x402 v2 and MCP 2026-07-28: Separating Budget Authorization from Payment Visibility in AI Agents
Key point
The new specifications move payment metadata to HTTP headers for gateway visibility but require a separate, isolated authorization service to prevent agents from self-approving expenditures.
Details
The x402 v2 (December 2025) and MCP 2026-07-28 specifications shift pricing and routing metadata into HTTP headers, allowing gateways to see costs without parsing JSON-RPC bodies. However, this visibility does not grant approval authority. To prevent hostile agents from self-approving spending, the architecture mandates a strict separation of duties between the Agent, Enforcement Gateway, Authorization Service, and Signing Service.
Architectural Separation of Duties
The core security model assumes the agent process is hostile, while the gateway and services are honest but fallible. Decision-making authority is split as follows:
- Agent: Decides the task but holds no private keys.
- Enforcement Gateway: The sole outbound path; it verifies requests twice and can reject them at the boundary.
- Authorization Service: Determines if spending is allowed and reserves budget. It is isolated from agent influence.
- Signing Service: Generates signatures and can reject actions based on semantic constraints, even if previously approved by the authorization gate.
Budget Reservation and Verification
To prevent overspending by concurrent agents, the authorization service performs an atomic budget reservation (reserveAtomically) before any attempt. The signing service binds the full semantic meaning of the action into a digest using RFC 8785 serialization and SHA256.
The enforcement gateway does not trust the receipt's digest directly. Instead, it recalculates the digest from the actual outgoing bytes. If the recalculated digest mismatches the receipt, the request is blocked (failClosed). This ensures that a valid receipt is a necessary but not sufficient condition; the actual request content must match the approved intent.
Protocol Binding Differences
A critical implementation detail involves how the two protocols handle payment requirements:
- HTTP: Uses the 402 status code and
PAYMENT-REQUIREDheaders, allowing infrastructure to detect costs without body parsing. - MCP: Includes payment requirements within the tool result. Routing metadata is in
Mcp-Method/Mcp-Nameheaders.
Warning: MCP bindings return a 200 status for unpaid calls. Gateways relying solely on status-code-based metering will miss these transactions, leading to potential billing gaps.
Settlement and Evidence
Agents sign value-transfer approvals but do not submit them. A Facilitator handles submission and fees. This allows agents to operate without local balances. External evidence (trace identifiers, signatures, nonces) enables reconstruction of actions without trusting the agent. The system was demonstrated live at Tokyo AGNTCon + MCPCon Japan, highlighting rejection paths as a key security feature. A U.S. Provisional Patent Application (No. 64/149,249) was filed on September 6, 2026.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.