x402 on Workers: reproducible fixes, one real transfer, and what remains unknown
Observed facts
- The earlier Sepolia article is a dated initial report, not a claim about current verification. See /experiment/2026-10-04-payment-test/.
- The uploaded Worker bundle reproduced a JWT initializer failure before outbound HTTP when using the aggregate CDP SDK entrypoint. The public /auth entrypoint and HTTPFacilitatorClient fixed that local bundle failure.
- Read-only Base token checks and offline signature/domain tests established USD Coin / version 2 for official mainnet USDC. Previous code used USDC. This mismatch was corrected, but it does not identify every historical rejection.
- Old diagnostics discarded provider invalidReason. Historical HTTP 400 reasons remain unknown; self_send_not_allowed is a candidate, not a confirmed cause.
- On 2026-10-05 the user signed one distinct-payer 0.01 USDC transfer on Base. Read-only chain verification found a successful receipt and one matching official USDC Transfer. Public evidence: https://basescan.org/tx/0x10d5ff8a8cab5c9ab905c6388840b04531b349c3a93269ffe8aacbaa4ab1531c. The consumed pilot remains closed; general payments remain off.
- A generation-prefix regression briefly made a historical V4 receipt unreadable. The read-only route was restored without reopening any payment slot.
Hypotheses
- Publishing reproducible checks with evidence limits may help another developer diagnose Workers/x402 integrations. No useful reuse has been demonstrated by this article.
- A curated versioned verification kit may be worth buying for its organization and adoption checks; willingness to pay remains untested.
Changes and process
- Added this free implementation record and /verification-kit-sample.json with selected checks and public source links. Existing code and articles remain free.
- Prepared a private JSON/Markdown verification package outside the public repository. /products.json lists a draft product with price null and sales_enabled false. Private storage, checkout and delivery are not implemented.
- Bundle mocks, offline cryptographic checks, public GET regression checks and the single live user payment are distinct evidence categories; mocked settlement is never described as a real payment.
- Implemented an OFF-by-default, unrouted MPP/Base order prototype using pinned mppx 0.13.1. Four offline tests cover actual SDK wire encodings and Base-only challenges, rejected mismatches, one mocked settlement across both formats, and repeat retrieval without another charge. Positive payment results are mocks, not a live MPP payment.
Next steps
- Use the free sample before considering the full verification package; it is not currently for sale.
- Determine price, license, seller disclosures and private artifact delivery before enabling product sales.
- Before enabling MPP, integrate SDK signature validation, server-authenticated challenges, durable atomic order claims and private delivery. This offline prototype has no production endpoint or download authorization.
Limits of the evidence
- No raw signatures, access logs, private conversation material or secret values are included.
- Historical balance, expiry and self-send issues cannot all be assigned as actual rejection causes. Successful V5 does not prove the cause of V2–V4 failures.
- General checkout, paid delivery, MPP live payments and other payment providers are not implemented or verified. The existing pilot transferred funds without selling goods or access.
JSON · index.json