> ## Content Index
> Fetch the complete content index at: https://stablecoininsider.org/llms.txt
> Use this file to discover other available public pages before exploring further.

# How to Process DFNS x402 Agent Payments (2026)
- URL: https://stablecoininsider.org/how-to-process-x402-agent-payments-with-dfns/
- Published: 2026-10-03T12:00:00.000Z
- Updated: 2026-10-03T12:14:00.000Z
- Description: Wire DFNS payer and merchant wallets for gasless USDC x402: EIP-712 sign, receiveWithAuthorization settle, and policy caps before every authorization.
- Author: Alexandra
- Tags: AI, Stablecoins

AI agents that hit paywalled HTTP APIs need a way to authorize gasless USDC pulls without holding native gas or exposing private keys.

The named object is **DFNS x402 agent payments**: payer wallets that sign ERC-3009 **ReceiveWithAuthorization** via EIP-712, and merchant wallets that broadcast settlement and pay gas. Wire it with **wallets.generateSignature** (**kind: 'Eip712'**) on the customer wallet and **wallets.signAndBroadcastTransaction** on the merchant wallet. That is not PayAI's hosted facilitator URL alone, not Circle's public facilitator alone, not Nevermined plan metering, and not Coinbase AgentKit as a buyer-only client.

📌

Stablecoin Insider's framing: use this guide when the job is wiring DFNS as the signer and merchant settle path for x402 ERC-3009 USDC pulls. Use How to Enable PayAI x402 Facilitator when you want a hosted verify/settle URL. Use How to Enable Circle x402 Facilitator when Circle's facilitator is enough. Use How to Enable Nevermined x402 when you need plans and createDelegation. Use How to Pay for an x402 API with Coinbase AgentKit when your agent only pays someone else's 402.

Facts below come from Dfns' [Process x402 agent payments](https://docs.dfns.co/solutions/process-x402-agent-payments) solution, the [dfns/dfns-solutions](https://github.com/dfns/dfns-solutions) **x402-ai-payments** blueprint, [Automate payments](https://docs.dfns.co/solutions/automate-payments), and [Create transfers](https://docs.dfns.co/guides/developers/create-transfers), as of October 3, 2026\. API shapes, Sepolia chain ID **11155111**, Sepolia USDC **0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238**, selector **0xef55bec6**, reference cap **5\_000\_000n** (5.00 USDC), and permission names are taken from those sources. No invented fee schedules.

### Key Takeaways

- Use two DFNS wallets: payer signs EIP-712; merchant broadcasts receiveWithAuthorization.
- Cap spend with in-process checks plus a DFNS Wallets:Sign policy on the payer wallet.
- Pin USDC verifyingContract, chain ID, and fresh nonces before every generateSignature.
- Merchant pays gas; budget settlement fees separately from the USDC amount.
- Prefer Dfns when you already custody agent keys there; use shared facilitators when you only need verify/settle.

⚠️

Named downside: you operate two DFNS wallets and a settle path. Merchant gas and policy misconfiguration are your ops problems, not a shared facilitator's. If that ops load is higher than the custody benefit, start with a hosted facilitator and revisit DFNS when policy depth matters.

## Who this is for

Use this path if you host AI agents (or agent runtimes) that must pay per API call in USDC, you already use or can adopt DFNS wallets and service accounts, and you want policy-gated EIP-712 signatures without putting gas ETH in every agent wallet.

Skip it if you only need a public facilitator URL with no DFNS custody (see [How to Choose an x402 Facilitator for USDC](https://stablecoininsider.org/how-to-choose-an-x402-facilitator-for-usdc/)), Nevermined plan metering (see [How to Enable Nevermined x402 USDC Payments](https://stablecoininsider.org/how-to-enable-nevermined-x402-usdc-payments/)), or buyer-side AgentKit alone (see [How to Pay for an x402 API with Coinbase AgentKit](https://stablecoininsider.org/how-to-pay-for-an-x402-api-with-coinbase-agentkit/)). For generic accept-side patterns, see [How to Accept x402 USDC Payments from AI Agents](https://stablecoininsider.org/how-to-accept-x402-usdc-payments-from-ai-agents/). For funding agent balances, see [How to Fund an AI Agent Wallet with USDC](https://stablecoininsider.org/how-to-fund-ai-agent-wallet-with-usdc/). Related wallet provisioning: [How to Provision Privy Agent Wallets for USDC](https://stablecoininsider.org/how-to-provision-privy-agent-wallets-for-usdc/).

## What DFNS x402 agent payments do

x402 revives HTTP **402 Payment Required**. The merchant returns a payment requirement (amount, asset, recipient, nonce, validity window). The agent asks a DFNS-backed signer to produce an ERC-3009 authorization. The agent retries with an **X-PAYMENT** header. The merchant verifies the typed data, then settles by calling USDC **receiveWithAuthorization** from its own DFNS wallet.

Dfns documents two roles that share one API client and differ only by **walletId**:

| Role                           | Wallet env                 | Responsibility                                                                                             |
| ------------------------------ | -------------------------- | ---------------------------------------------------------------------------------------------------------- |
| Payer (customer)               | DFNS\_CUSTOMER\_WALLET\_ID | Holds USDC. Signs via wallets.generateSignature with kind: 'Eip712'. Never broadcasts.                     |
| Payee + facilitator (merchant) | DFNS\_MERCHANT\_WALLET\_ID | Verifies signature, broadcasts receiveWithAuthorization via wallets.signAndBroadcastTransaction, pays gas. |

USDC enforces **msg.sender == payee** inside **receiveWithAuthorization**, so a stolen authorization is worthless to anyone except the named merchant address. That is the pull-payment security model Dfns leans on. The reference stack on Sepolia uses **@dfns/sdk**, ethers v6, Circle USDC **FiatTokenV2**, and Node.js v22+, per the [Process x402 agent payments](https://docs.dfns.co/solutions/process-x402-agent-payments) page.

## Prerequisites

You need a DFNS organization and service account with **Wallets:GenerateSignature** on the payer wallet, **Wallets:BroadcastTransaction** on the merchant wallet, and **Wallets:Read** on both (as listed in Dfns docs). Provision two DFNS wallets on the target chain (docs demo: Ethereum Sepolia, chain ID **11155111**). Fund the payer with testnet USDC (Circle faucet on Sepolia) and the merchant with native ETH for gas.

Required env vars include **DFNS\_API\_URL=https://api.dfns.io**, **DFNS\_ORG\_ID**, **DFNS\_AUTH\_TOKEN**, **DFNS\_CRED\_ID**, **DFNS\_PRIVATE\_KEY**, both wallet IDs, **MERCHANT\_ADDRESS** matching the merchant wallet's on-chain address, **USDC\_CONTRACT\_ADDRESS**, and **CHAIN\_ID**.

git clone https://github.com/dfns/dfns-solutions.git
cd dfns-solutions/x402-ai-payments
npm install
cp .env.example .env
# fill env, then:
npm run wallets:list
npm start

## Worked flow: payer signs, merchant settles

### 1\. Agent receives 402 + PaymentRequirement

The merchant responds with amount (USDC base units, 6 decimals), recipient (must equal merchant address for ERC-3009 receive), contract address, chain ID, **validAfter** / **validBefore**, and a fresh 32-byte nonce. Dfns' reference uses **ethers.randomBytes(32)** for the nonce.

### 2\. Signer enforces policy, then EIP-712 signs

Dfns' sample caps each payment at **5.00 USDC** (**MAX\_PAYMENT\_AMOUNT = 5\_000\_000n**) before calling the API, per the [Process x402 agent payments](https://docs.dfns.co/solutions/process-x402-agent-payments) docs. Production should also check recipient allowlists, asset allowlists, and a time-windowed spend budget.

Then call **wallets.generateSignature** with **kind: 'Eip712'**, types for **ReceiveWithAuthorization** (**from**, **to**, **value**, **validAfter**, **validBefore**, **nonce**), domain **{ name: 'USDC', version: '2', chainId, verifyingContract }**, and the message fields. Poll **wallets.getSignature** until status is **Signed** (or fail on **Failed** / **Rejected**).

💡

Stablecoin Insider's take: treat the in-process cap as a fast UX gate and the DFNS Wallets:Sign policy as the non-bypassable safety net. If the signer process is compromised, only the DFNS-side policy still holds.

### 3\. Agent retries with X-PAYMENT

The agent attaches the ERC-3009 signature (and message) in the **X-PAYMENT** header and retries the original request.

### 4\. Merchant verifies and broadcasts settlement

Verify with **ethers.verifyTypedData**. Encode **receiveWithAuthorization** using selector **0xef55bec6**, pack **(from, to, value, validAfter, validBefore, nonce, v, r, s)**, and call **wallets.signAndBroadcastTransaction** with **kind: 'Eip1559'**, **to** \= USDC contract, **value: '0'**, and explicit gas fields (docs sample: **gasLimit: '200000'**, **maxFeePerGas: '5000000000'**, **maxPriorityFeePerGas: '1000000000'**). Return the **txHash** to the agent with HTTP 200.

## Worked numbers (Sepolia demo)

| Field                       | Example from Dfns docs                     |
| --------------------------- | ------------------------------------------ |
| Chain ID                    | 11155111 (Ethereum Sepolia)                |
| Sepolia USDC                | 0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238 |
| Per-payment cap (reference) | 5\_000\_000 base units = 5.00 USDC         |
| Function selector           | 0xef55bec6 (receiveWithAuthorization)      |
| Sample gasLimit             | 200000                                     |
| Sample maxFeePerGas         | 5000000000 wei                             |
| Sample maxPriorityFeePerGas | 1000000000 wei                             |

Paste the returned hash into [sepolia.etherscan.io](https://sepolia.etherscan.io) to confirm settlement, as the docs instruct.

## Policy bounds table (operator checklist)

Dfns' [Automate payments](https://docs.dfns.co/solutions/automate-payments) solution shows velocity and approval patterns you can mirror for agent payers. Combine those ideas with the x402 signer checks:

| Control                | Where it runs                         | Suggested starting bound                                                                                                 | Action on breach          |
| ---------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ------------------------- |
| Per-payment USDC cap   | Signer process + DFNS Wallets:Sign    | 5.00 USDC (docs sample) or tighter                                                                                       | Reject signature          |
| Recipient allowlist    | Signer + DFNS policy                  | Only known merchant addresses                                                                                            | Reject                    |
| Verifying-contract pin | Signer                                | Only known USDC contract per chain                                                                                       | Reject                    |
| Unique nonce           | Merchant + signer                     | Refuse duplicate nonce on same payer                                                                                     | Reject / regenerate 402   |
| Daily velocity         | DFNS policy (automate-payments style) | Org-specific (docs example: $100k/day block for treasury)                                                                | Block                     |
| Large-ticket approval  | DFNS policy                           | Docs example: >$10k require 1-of-2 for standard payroll; agent micropayments usually stay auto under the per-payment cap | Require approval          |
| Merchant gas budget    | Ops monitoring                        | Explicit ETH top-up alerts                                                                                               | Pause settle until funded |

Do not copy treasury dollar caps blindly onto agent micropayments. Use the automate-payments examples as policy shapes, then set micro amounts that match your API price list. For outbound transfer status semantics (**Pending**, **Executing**, **Broadcasted**, **Confirmed**, **Failed**, **Rejected**), see [Create transfers](https://docs.dfns.co/guides/developers/create-transfers).

## Design rules that keep pulls safe

**Enforce policy before signing.** A signed authorization is irrevocable until **validBefore**. Validate amount, recipient, asset, and chain first.

**Layer DFNS policy.** In-process checks are fast; DFNS **Wallets:Sign** on the customer wallet cannot be bypassed if the signer host is owned.

**Unique nonces.** Merchants must mint a fresh nonce per 402\. Signers should refuse to sign the same nonce twice.

**Pin verifyingContract.** EIP-712 binds the signature to the USDC contract. Refuse unknown contracts so a malicious 402 cannot redirect the authorization.

**Treat gas as COGS.** The merchant pays gas every settle. Budget and monitor it; consider folding gas into API pricing the way card networks pass interchange.

## Comparison: Dfns vs PayAI vs Circle vs Nevermined

| Dimension   | DFNS x402 (this guide)                      | PayAI facilitator                              | Circle x402 facilitator           | Nevermined x402                     |
| ----------- | ------------------------------------------- | ---------------------------------------------- | --------------------------------- | ----------------------------------- |
| Primary job | Custody + EIP-712 sign + merchant broadcast | Hosted verify/settle                           | Hosted Circle facilitator URL     | Plans, credits, createDelegation    |
| Agent gas   | Gasless for payer (USDC only)               | Facilitator settles; buyer still signs payment | Facilitator path                  | ERC-4337 / plan path                |
| Policy      | DFNS Wallets:Sign + in-process              | PayAI free credits / API keys                  | Circle facilitator rules          | Nevermined plan caps                |
| Best when   | You already run DFNS wallets for agents     | You want Express middleware + multi-chain host | You standardize on Circle's stack | You sell metered agent access plans |

Deep dives: [How to Enable PayAI x402 Facilitator for USDC](https://stablecoininsider.org/how-to-enable-payai-x402-facilitator-for-usdc/), [How to Enable Circle x402 Facilitator for USDC](https://stablecoininsider.org/how-to-enable-circle-x402-facilitator-for-usdc/), [How to Enable Nevermined x402 USDC Payments](https://stablecoininsider.org/how-to-enable-nevermined-x402-usdc-payments/), [How to Pay for an x402 API with Coinbase AgentKit](https://stablecoininsider.org/how-to-pay-for-an-x402-api-with-coinbase-agentkit/). Related: [How to Authenticate Alchemy APIs with x402 USDC](https://stablecoininsider.org/how-to-authenticate-alchemy-apis-with-x402-usdc/), [How to Charge for MCP Tools with Cloudflare Agents x402](https://stablecoininsider.org/how-to-charge-for-mcp-tools-with-cloudflare-agents-x402/).

## When Dfns fits (and when it does not)

**Fit:** platforms that already custody agent keys in DFNS, need per-agent spend policies server-side, want gasless USDC pays for agents, and can run a merchant settle service that holds ETH for gas.

**Poor fit:** teams that only want a drop-in facilitator URL with no wallet custody change; product surfaces that need Nevermined-style plans; buyers who only need AgentKit against someone else's merchant.

## Stablecoin Insider's take

💬

Stablecoin Insider's take: DFNS x402 is the right default when agent keys already live in DFNS and you need irrevocable policy before every EIP-712 authorization. Shared facilitators win on time-to-first-settle. Do not pretend they solve the same problem. Pick custody-plus-policy or hosted verify/settle on purpose, then document which wallet pays gas.

[Compare x402 facilitators](https://stablecoininsider.org/how-to-choose-an-x402-facilitator-for-usdc/)

---

## FAQ

#### What is DFNS x402 agent payments?

It is Dfns' two-wallet pattern for x402: the payer wallet signs ERC-3009 `ReceiveWithAuthorization` with EIP-712, and the merchant wallet broadcasts settlement and pays gas. See the [Process x402 agent payments](https://docs.dfns.co/solutions/process-x402-agent-payments) docs.

#### Does the agent need ETH for gas?

No for the payer path in the docs. The agent (payer) holds USDC; the merchant DFNS wallet pays native gas on settle.

#### Which API calls are required?

At minimum `wallets.generateSignature` (`kind: 'Eip712'`) on the payer wallet and `wallets.signAndBroadcastTransaction` on the merchant wallet, plus read permissions on both.

#### What chain does the reference use?

Ethereum Sepolia, chain ID `11155111`, with Sepolia USDC at `0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238`, per Dfns docs.

#### How do I stop an agent from overspending?

Enforce an in-process per-payment cap (docs sample 5.00 USDC) and attach a DFNS `Wallets:Sign` policy so compromised signer code cannot bypass limits.

#### Can I reuse a PaymentRequirement nonce?

No. ERC-3009 uses the nonce for replay protection. Merchants should generate a fresh random nonce per 402; signers should refuse duplicates.

#### How is this different from PayAI or Circle facilitators?

Those are primarily hosted verify/settle services. DFNS x402 centers on custodial wallets you control for signing and broadcasting, with DFNS policies on spend. See [PayAI](https://stablecoininsider.org/how-to-enable-payai-x402-facilitator-for-usdc/) and [Circle](https://stablecoininsider.org/how-to-enable-circle-x402-facilitator-for-usdc/) how-tos for the hosted path.

#### Where is the sample code?

In [github.com/dfns/dfns-solutions](https://github.com/dfns/dfns-solutions) under `x402-ai-payments`, linked from the Process x402 agent payments docs.

---

**Need the facilitator shortlist before you commit to DFNS custody?** Start with Stablecoin Insider's x402 facilitator comparison, then come back to this DFNS wire-up.

[Choose an x402 facilitator ](https://stablecoininsider.org/how-to-choose-an-x402-facilitator-for-usdc/) 

[How to Enable PayAI x402 Facilitator for USDC (2026)Wire PayAI's hosted x402 verify/settle facilitator for USDC agent and API payments.![](https://stablecoininsider.org/favicon.ico)Stablecoin Insider](https://stablecoininsider.org/how-to-enable-payai-x402-facilitator-for-usdc/)

This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice; no material herein should be interpreted as a recommendation, endorsement, or solicitation to buy or sell.