AI Briefing
KOSign in

Enterprise MCP Server Obligations for x402 v2 and MCP 2026-07-28 Payment Integration

·2026.09.30 18:00

Key point

The article defines five critical server obligations, including price re-verification and replay rejection, to secure agent payments under the new x402 v2 and MCP 2026-07-28 specifications.

1 / 2

Details

The integration of x402 v2 (released December 2025) and the MCP 2026-07-28 specification introduces a new paradigm where infrastructure must actively recognize and enforce pricing for AI agent transactions. While x402 v2 moves payment data to HTTP headers (PAYMENT-REQUIRED, PAYMENT-SIGNATURE, PAYMENT-RESPONSE) and MCP 2026-07-28 removes session IDs in favor of explicit routing headers (Mcp-Method, Mcp-Name), the core challenge remains defining who decides spending limits and how servers must validate those decisions.

The Four Decision Points for Paid Tool Calls

The shift from simple tool invocation to paid execution splits the decision process into four distinct layers, each with specific failure modes:

  • What work: Determined by the agent/model. Failure results in poor planning or wasted low-cost attempts.
  • Who is asking: Verified by ID providers or gateways. Failure allows unauthorized or out-of-scope access.
  • What it costs: Calculated by the server based on arguments. Failure leads to overpayment or underpayment.
  • Whether permitted: Determined by a budget authority independent of the agent. Failure allows agents to manipulate spending limits through persuasion or prompt injection.

The article emphasizes that the fourth decision—budget authority—must be isolated from the agent's context. The threat model assumes the agent process and its inputs (prompts, tool outputs) are hostile, capable of attempting price misreporting, wrong payee designation, or authorization replay. Gateways and servers are assumed to be honest but fallible.

Five Obligations for Enterprise MCP Servers

To secure the payment flow, servers must adhere to five strict obligations that go beyond protocol compliance:

  1. Price Verification: Servers must recalculate prices based on current arguments or verify bindings of previous quotes (resource, args, conditions, expiry). Never trust client-presented prices.
  2. Free Discovery: The tools/list endpoint must have a cost of 0 to allow agents to compare options before purchase.
  3. Explicit Replay Rejection: Servers must atomically track authorization usage across all instances, preserve records for the validity period, and define idempotent retry logic for settlement failures.
  4. Local Payee Enforcement: Servers must use their own configured address for payment, ignoring any payee specified in the authorization request.
  5. Binding Disclosure: Servers must explicitly state whether they support HTTP or MCP bindings and which clients have been tested.

Implementation and Security Patterns

The article highlights a pattern where spending permission is evaluated using two independent primary sources: an authorization service and an egress enforcement point. The authorization service issues a short-lived signed receipt containing a canonical digest of the action, not the action itself. The egress point recalculates the digest from the actual bytes being sent and compares it to the receipt. This ensures that even if an agent modifies the request after approval, it cannot pass the enforcement point without a valid receipt matching the modified action.

Key technical details include:

  • x402 v2 Changes: Price field changed from maxAmountRequired to amount; network identifiers now use CAIP-2 (e.g., eip155:84532).
  • MCP 2026-07-28 Changes: Session removal (Mcp-Session-Id deprecated); versioning via MCP-Protocol-Version header.
  • Verification Order: Checks should proceed from low-cost to high-cost: version -> shape -> scheme/network -> asset -> payee -> amount -> nonce -> expiry -> signature recovery.
  • Replay Protection: In-memory nonce sets are insufficient for production; distributed atomic tracking is required to prevent double-charging across server instances.

The article concludes that while x402 v2 and MCP 2026-07-28 provide the mechanisms for price signaling and routing, the responsibility for defining and enforcing budget limits remains a critical developer and operator concern.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.