x402 Payments
on Canton

Agent payments, made institutional.

FTP Tech LLC operates the payment infrastructure that lets an HTTP API charge per request and settle each payment on-ledger in Canton Coin or USDCx, using the x402 standard. Every payment is a verifiable, non-custodial transfer on Canton MainNet.

What it provides

Four properties define the offering. Each payment is metered per request, settled in Canton Coin or USDCx, verified on-ledger, and routed through a facilitator that controls no funds.

Charge per HTTP request

Gate any route behind a price using the standard 402 Payment Required flow. A client receives the price, pays, and retries with proof in a single extra round trip.

Settle in Canton Coin or USDCx

Each payment settles natively on Canton MainNet, in Canton Coin or in a CIP-56 registry token such as USDCx, in a single ledger transaction with no bridging step in the payment path. Amounts settle as fixed-scale Daml Decimals; on the wire they are quoted as integer atomic units.

On-ledger verification

Settlement is an on-ledger transfer confirmed by the Global Synchronizer, not an off-ledger voucher. The resulting updateId is the proof, resolvable on any Scan API.

Non-custodial facilitator

The facilitator relays each payment on-ledger but never holds buyer or seller funds: it submits a transfer the payer already signed and cannot sign on the payer's behalf. Per-party projection means it sees only the transfer it was asked to verify.

How it works

A payment is one extra round trip layered onto a normal HTTP request. The server prices the call, the client signs a transfer and retries with it carried in the payment header, and the facilitator verifies and relays it on-ledger before the server delivers.

Request

The client calls the gated route with no payment attached.

402

The resource server answers 402 with its price and a PAYMENT-REQUIRED header describing the exact payment requirements.

Sign

The client builds and signs the transfer with its own key and retries the request, carrying the signed transfer inline in the payment header. It does not submit the transfer itself.

Settle

The facilitator checks the signed transfer against the server's requirements, relays it on-ledger in a single transaction and pays the network fee, and the server runs the handler and returns 200 with the settlement updateId.

The wire format follows upstream x402 v2 carried in base64-encoded JSON headers, with the Canton-native exact scheme. For the full handshake, headers, and error reasons, see the documentation or the live demo.

The building blocks

The offering ships as three components: a facilitator that verifies and settles, a client SDK that pays, and middleware that gates a resource server. Each is independent and conforms to the x402 specification.

Facilitator

A service the merchant calls per request. It verifies a payment against the resource server's requirements, then relays the payer-signed transfer on-ledger in a single transaction, paying the network fee so the payer pays no gas. A hosted facilitator is live over HTTPS; teams can also run their own. Ships via Docker and source.

facilitator.ftptech.xyz

Client SDK

Wraps fetch with a Canton signer. The wrapped fetch detects a 402, builds and signs the payment with the caller's party key, retries, and returns the final response with the settlement header.

@ftptech/x402-canton-client

Resource-server middleware

Drop-in middleware for Express and a wrapper for the Next.js App Router. It runs the full handshake, pins every payment to the route's configured requirements, and runs the handler only after settlement succeeds.

@ftptech/x402-canton-express · -next
Install
# Charge for an API (resource server)
npm i @ftptech/x402-canton-core @ftptech/x402-canton-express

# Pay for an API (client)
npm i @ftptech/x402-canton-core @ftptech/x402-canton-client
Published packagesApache-2.0
  • @ftptech/x402-canton-core1.3.0
    Wire types, header encoding, requirements pinning.
  • @ftptech/x402-canton-ledger0.5.0
    Canton ledger and Scan clients, external-party signing.
  • @ftptech/x402-canton-client1.2.1
    Buyer SDK: wrapFetchWithCantonPayment and the CantonSigner interface.
  • @ftptech/canton-agent-wallet2.3.0
    Self-custody agent wallet and signer: makePayingFetch, plus the CLI.
  • @ftptech/x402-canton-express0.2.6
    Express middleware cantonPaymentMiddleware.
  • @ftptech/x402-canton-next0.2.6
    Next.js wrapper withCantonPayment.

The facilitator ships via Docker and source, not npm.

Who it is for

The same infrastructure serves the seller, the buyer, and the institution that needs settlement it can audit on the ledger.

API providers

Meter and monetize an HTTP API per request without managing subscriptions, keys, or invoices. Pricing is enforced server-side, per route.

AI-agent builders

Give an autonomous agent the ability to pay for a gated resource and retry, settling each call on-ledger from its own party.

Institutions

Settle agent and machine payments on Canton MainNet with on-ledger finality, per-party privacy, and a non-custodial settlement path that controls no funds.

Evaluating x402 for your institution

FTP Tech LLC runs the hosted facilitator and supports self-hosted deployments on your own validator. Reach out to discuss an integration.

Talk to us

The facilitator never controls buyer or seller funds. It verifies each payment against the resource server’s requirements and relays it on-ledger in a single transaction it cannot alter; the transfer is signed by the payer, so funds move only as the parties authorized themselves.

Settlement is verifiable on the ledger: every paid request resolves to an updateId on Canton MainNet that either party can confirm on any Scan API. Built on the Canton Network and the Canton Token Standard, the integration is open source under Apache-2.0.

Let’s build something
that stays online

Launching a network, need a battle-tested validator, or want a community that actually shows up? Talk to us.