{"_id":"@altananetwork/x402-server","_rev":"2-6d22c56c09d54520d9da3058913757c3","name":"@altananetwork/x402-server","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@altananetwork/x402-server","version":"0.1.0","keywords":["x402","b402","payments","agentic","merchant","eip-3009","permit2","altana"],"license":"GPL-3.0-or-later","_id":"@altananetwork/x402-server@0.1.0","maintainers":[{"name":"dorisg_xyz","email":"doris@functor.sh"}],"homepage":"https://docs.altana.network","bugs":{"url":"https://github.com/altananetwork/sdk/issues"},"dist":{"shasum":"4c55881425f49ac59c581229ca16506af7e12da3","tarball":"https://registry.npmjs.org/@altananetwork/x402-server/-/x402-server-0.1.0.tgz","fileCount":34,"integrity":"sha512-8O76cHC4ks0oPwXBkUMmwYimib74H7GEfCPF65bkGHgxlkfT4+pLClpwnd/lIupLB6gUEHhI5tNgmsFuAFVGzA==","signatures":[{"sig":"MEQCIEmirDX1wrlJM9/8R61LqhsQZtgvLIYX1wxssRXarw/4AiB91hoOqXhk7vo6PavR4Qi/XfUMx0KJWnMKxoVyxVwyaA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61827},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"0026bdf08c1e32bb50878bf50274774c5bc82cf9","scripts":{"test":"bun test","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-publishable.mjs && bun run build"},"_npmUser":{"name":"dorisg_xyz","email":"doris@functor.sh"},"repository":{"url":"git+https://github.com/altananetwork/sdk.git","type":"git","directory":"packages/x402-server"},"_npmVersion":"11.12.1","description":"Seller-side x402/B402 payments: 402 challenges, X-PAYMENT verification (EOA + ERC-1271), and on-chain settlement for agents charging per request.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"viem":"^2.21.0","@altananetwork/sdk":"^0.6.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3"},"_npmOperationalInternal":{"tmp":"tmp/x402-server_0.1.0_1784638734611_0.723341335707947","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@altananetwork/x402-server","version":"0.2.0","description":"Seller-side x402/B402 payments: 402 challenges, X-PAYMENT verification (EOA + ERC-1271), and on-chain settlement for agents charging per request.","license":"GPL-3.0-or-later","repository":{"type":"git","url":"git+https://github.com/altananetwork/sdk.git","directory":"packages/x402-server"},"homepage":"https://docs.altana.network","bugs":{"url":"https://github.com/altananetwork/sdk/issues"},"keywords":["x402","b402","payments","agentic","merchant","eip-3009","permit2","altana"],"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test":"bun test","prepublishOnly":"node ../../scripts/check-publishable.mjs && bun run build"},"dependencies":{"@altananetwork/sdk":"^0.7.0","viem":"^2.21.0"},"devDependencies":{"typescript":"^5.6.3"},"publishConfig":{"access":"public"},"gitHead":"24d272014dd1c30dedde7933ed6ed320dc6972b9","_id":"@altananetwork/x402-server@0.2.0","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-zjvFJWtetoU7P9ugJuEhQqRgcZrsnjMsJayHY9kyYLK1NcD5I3TBNncFlCEtOOjHVZML+BKcdHbxgal9eDHPPw==","shasum":"d02f043867a013543e2d2aea32c21760805768e0","tarball":"https://registry.npmjs.org/@altananetwork/x402-server/-/x402-server-0.2.0.tgz","fileCount":34,"unpackedSize":63668,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCOgUdsgJwoQbqj5C81z7ynZ2eVr2uvDhe7NrLk+bH2xAIhAK/n+iWX04G+NFWocPEs3gU14BJvGIps0+XKJEjYNIOb"}]},"_npmUser":{"name":"dorisg_xyz","email":"doris@functor.sh"},"directories":{},"maintainers":[{"name":"dorisg_xyz","email":"doris@functor.sh"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/x402-server_0.2.0_1785853303189_0.7622722692662589"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-21T12:58:54.346Z","modified":"2026-08-04T14:21:43.587Z","0.1.0":"2026-07-21T12:58:54.745Z","0.2.0":"2026-08-04T14:21:43.360Z"},"bugs":{"url":"https://github.com/altananetwork/sdk/issues"},"license":"GPL-3.0-or-later","homepage":"https://docs.altana.network","keywords":["x402","b402","payments","agentic","merchant","eip-3009","permit2","altana"],"repository":{"type":"git","url":"git+https://github.com/altananetwork/sdk.git","directory":"packages/x402-server"},"description":"Seller-side x402/B402 payments: 402 challenges, X-PAYMENT verification (EOA + ERC-1271), and on-chain settlement for agents charging per request.","maintainers":[{"name":"dorisg_xyz","email":"doris@functor.sh"}],"readme":"# @altananetwork/x402-server\n\nSeller-side x402/B402 payments for agents that charge per request.\n\nPut `guard()` in front of any HTTP route and it becomes a paid capability:\nunpaid requests get a 402 challenge; requests carrying a valid `X-PAYMENT`\nheader are settled **on-chain, immediately** and passed through.\n\nPayable out of the box by:\n\n- **BNB Agent Studio agents** (`bag x402 trust <your-url>` → `bag x402 buy`) —\n  they sign EIP-3009 `TransferWithAuthorization` on $U (United Stables).\n- **Altana SDK agents** (`fetchWithX402` / the MCP `x402_request` tool) —\n  smart-account session keys signing the B402 permit2-exact rail (ERC-1271).\n- Anything else speaking the B402 v2 wire (CAIP-2 networks, `scheme:\"exact\"`,\n  `extra.assetTransferMethod`).\n\n## Usage\n\n```ts\nimport { privateKeyToAccount } from \"viem/accounts\";\nimport { bsc } from \"viem/chains\";\nimport { createX402Merchant, U_TOKEN, USDT_BSC } from \"@altananetwork/x402-server\";\n\nconst merchant = createX402Merchant({\n  chainId: 56,\n  payTo: \"0xYourAltanaSmartAccount\",          // where earnings land\n  price: 200_000_000_000_000_000n,            // 0.2 per call (18 dec)\n  minPrice: 50_000_000_000_000_000n,          // clamp floor\n  maxPrice: 2_000_000_000_000_000_000n,       // clamp ceiling\n  rails: [\n    { rail: \"eip3009\", token: U_TOKEN[56] },  // Studio buyers\n    { rail: \"permit2-exact\", token: USDT_BSC, spender: facilitator.address }, // Altana/B402 buyers\n  ],\n  resource: \"https://api.example.com/audit\",\n  facilitator: privateKeyToAccount(process.env.FACILITATOR_KEY),  // settler EOA (gas only)\n  rpcUrl: \"https://bsc-dataseed.binance.org\",\n  chain: bsc,\n});\n\nBun.serve({\n  port: 8080,\n  async fetch(req) {\n    const { response, receipt } = await merchant.guard(req);\n    if (response) return response;             // 402 (challenge or rejection)\n    return Response.json({ data: await doTheWork(), tx: receipt.txHash });\n  },\n});\n```\n\n## How settlement works\n\n| Rail | Buyer signs | Settled via | Verified by |\n| --- | --- | --- | --- |\n| `eip3009` | `TransferWithAuthorization` ($U) | `token.transferWithAuthorization(bytes)` | the token contract |\n| `permit2-exact` | `PermitWitnessTransferFrom` (any Permit2-approved token) | `Permit2.permitWitnessTransferFrom` | Permit2 |\n\nThe facilitator account only broadcasts and pays gas — funds move directly\nfrom the payer to `payTo`. The recipient is **bound into the buyer's\nsignature** (EIP-3009 `to` / the permit2 `Witness`), so a compromised\nfacilitator key cannot redirect earnings.\n\nOff-chain checks run first (token, amount within `[minPrice, maxPrice]`,\nrecipient, expiry, signature). Checker-restricted smart accounts (Altana\nsession keys answer `isValidSignature` only to their approved checker) defer\nthe signature check to the settling contract — an invalid signature reverts\nthe settlement, and the request is refused. Replay is impossible: EIP-3009\nnonces and the Permit2 nonce bitmap burn on-chain.\n\n## Verified end-to-end\n\n`tests/e2e/fork-x402-server.ts` runs both buyer families against a real\nBNB-mainnet fork (genuine $U, USDT and Permit2 bytecode): Studio-envelope\neip3009 settlement, Altana session-key permit2-witness settlement, and replay\nrefusal. Run it with `bun run fork:x402-server` from `tests/e2e`.\n","readmeFilename":"README.md"}