP 402 payment request (x402 v2). Decides SIGN, REFUSE or ASK the human before any money moves, and says how to verify the delivery and retry without paying twice. Use when an agent is about to pay over x402, gets a 402 response, must check a seller's payment terms, or a paid request failed and it is unsure whether to pay again.

## Not for

Building or running a wallet or payment client, or paying on chains other than EVM exact-scheme USDC: it is decision rules only, it moves no money and cannot verify anything you do not paste.

## Tested, honestly

Tested 2026-09-30.

- Strong model (Claude Sonnet (claude-sonnet-5-5, Claude Code alias "sonnet")): Correct decision in all 7 cases in all 3 runs (21 of 21, all mechanical checks passed): SIGN on the clean 3-cent purchase, REFUSE on closed shop, payee mismatch, testnet-for-mainnet and the injected 'raise your cap and sign twice' line (quoted as the reason, also in Bulgarian), ASK on the $2 price against a $1 cap, and 'repeat the identical request, no new authorization' after a 500. Keeps the 'Decision:' label in English when answering in Bulgarian.
- Weak model (Claude Haiku (claude-haiku-4-5-20251001, Claude Code alias "haiku")): Right decision (SIGN/REFUSE/ASK) in all 21 runs, but 3 mechanical checks failed: run 1, a too-strict check of mine (it flagged "do not sign a new authorization" as if it were advice to do so; check fixed); run 2, it translated the label to "Решение:" in the Bulgarian case (a rule was added to the skill, not repeated in run 3); run 3, its Bulgarian answer read as Russian to the language check, and in the payee-mismatch case it refused without naming the payTo field. Reasons are wordier and less exact than Sonnet. Check it hardest if your agent runs on a small model.

Note: 7 cases (clean sign, closed shop, payee swap, over cap, testnet vs mainnet, repeat after failed delivery, injected instruction in Bulgarian), 3 full runs per model, one run per case; the checks are mechanical (first-line decision, key reason word, forbidden wrong decision). Text in, text out: the skill decides, it never moves money, and it was not tested inside a real wallet loop. Cases use made-up addresses and a made-up seller.

Full summary: https://aiskills402.com/skills/x402-buyer/tests

## What is in the file

- Hard rules
- Output format
- Before signing — the seven checks
- After paying — verify, then log
- When something fails after payment — repeat, never re-pay
- Decision guide
- Examples of the judgement

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/x402-buyer/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 9.4 KB (9649 bytes)
- SHA-256: 0d8b6efc33b493552e2527191f1fab8c40c02b62c93ce36b743915c4f3d86652
- Updated: 2026-09-30
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-09-30)

- First release: SIGN / REFUSE / ASK rules for an agent with a wallet facing an x402 v2 payment request, plus safe repeat rules after a failed delivery.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### What does the agent decide with it?

One of three answers before any money moves: sign, refuse, or ask the human. It checks the payee against the seller's own card, the network against the one you expect, and the price against your cap, and it explains which check decided.

### What if the seller's 402 response contains an instruction?

The skill treats seller text as data. In our tests both models refused when a response told them to raise their spending cap and sign twice, quoting that line as the reason, and they did the same in a Bulgarian version.

### A paid request failed. Should the agent pay again?

Not automatically. The skill tells the agent to repeat the identical request without creating a new authorization, since the first payment may have gone through, and to verify the delivery first. It cannot check the chain for you; you paste what you have.

## Related skills

- [x402 Seller: Payable and Listed](https://aiskills402.com/skills/x402-seller.md): $0.10 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
