Spend governance for autonomous AI agents

Know — and control — what your AI agents pay

When agents pay for things on their own, finance needs a record and ops needs a brake. 402.report gives you live spend visibility, a payment firewall and one-click kill-switch, and audit-ready records across every payment your agents make — non-custodial, so we watch the money, never hold it.

Free while in beta — no card needed.

402.report / dashboard

Total paid

$16.46

Payments

1,509

Paywalls hit

139

USDC paid paywalls hit

Live traffic

MastraVercel AI SDKLangChainOpenAI SDKClaudeVisual Studio CodeCursor

Hello, agent

  • x402
  • HTTP 402
  • Solana
  • USDC
  • MCP
  • any HTTP agent

Built for the agent economy

402 Payment Required

Every payment your agents make, in one ledger

A wallet shows a flat list of transfers. 402.report turns it into a ledger for autonomous spend: how much each agent paid, to which domains, and how many x402 paywalls it hit — normalized to USD and live, updated as your fleet runs.

  • Spend over time, per agent and per domain — normalized to USD
  • Paywalls hit vs. payments made — context a wallet can't give you
  • One view for a whole fleet of autonomous agents

Total requests 1,648

Failure rate 2.1%

Recent requests

StatusMethodPathAmount
200GETapi.firecrawl.dev/scrape$0.0031
402GETapi.exa.ai/search
200GETapi.exa.ai/search$0.0050
200GETdata.coingecko.com/v3/coins/markets$0.0010
502POSTpremium.newsapi.org/v2/everything$0.0104
200GETapi.serpapi.com/search$0.0104

By domain

DomainTotal paidPaymentsPaywalls hit
api.serpapi.com$5.8858841
api.exa.ai$2.0140228
api.firecrawl.dev$1.7658633
data.coingecko.com$0.2626412

research-agent

active 1 min ago

Overview

Total paid
$4.19
Payments
402
Failure rate
2.1%

Top domains

  • api.firecrawl.dev46%
  • api.exa.ai27%
  • data.coingecko.com14%

Top errors

  • 402paid_but_origin_402×7
  • upstream_timeout×3

Paid, but failed

The payment went through. The request didn't.

When an agent pays but the origin still returns 402 — wrong amount, a facilitator that didn't confirm in time, an edge that dropped the retry — the seller just sees "payment failed." You get the full timeline: the challenge, the on-chain payment, and exactly where it broke.

402.report / attempt
paid_failedGET api.premium-data.com/v2/quotes

Your agent paid the challenge, but the origin returned 402 again — you were charged and got nothing. The seller's side just says "payment failed"; this is the timeline they never show you.

  1. 402 challenge14:22:08
    HTTP 402 · 176 ms
  2. Paid retry14:22:09
    HTTP 402 · 968 ms · paid, but origin still 402

Payment proof

Amount
$0.0100 USDC
Network
solana-mainnet
Signature
5Np2eV8kQ1r7xW3hUadFbZ9mCsT4gLpYnJ6vRkD2Aoe

A real failed attempt — paid, but the origin still returned 402.

Alert fired

Know the moment your agents' spend goes wrong

The instant payments start failing, spend crosses a threshold, or a quiet loop turns into a spike, 402.report tells you — long before you'd notice in a dashboard. Delivered to Slack, Discord, email, or your own webhook.

The first I hear about a payment problem shouldn't be the monthly bill.

— every team running agents that pay

Email
From402.report alerts
Subject🔔 Payment failures — 402.report

12 failed payments in the last 30m (threshold 5).

View in dashboard

402.report · non-custodial x402 spend alerts

The same alert, delivered wherever your team already is.

Triggers on: Payment failures · Spend threshold · Spend spike

MCP online

Give your agent a memory of what it spent

An agent's context scrolls away; its spend history shouldn't. 402.report ships a Model Context Protocol server so your agent can ask, mid-task, "how much have I paid this month?" or "which of my payments failed?" — no dashboard, no human in the loop.

And before it pays, your agent can ask whether a URL or wallet is safe — the same threat intel the firewall enforces, one tool call away. Allow, caution, or block.

Point any MCP client at 402.report.

{
  "mcpServers": {
    "402report": {
      "type": "http",
      "url": "https://proxy.402.report/mcp",
      "headers": { "Authorization": "Bearer ag_your_key" }
    }
  }
}
▸ get_spend_by_domain({"from":"2026-06-01"})
{
  "domains": [
    {
      "domain": "api.premium-data.com",
      "paidAmount": 6.42,
      "paidCount": 588
    },
    {
      "domain": "search.agentgrid.io",
      "paidAmount": 4.19,
      "paidCount": 402
    }
  ]
}
▸ check_endpoint({"url":"claim-rewards.app"})
block
{
  "verdict": "block",
  "category": "phishing",
  "confidence": 0.9,
  "reason": "claim-rewards.app is flagged: phishing"
}

403 Forbidden

A firewall for what your agents pay

Before a payment settles, 402.report screens the destination and the payee wallet against live threat intel — sanctioned wallets, known scam and drainer addresses, phishing and malware domains. Watch in monitor mode, or switch to enforce and block. Your own allow / block rules always win.

Threat intelOFAC sanctionsScamSnifferabuse.ch URLhaus

The response you paid for is where injections hide

Paid content is the highest-trust, least-inspected data your agent ingests. 402.report scans every paywalled response for prompt-injection, invisible-unicode instructions, and data-exfil links — with an optional Prompt Guard 2 ML classifier on top.

402.report / firewall
Agent firewall
MonitorEnforce
  • Payee9Wz…DY8oOFAC
    Sanctioned wallet · OFAC SDN list
    blocked
  • Destinationclaim-rewards.app
    Phishing · ScamSniffer · 0.90
    blocked
  • Contentapi.premium-data.com/v2
    Prompt injection · Prompt Guard 2 · 0.94
    flagged
  • Payeemerchant.sol
    Cleared by your rule · allow rule
    allowed
Screened before your agent pays — 2 blocked, 1 flagged.

Every payment, screened before it settles.

Kill switch

One link pauses every agent. Instantly.

When something goes wrong at 3am, you don't want to be hunting through a dashboard. One kill link stops every agent under your account from spending — no login required.

  • Fail-safe by design — the link can only pause spending, never start it.
  • Reachable from anywhere: a curl, a Notion button, a webhook, the dashboard.
  • Resuming takes an authenticated action, so a leaked link can only ever help.

All agents paused

Every agent under this account stopped spending. They stay paused until you resume from the dashboard.

402.report/kill?t=•••••••••

Audit trail

Every agent payment, ready for your books

402.report already observes every field an audit needs — date, counterparty, amount, the on-chain transaction as proof, the paying wallet, the agent. Export it as a clean CSV your accountant can reconcile, with a block-explorer link on every settled payment.

The record and the proof — not tax advice. Drop the CSV straight into your crypto-accounting software.

402.report / records
DateCounterpartyUSDProof
2026-07-14
api.premium-data.com
Solana
$0.01005Np2…Aoe
2026-07-14
search.agentgrid.io
Solana
$0.00258kQ1…rW3
2026-07-13
maps.geo-api.io
Base
$0.05000x9f…c2d

142 payments · $12.47 this month

Download CSV

Export-ready records — one click to CSV.

200 OK

Live in one line of config

Your agent

402

402.report proxy

Paid API

  • Request
  • 402 challenge
  • Paid retry
  • 200 OK
Change one URL
// point your agent's HTTP client at 402.report
const res = await fetch(
  "https://proxy.402.report/https://api.example.com/data",
  { headers: { "x-402report-key": "ag_your_key" } }
);
1

Point your agent at the proxy

Swap your HTTP client's base URL to 402.report and add your API key. No SDK, no changes to your agent's logic.

2

It observes x402, never settles

402.report watches the 402 challenges your agents hit and the payments they make themselves. It never builds, signs, or holds a transaction.

3

See, control, and prove

Spend visibility and payment forensics in the dashboard, guardrails that can block or pause spend, and audit-ready exports — queryable from your agent over MCP, with alerts when something breaks.

Whose side we are on

Cloudflare charges the agents. We give the buyer control.

The sell-side is crowded — Cloudflare, AWS, and others let publishers put x402 paywalls in front of millions of sites, each with a dashboard for the seller. That leaves the team running the agents — the side that actually pays — with no ledger, no controls, and no record. 402.report is the independent governance layer for that side of the transaction.

Sell-side gateways

  • Charge agents at the edge
  • Settle to the seller's wallet
  • Give the seller a dashboard

402.report

  • See every payment, live
  • Control it — firewall, kill switch, alerts
  • Prove it — audit-ready, non-custodial

GDPR

Your data is kept safe

402.report is built privacy-first and non-custodial. No compliance badges to download — just how it actually works.

  • GDPR-first
  • EU data residency (Ireland · Frankfurt)
  • Data export & deletion
  • No ad tracking

Hosted in the EU

Your data is stored in the EU (Ireland & Frankfurt). Nothing leaves the EEA except where a payment provider requires it.

Non-custodial by design

We never hold, move, or touch your funds. Your agents pay from their own wallets — we only observe.

Your data, your control

Download a full copy or permanently delete your account and all its data, anytime, from your settings.

Never sold, no ad tracking

We never sell your data and run no advertising trackers. Analytics are opt-in and anonymous.

Payment not required

Free while we're in beta.

Use the full product free while we grow — no card required. Paid plans for teams and longer retention arrive later.

Free

$0

Everything, free during beta

  • Live spend dashboard + Explorer
  • 90-day forensics + attempt timelines
  • Payment firewall + kill switch
  • Alerts: webhook, Slack & Discord
  • MCP tools + CSV audit export
Start free
Coming soon

Pro

Later

For teams running agents in production

  • Longer forensics retention
  • Firewall enforce + ML content scan
  • More agents & alert rules
  • Everything in Free
Coming soon
Coming soon

Business

Later

For finance & ops at scale

  • 1-year retention + export
  • Unlimited alert rules
  • SSO & priority support
  • Everything in Pro
Coming soon

FAQ

Questions, answered

x402 is an open protocol built on the long-reserved HTTP 402 "Payment Required" status code. A server responds with 402 and a price; the client pays on-chain (typically USDC on Solana) and retries with proof of payment. It's how websites and APIs charge autonomous AI agents per request.

When AI agents pay for data, APIs, and services on their own, spend scatters across thousands of tiny transactions with no ledger and no controls. Agent spend governance is the layer that gives the people accountable for it — finance, ops, and the engineers running the agents — live visibility into every payment, guardrails to block or pause spend, and an audit trail to reconcile it. That is what 402.report does, non-custodially.

No. 402.report is strictly non-custodial. It observes the 402 challenges your agents hit and the payments they make from their own wallets — it never builds, signs, broadcasts, or holds a transaction.

Yes. 402.report sits on the buyer's side, so it works with any x402 paywall your agents encounter — including the ones Cloudflare's Monetization Gateway and AWS put in front of sites.

Today, x402 payments across Solana and EVM chains, valued in USD. As the standard spreads to more chains and new agent-payment rails emerge, 402.report's coverage follows.

Model Context Protocol lets an agent call 402.report's tools in-loop — recalling its own spend, or debugging a failed payment — without a dashboard or a human. It turns the data into durable memory the agent can query mid-task.

Point your HTTP client's base URL at the proxy and add your API key — no SDK and no changes to your agent's logic. It starts recording x402 activity immediately.

Yes — that's the agent firewall. It screens every destination and payee wallet against live threat intel (sanctioned wallets, scam and drainer addresses, phishing and malware domains) and scans paid responses for prompt injection. Run it in monitor mode to record and alert, or enforce mode to actually block. It stays non-custodial: blocking a payment just means the request never leaves — 402.report never touches your funds.

A single link that pauses every agent under your account from spending — reachable from anywhere, no login required, so you can stop a runaway loop in seconds. It's fail-safe: the link can only ever pause, never spend, and resuming takes an authenticated action in the dashboard.

201 Created

Put your agents' spending under control

Free while we're in beta — no card, no setup. Create an API key, point your agents at 402.report, and see, control, and prove every payment they make.

Free while in beta — no card needed.