x402 isn’t good (yet) — Jan Curn, Apify
Between the moment an x402 server verifies a payment signature and the moment it settles on the blockchain, nothing stops the buyer spending that money somewhere else. Jan Curn's point is that a client can mint a thousand signatures against one wallet, so any seller starting real work on the strength of a verification is exposed. The workaround is to do the work only after settlement, fine for a fixed price API call and awkward for anything slower. Curn is bullish enough on x402 to have shipped it two days before this talk, adding 20,000 Apify tools to a marketplace that previously carried about 2,000, a
Watch on YouTube →Transcript
Chapters11
- A callback to "MCP isn't good yet"
- Apify's 45,000 tools, and 10x'ing the x402 catalog
- The standards pileup, from L402 to Agent Pay
- Why crypto fits agentic payments, disputes included
- A 30 year old status code finally picked up
- The x402 flow, and the double spending window
- When x402 wants a 402 and MCP wants a 401
- Exact, then "up to", and what it still did not fix
- Charging in full, refunding the rest, and batch settlement
- AGI, an agent general interface
- Where the volume actually is today
A callback to "MCP isn't good yet"
00:12Hello everyone. Uh last year here at AI Engineer Worlds Fairfare, uh David Kramer from Sentry had a mildly provocative talk called uh MCP isn't good yet. And back then MCP was the new kit on the block, right? Uh it was like a lot of hype around it.
00:26people, you know, were excited about it, but also like it wasn't really developed back then very much and was fairly clunky. And in this talk, David argued, hey, like this technology is cool, but it has like a lot of rough edges, right? So, just, you know, go play with that, but you know, have your expectations low, right?
00:38By the way, they went on and actually built one of the best MCP servers on the market, right? Like Centric MCP is really like well very well-designed server, like nice design and so on. And actually over the the last year uh MCP became like a standard that's actually widely adopted you know across the industry like the top AI agents like cloud and chpt actually uh cloud offers MCP connectors right so you can plug tools into your AI agents uh uh chity calls it mc uh calls it apps but
01:10you can also like you know directory of different services you can plug into your cloud and it actually became a standard thing for agent to interaction right and u uh despite a little little hate also about MCP you know I have yet to see CLI connectors in any of these agents right so MCP1 and so inspired by David's talk uh today uh I have a similar talk uh which is called X42 isn't good yet and in that talk I would like to argue you know that uh while X42 is very exciting technology
01:42it has also still some rough edges you know and perhaps if I do it this well we'll also build one of the best integrations with X42 on the market like Centry did with NCP. My name is Yan Churn. I'm the founder and CEO of Appify. And uh for those who don't know, Appify is the largest uh marketplace of tools for AI.
01:53Uh we have
Apify's 45,000 tools, and 10x'ing the x402 catalog
02:02about 45,000 of these tools. uh we call them actors and they are spending use cases like you know extraction of data from social media sites, e-commerce, hospitality, travel, search engines, maps but over time also like age AI agents or agent use cases you know different automations and so on right and some of these tools some of these actors are built by our community some are built by us and our community is is making uh now more than $1 million per month on on payouts uh by selling these tools right
02:34They build the tools, we sell them to to to users and you know we pass the money to them and so it's a driving marketplace and I guess by now everybody understands like why we are so excited about agentic payments right because we really want our tools to be easily accessible to agents like wherever they are with whatever protocol is out there.
02:53Uh just two days ago we launched uh together with with Coinbase our our X42 integration. Uh I would say the the launch went pretty viral. we got like about million views. Um, and before before this launch, there were about like 2,000 tools available on the on the agentic u market basically on x4 x 402.
03:09We brought another 20,000 tools. So basically we 10x 10x the size of the of the agentic market uh on x42. So this is very exciting for us and we we believe also for the community and actually we're very excited about this topic like long term.
03:26So actually last year here at AI engineer worlds fair I was the only one talking about the agent e-commerce and agent economy in general and really argued that that like in a couple of years like the most most of the economic economic activity in the world will be done autonomously between agents and actually it looks like u uh really um it picked up uh I think like now everybody understands that agents in order to get work done or like longer jobs without even intervention they will actually need to have budget as well Right?
04:01It's it's not like uh you can do a lot of things in this world without without money. And once agents you know can be trusted with money, they will complete like far longer and you know more complex task than they can do now. So obviously lot of people understand this uh across the industry.
04:17So over the past year or so we saw a lot of new standards or agentic payments protocol coming to the market because obviously every player in f finance or or payments is very excited about this opportunity because everybody wants to get a part of this of this like huge future agentic economy and uh and uh transaction volume.
04:39So first was L402 uh it was like in mid 2020 but then uh
The standards pileup, from L402 to Agent Pay
04:47Mastercard agent pay we have X42 by Coinbase in May May last year. KY Pay from Skyfire with Visa. APA2 by Google. ACP by OpenAI and Stripe. Tab by Visa. Uh UCP by Google and Shopify. ACTP by Alipe. MPP by Stripe and Tempo. AMP by Alipe. AOP by Union Pay.
05:00A by OKX. And finally, agent pay for machines by Mastercard. You can see this is really becoming a heated battleground and for the future of the agent e-commerce. And it's really hard to sort of keep track of all the standards uh and all the technologies we're trying to but I would say for crypto world uh actually asked all the speakers not to use uh sloppy AI generated images in presentations but I couldn't resist myself here.
05:34Um I think for crypto world like the agent commerce has been like super exciting news like because finally there is like really
Why crypto fits agentic payments, disputes included
05:42solid use case for crypto except for like tra trading and gambling buying illegal substances uh on marketplaces and hiding money away from your spouses. Right. So finally a commerce really brings a like long sought like use case for crypto that that I actually think is is pretty solid and I'm not like a crypto bro myself.
06:00I I'm not hodling anything actually. I was fairly skeptical to crypto all the time but I feel that crypto is really well suited for agentic commerce or agentic uh payments. Why? Because the traditional payment methods uh designed for people are super expensive and you know uh like credit cards, PayPal or you know a bank debit they cannot be used for microtransactions they are just very ineffective uh as we saw in the previous presentation as well.
06:23So, but there's another problem. There are buyer disputes. Like anybody who's selling things online, you know that uh there are some people who sort of like buy services from your website and then dispute the payment and ask for refund, you know, or or dispute it through their bank and you have to pay for that.
06:40Like in like traditional like well human economy there is some trust signals you can you can do with the credit cards you know uh like Stripe and and others have different services to prevent fraud and so on. But in agentic interaction like you really have no idea who the agent is like there's no agent identity.
06:56I mean there are some standards being developed but it's really not clear uh who are you transacting with. So you just can't allow them to dispute the payments. You really it needs to be one way transaction and it needs to be like safe for you right.
07:13So I think uh crypto is is a superp position for that. But also there's important part uh crypto if done well it's like truly decentralized blockchain where where no company has like majority of of you know of of the vote in the network it can be really decentralized and it can be like a public standard you know not owned by a single company who for example like Visa or Mastercard sort of would abuse their dominant power you know to to extract fees from the from the from from the system.
07:44So I I'm I'm very very bullish on crypto in this in this space and there are basically like currently two largest uh crypto payment uh providers for payments. One is X42 from from Coinbase and second was MPPP machine payments protocol from Stripe.
07:58Looking at the stats uh just yesterday uh X42 is like 20 times larger in the number of transactions and the the volume. Uh so obviously we went first with implementation of X42 but we added MPPP in the process as well and today I'm going to share like a bit of our experience.
08:14This was also presented in the slide before uh X42 built on the status code introduced like more like almost 30 years ago in the original HTTP
A 30 year old status code finally picked up
08:29specification like called 402 payment required. So this status code was waiting for 30 years patiently for someone to pick it up and obviously Coinbase took that opportunity because obviously it's great for marketing. you know we're finally make uh internet money work.
08:37It's awesome. So how it works? I'll just go quickly because we saw it in the last presentation as well. So first the client initiates like calls server with some API request. The server responds and actually this is important part specification and forces the server to respond 402 payment required.
08:56There is no other way to do that. It it needs to use the 402. Then you know the client creates a signature uh by basically withdrawing money from the wallet uh or you know allocating the budget from from the wallet sends the signature to the to the server.
09:09Oh the server verifies with the facilitator which can be like Coinbase for example whether the transaction is correct. It gets confirmation that the transaction is is right and then it's
The x402 flow, and the double spending window
09:24supposed to do the work right but there is a problem there. I'll get to that uh in a second. And after the work is done uh you send a transaction you send request to the facilitator to settle which means like you know physically transfer the money to to your own wallet and then facilitator performs the operation on the blockchain transaction is confirmed everything is settled all good.
09:41But there is a problem here in this moment like until until the transaction is is actually submitted to the blockchain the buyer can use the same wallet and same money to other transaction. And basically there is like nothing preventing uh the client from double spending.
09:57So you know uh it can just create like 1,000 signatures like that send like to 10,000 requests and then you know like um maybe it will not get the results but let's say if it's like a simple API call you know where there's like a like zero marginal cost for you as a provider you can do it you can do the work you know before uh you settle but imagine there is like some notable work or maybe you have to pay external service and then you realize oh the money is gone right uh the the the client skipped out on the bill which is not great.
10:30So there is a work around that. You can actually uh just do the work after the transaction is settled. You just need to make sure you actually get the work done didn't fail and so on because then the clients would be pretty angry I guess. But there is a workound for this and then you send like 200 okay and payment response all good.
10:49So there is a problem though like um as I showed before like uh the standard requires HTTP 402 uh as a first response from the server but MCP plus requires HTTP 401 so there are like two conflicts in standards and you know each of them
When x402 wants a 402 and MCP wants a 401
11:12are actually enforcing it and you cannot like sort of like you know return two error codes or two status codes at the same time. So how do companies resolve that? Well, quite often they create a dedicated like host name host uh like let's say x42.alami.com to serve just the agentic payments gateway.
11:28So they implement basically a new API host just to serve uh the the agentic payments and then they have like mcp.appifi sorry mcp.alchemy.com and maybe mpp. Alchemy.com right? But it sounds like antipattern. Why would you have to duplicate like your uh API host for different payment provider?
11:44It's like imagine like you had like Amazon.com for different like credit cards. You have like 20 different Amazons. Like doesn't make sense, right? So, so I think this is like one of the weaknesses. It's like I I understand like using HTTP 402 is great for marketing, but I think there should be in protocol some way to circumvent that and use use just purely headers, you know.
12:04So, for example, the payment payment required header without the the the status code. And then uh originally when X42 was created, it was designed for uh like fixed payments. Uh the the first payment scheme they introduced was uh called exact and it's like for simple API calls like there's like a fixed fee per transaction, fixed fee per per call, which is great for I don't know simple APIs.
12:30But unfortunately, Appify actors are tools on the marketplace. They typically perform bad jobs and you know they can run for you know a few seconds but they can also run for a few hours and consume a lot of resources on the way. They are like typically like built uh as you go kind of like meter billing.
12:52So how to do that like how to put this on X42. So in May 2025 uh Coinbase introduced X42 with exact payment
Exact, then "up to", and what it still did not fix
12:59scheme. In December 2025, uh they uh announced the version two of the protocol which was promising the up to payments payment scheme to kind of fix this problem of like meter billing. But it it took actually uh another like half a year almost uh to uh release the the up to finally it was just like two or three months ago.
13:15So we were super excited about that. We were like finally uh we can make this work uh for our services. But then we realized actually the same double spending problem is on on exact is also with with up to I mean up to it was just just a small sort of like improvement to the protocol where when you you know call the tool you say oh my maximum is $5 and then the the the server can charge anything up to $5 but it doesn't prevent the double spending problem.
13:37So basically we are sort of stuck again. So you know we had to go back to the drawing boards and figure like how to do that. And so one way we we did it was we just use exact payment scheme. So kind of like fixed like charge the fixed payment
Charging in full, refunding the rest, and batch settlement
14:00and then after the the the job is done we we would like refund the the the wallet with the with the leftover money basically the money that u that wasn't spent. I mean that worked but uh so you charge you do the work you refund the remainder but that means like there's suddenly like two blockchain transactions that means like uh there's a time you know to to set those transactions there might be like some fees associated with that and so on and
14:26also the clients really need to trust the server to kind of like hey I give you the money then you give it to me back right but I think that that that's that's milder issue but it just feels somehow clunky like why would we need to do these workarounds you know this protocol should support these things out of the box.
14:40So just two months ago um Coinbase introduced like new payment scheme uh which is called batch settlement which looks very promising. We haven't implemented it yet so we'll report soon on that but basically just quickly it works like so first the clients like deposit some money.
14:48So basically it's actually like like real transactional blockchain using some uh Ethereum virtual machine black magic. Basically the money is put into the escrow and then the the client gets back a voucher like from the server say hey here is some cryptographic voucher and you can use it to sign like microtransaction as part of this batch and then like the client sends request for example like API calls or you know for like individual tokens whatever and uses like passes this voucher to uh sign
15:26those like microp payments but these transactions are basically offchain they are just like sort of like crypto cryptographically guaranteed locally but you don't need to like write these like to the to the to the blockchain which again is inefficient slow you know uh expensive and then at some point you're like hey I I accumulated a lot of these like microtransactions so I just like settle them in batch and then like you basically perform the transaction on blockchain and then you can do this a
15:50couple of times and eventually refund the rest of the money uh like sort of like release the escrow right so actually this looks really cool very exciting we'll um we're currently working on implementing it now. So we'll see. But uh so how did we resolve like all this to make it work, right?
15:58So we didn't really want to create like new new endpoints uh for different payment services. Uh we didn't want to like the like hack the variable usage, you know, to our services and also we really don't want to like tweak too much our API because we have like tens of thousands of customers depending on that API.
16:14So we just can't like sort of like you know uh do whatever like new uh agentic payment standard is out there just implemented right away. So to kind of to fix these problems uh let me introduce you uh let me introduce our newest uh service on aifi which is called
AGI, an agent general interface
16:38agi.appify.com ify.com and AGI uh is not uh what you mean it is it's actually it stands for agent general interface. So instead of like application programming interface we have agent general interface that can change any time because it's used by agents so they're flexible right and on AGI it's just a simple website with like one markdown document.
16:53It's not designed for people so it kind of looks ugly but it's okay. And there's instructions for agents like hey how can you actually buy things on aify yourself through x42 mpp we can iterate quickly on this on this on this website or on this service because you know agents can pick up new version uh it's not like fixed like API that that needs to be basically you know backwards compatible all the time and the way it works is like the agent comes to api.com gets basically can buy a prepaid token token.
17:31So basically they say like hey here's $5 give me give me a token we give them like aify token back and then they can use the token uh through our normal API or through MCP to uh run our jobs and services you know uh normally and it it works pretty well uh there is like no skill required you just like point your agent to agify.com it picks it up and uh I have here like a short demo uh we're running out of time so this is just like example how it works like Actually the explorer ecosystem is like really early so that even you know
18:07uh we had to build our own like local wallet uh tool which you can like create like local like cryptographic key to charge you know with money and show QR code like I mean these things are still not not existing I mean the ecosystem is like super super early.
18:15So I have local wallet with $10 then I call like agiify.com uh allocate like token with $1. I get back uh 402 payment required. So there's like this like super long like payment required signature. Uh I use aifi u I I use our MCPc which is like MCPC client to sign uh the payment and then I can send the oh oh this demo didn't work as expected.
18:50Uh here we go. Well, anyway, uh I have one minute left. Demo will come later. Sorry about that. So to conclude my presentation like really like try it out and like try to build try try to use it like actually I tried tried to use it for the first time like a couple of weeks ago because I always thought oh my god it's somehow complicated you know there is a lot of this like weird crypto lingo you know like like I don't know what it what it means but actually it's really really
Where the volume actually is today
19:29simple to to play with that you can you know get get up and running in like 10 minutes and u it's still super early uh I think there's like $1 million transaction volume like per month like this is nothing right like the econom is much much bigger but I think it will soon ramp up and I think once uh really this like era of like uh token subsidies will end I mean when the when you really will have to pay for the tokens you know that your agents consume I think suddenly this decision whether to build or buy will you know make more economic
20:00sense actually to buy external you know services for a lot of things rather than build from scratch and I think at this time really the agentic payments will explode and u very soon uh uh the H&T commerce might overtake the normal commerce.
20:07Thanks a lot for your attention and please come uh to join us uh in our booth and actually I have another talk coming up in two hours uh about MCP and CLI. So can check that one as well in expo stage two. Thank you.