x402 isn’t good (yet) — Jan Curn, Apify

AI Engineer · 20 min · 245 sentences · from YouTube's caption track

Each timecode opens YouTube at the start of that sentence. Line anchors (#s42) are the cue ids in the WebVTT, and every line carries its start and end seconds. All transcripts has every talk, and the whole corpus as one file.

  1. 00:01[music]
  2. 00:12Hello everyone.
  3. 00:14Uh last year here at AI Engineer World Fair, uh David Cramer from Sentry had a mildly provocative talk called MCP isn't good yet.
  4. 00:21And back then, MCP was the new kid on the block, right?
  5. 00:25Uh it was like a lot of hype around it.
  6. 00:26People were, you know, were excited about it.
  7. 00:28But also like it wasn't really developed back then very much and it was very clunky.
  8. 00:32And in this talk, David argued, "Hey, like this technology is cool, but it has like a lot of rough edges, right?
  9. 00:38So just you know, go play with it, but you know, have your expectations low, right?"
  10. 00:42By the way, they went on and actually built one of the best MCP servers on the market, right?
  11. 00:46Like Sentry MCP is is is really like very well-designed server, like nice nice design and so on.
  12. 00:52And actually over the the last year, uh MCP became like a standard that's actually widely adopted, you know, across the industry.
  13. 00:58Like the top AI engines like Claude and ChatGPT, actually uh Claude offers MCP connectors, right?
  14. 01:04So you can plug tools into your AI agents.
  15. 01:07Uh uh ChatGPT calls it MC calls it apps, but you can also like, you know, directory of different services you can plug into your Claude.
  16. 01:14And it actually became a standard thing for agent-to-agent interaction, right?
  17. 01:19And uh uh despite a little little hate also about MCP, you know, I have yet to see CI connectors in any of these agents, right?
  18. 01:27So MCP won.
  19. 01:29And so, inspired by David's talk, uh today uh I have a similar talk uh which is called X 402 isn't good yet.
  20. 01:38And in that talk, I would like to argue, you know, that uh while X 402 is very exciting technology, it has also still some rough edges, you know.
  21. 01:44And perhaps if I do it as well, we'll also build one of the best integrations with our X 402 on the market like Sentry did with MCP.
  22. 01:53My name is Jan Černý.
  23. 01:54I'm the founder and CEO of Apify.
  24. 01:56And uh for those who don't know, Apify is the largest marketplace of tools for AI.
  25. 02:01Uh we have about 45,000 of these tools.
  26. 02:04Uh we call them actors.
  27. 02:06And they are spending use cases like, you know, extraction of data from social media sites, e-commerce, hospitality, travel, search engines, maps, but over time also like AI agents or agentic use cases, you know, different automations and so on, right?
  28. 02:21And some of these tools, some of these actors are built by our community, some are built by us, and our community is is making now more than $1 million per month on on payouts
  29. 02:32by selling these tools, right?
  30. 02:33So they build the tools, we sell them to to to users, and you know, we pass the money to them.
  31. 02:38And so it's a thriving marketplace.
  32. 02:40And I guess by now everybody understands like why we are so excited about agentic payments, right?
  33. 02:44Because we really want our tools to be easily accessible to agents, like wherever they are, with whatever protocol is out there.
  34. 02:53Uh just 2 days ago we launched uh together with with Coinbase our our XYO 2 integration.
  35. 02:59Uh I would say the the launch went pretty viral.
  36. 03:02We got like 1 million views.
  37. 03:04Uh and before before this launch, there were about like 2,000 tools available on the on the agentic uh market uh basically on XYO XYO 2. We brought another 20,000
  38. 03:19tools.
  39. 03:19So basically we 10X 10X the size of the of the agentic market uh on XYO XYO 2. So this is very exciting for us and I I we we believe also for the community.
  40. 03:29And actually we're very excited about this topic like long term.
  41. 03:32So actually last year here at AI Engineer World's Fair, I was the only one talking about the agentic commerce and agentic economy in general.
  42. 03:39And really argued that that like in a couple of years, like the most most of the economic economic activity in the world will be done autonomously between agents.
  43. 03:47And actually it looks like uh uh really it picked up.
  44. 03:53Uh I think like now everybody understands that agents, in order to get work done or like longer jobs without human intervention, they will actually need to have budget as well, right?
  45. 04:02It's It's not like you can do a lot of things in this world without without money.
  46. 04:08And once agents, you know, can be trusted with money, they will complete like far longer and, you know, more complex tasks than they can do now.
  47. 04:16So, obviously, a lot of people understand this across the industry.
  48. 04:20So, over the past year or so, we saw a lot of new standards or agentic payments protocol coming to the market because, obviously, every player in finance or or payments is very excited about this opportunity because everybody wants to get a part of this of this like huge future
  49. 04:37agentic economy and and transaction volume.
  50. 04:41So, first was L402.
  51. 04:43It was like in mid 2020.
  52. 04:46But then, MasterCard Agent Pay, we have X242 like Coinbase in my last year, KY Pay from Skyfire with Visa, API 2 by Google, ACP by OpenAI and Stripe, Tab by Visa,
  53. 05:00UCP by Google and Shopify, ACTP by Alipay, MPP by Stripe and Tempol, AMP by Alipay, Apple by UnionPay, APP by OKX, and finally, Agent Pay for Machines by MasterCard.
  54. 05:12You can see this is really becoming a heated battleground and for the future of the agentic commerce.
  55. 05:18And
  56. 05:18[snorts]
  57. 05:20it's really hard to sort of keep track of all the standards and all the technologies.
  58. 05:24We're trying to.
  59. 05:25But, I would say for crypto world, actually, Swix asked all the speakers not to use sloppy AI-generated images in presentations, but I couldn't resist myself here.
  60. 05:35Um I think for crypto world, like the agentic commerce has been like super exciting news like because finally, there is like really solid use case for crypto except for like trading trading and gambling,
  61. 05:46buying illegal substances on marketplaces and hiding money away from your spouses, right?
  62. 05:51So, finally, agentic commerce really brings the like long-sought like use case for crypto that that I actually think is is pretty solid.
  63. 05:59And I'm not like a crypto bro myself.
  64. 06:00I I'm not holding anything.
  65. 06:02Actually, I was fairly skeptical to crypto all the time.
  66. 06:05But I feel that crypto is really well suited for agentic commerce or agentic uh payments.
  67. 06:11Why?
  68. 06:11Because the traditional payment methods uh designed for people are super expensive, right?
  69. 06:17And you know, uh like credit cards, PayPal, or you know, ACH and bank debit, they cannot be used for microtransactions.
  70. 06:24They are just very ineffective uh as we saw in previous presentation as well.
  71. 06:28So, but there's another problem.
  72. 06:31There are buyer disputes.
  73. 06:32Like anybody who's selling things online, you know that uh there are some people who sort of like buy certain services from your website and then dispute the payment and ask for refund, you know, or
  74. 06:43or dispute it through their bank and you have to pay for that.
  75. 06:45Like in like traditional like well, human economy, there are some trust signals you can you you can do with the credit credit cards, you know, uh like Stripe and and others have different services to prevent fraud and so on.
  76. 06:58But in agentic interaction, like you really have no idea who the agent is.
  77. 07:02Like there's no agent identity.
  78. 07:04I mean, there are some standards being developed, but it's really not clear uh who are you transacting with.
  79. 07:09So, you just can't allow them to dispute the payments.
  80. 07:12You really need it it needs to be a one-way transaction and it needs to be like safe for you.
  81. 07:17Right?
  82. 07:17So, I think uh crypto is is is a super position for that.
  83. 07:21But also, there's important part uh crypto, if done well, is like truly decentralized blockchain where where no company has like majority of of, you know, of the of the of the of the vote in the network,
  84. 07:33it can be really decentralized and it can be like a public standard, you know, not owned by a single company who, for example, like Visa or MasterCard, sort of would abuse their dominant power, you know, to to extract fees from the from the from the system.
  85. 07:46So, I am I'm very very bullish on crypto in this in this space and uh there are basically like currently two largest uh crypto payment uh providers for any payments.
  86. 07:57One is XRO2 from from Coinbase and second was in this MPP, machine payments protocol from Stripe.
  87. 08:02Looking at the stats uh just yesterday, uh XRO2 is like 20 times larger in the number of transactions and the the the the volume.
  88. 08:11Uh so, obviously, we went first with implementation of XRO2, but we added in MPP in the process as well.
  89. 08:17And today, I'm going to share like a bit of our experience.
  90. 08:20This was also presented in the slide before.
  91. 08:22Uh XRO2 builds on the uh status code introduced like more like almost 30 years ago in the original HTTP specification uh called 402 payment required.
  92. 08:32So, this status code was waiting for 30 years patiently for someone to pick it up.
  93. 08:36And obviously, Coinbase took that opportunity because obviously, it's great for marketing, you know, we're finally make uh internet money work.
  94. 08:43It's awesome.
  95. 08:44So, how it works?
  96. 08:45I'll just go quickly because we saw it in the last presentation as well.
  97. 08:48So, first, the client initiates like calls server with some API request.
  98. 08:52The server responds and actually, this is important part.
  99. 08:54Specification enforces the server to respond 402 payment required.
  100. 08:58There is no other way to do that.
  101. 08:59It it needs to use the 402.
  102. 09:02Then, you know, the client creates a signature uh by basically withdrawing money from the wallet uh or you know, allocating the budget from from from the wallet.
  103. 09:10Sends uh the signature to the to the server.
  104. 09:13Oh, the server verifies with a facilitator, which can be like Coinbase, for example, whether the transaction is correct.
  105. 09:20It gets uh confirmation that the transaction is is right.
  106. 09:23And then, it's supposed to do the work, right?
  107. 09:26But there is a problem there.
  108. 09:28I'll get to that uh in a second.
  109. 09:30And after the work is done, uh you send a transaction you send a request to the facilitator to settle, which means like, you know, physically transfer the money to to your own wallet.
  110. 09:41And then facilitator performs operation on the blockchain, transaction is confirmed, everything is settled, all good.
  111. 09:47But there is a problem here.
  112. 09:49In this moment, like until until the transaction is is actually submitted to the blockchain, the buyer can use the same wallet and same money to other transaction.
  113. 09:59Basically, there is like nothing preventing the the client from double spending.
  114. 10:03So, you know, uh it can just create like 1,000 signatures like that, send it to 1,000 requests, and then, you know, like um maybe it will not get the result,
  115. 10:14but let's say if it's like a simple API call, you know, where there is like a like zero marginal cost for you as a provider, you can do it.
  116. 10:20You can do the work, you know, before uh you settle.
  117. 10:24But imagine there is like some non-trivial work, or maybe you have to pay external service, and then you realize, "Oh, the money is gone, right?"
  118. 10:31Uh the the the client skipped out on the bill, which is not great.
  119. 10:35So, there is a work around that.
  120. 10:38You can actually uh just do the work after the transaction is settled.
  121. 10:41You just need to make sure you actually get the work done, you don't fail, and so on, because then the clients would be pretty angry, I guess.
  122. 10:48But there is a work around for this, and then you send like 200 OK and payment response, all good.
  123. 10:54So, there is a problem though.
  124. 10:57Like um as I showed before, like uh the standard requires HTTP 402 uh as a first response from the server.
  125. 11:04But MCP Alt requires HTTP 401.
  126. 11:08So, there are like two conflicts in the standards, and you know, each of them are actually enforcing it, and you cannot like sort of like, you know, return two error codes or two status codes at the same time.
  127. 11:19So, how do you companies resolve that?
  128. 11:21Well, quite often they create a dedicated like hostname host uh like let's say x402.alchema.com to serve just the agentic payments gateway.
  129. 11:30So, they implement basically a new API host just to serve the the HTTP payments and then they have like Sorry, mcp.alchemy.com and maybe mpp.alchemy.com, right?
  130. 11:42But it sounds like anti-pattern.
  131. 11:43Why would you have to duplicate like your API host for different payment providers?
  132. 11:49It's like imagine like you had to like amazon.com for different like credit cards.
  133. 11:53You had like 20 different Amazons.
  134. 11:54Like it doesn't make sense, right?
  135. 11:55So So, I think it is like one of the weaknesses.
  136. 11:58It's like I I understand like using HTTP 402 is great for marketing, but I think there should be in protocol some way to circumvent that and use use just purely headers, you know?
  137. 12:07So for example, the payment payment required header without the the the status code.
  138. 12:14And then originally when X-Request-ID was created, it was designed for like fixed payments.
  139. 12:23Uh The the first payment scheme they introduced was called exact and it's like for simple API calls.
  140. 12:30Like there's like a fixed fee per transaction, fixed fee per per call, which is great for I don't know simple APIs.
  141. 12:36But unfortunately, Apify actors are tools on the marketplace.
  142. 12:39They typically perform bad jobs and you know, they can run for, you know, a few seconds, but they can also run for a few hours and consume a lot of resources
  143. 12:46on the way.
  144. 12:47They are like typically like built as-you-go kind of like meter billing.
  145. 12:52So how to do that?
  146. 12:53Like how to put this on X-Request-ID 2?
  147. 12:55So in May 2025, Coinbase introduced X-Request-ID 2 with exact payment scheme.
  148. 13:00In December 2025, they announced the version two of the protocol, which was promising the up to payments payment scheme to kind of fix this problem of like meter billing.
  149. 13:10But it it took actually another like half a year almost to release the the up to finally.
  150. 13:15It was just like two or three months ago.
  151. 13:17So we were super excited about that.
  152. 13:18We were like finally we can make this work for our services.
  153. 13:24But then we realized actually the same double spending problem which is on on on exact is also with with up to.
  154. 13:30I mean, up to it was just a small sort of like improvement to the protocol where when you, you know, call the tool, you say, "Oh, my maximum is $5."
  155. 13:39And then the the the server can charge anything up to $5.
  156. 13:42But it doesn't prevent the double-spending problem.
  157. 13:44So, basically, we are sort of stuck again.
  158. 13:46So, you know, we have to go back to the drawing boards and figure like how to do that.
  159. 13:51And so, one way we we did it was we just use exact payment scheme to kind of like fixed uh like charge a fixed payment.
  160. 14:00And then after the the the the job is done, we we would like refund the the the wallet with the with the leftover money, basically, the money that that wasn't spent.
  161. 14:10I mean, that worked.
  162. 14:11But uh so, you charge, you do the work, you refund the remainder.
  163. 14:15But that means like there's suddenly like two blockchain transactions.
  164. 14:18That means like uh there's a time, you know, to to settle those transactions.
  165. 14:22There might be like some fees associated with that and so on.
  166. 14:25And also, the clients will need to trust the server to kind of like, "Hey, I give you the money, but you give it to me back, right?"
  167. 14:32But I think that that that's that's a minor issue.
  168. 14:34But it just feels somehow clunky.
  169. 14:35Like, why would we need to do these workarounds, you know?
  170. 14:38This protocol should support these things out of the box.
  171. 14:41So, just 2 months ago, uh Coinbase introduced like new payment scheme uh which is called batch settlement, which looks very promising.
  172. 14:48We haven't implemented it yet, so we'll report soon on that.
  173. 14:50But basically, just quickly, it works like So, first, the clients like deposit some money.
  174. 14:55So, basically, it's actually like like real transaction on blockchain using some uh Ethereum virtual machine black magic.
  175. 15:01Basically, uh the money is put in the escrow.
  176. 15:04And then the the client gets back a voucher like from the server.
  177. 15:08Say, "Hey, here is some cryptographic voucher, and you can use it to sign like microtransaction as part of this batch."
  178. 15:15And then like the client sends sends requests, for example, like API calls or, you know, for like individual tokens, whatever, and uh use this like passes this voucher to
  179. 15:26sign the those like a micro payments.
  180. 15:27But this transactions are the basically off-chain.
  181. 15:29They are just like sort of like cryptographically guaranteed locally, but you don't need to like write this like to the to the to the blockchain, which again is inefficient, slow,
  182. 15:38you know, uh expensive.
  183. 15:40And then at some point, you're like, "Hey, I I I accumulated a lot of these like micro transactions, so I just like settle them in batch."
  184. 15:46And then like you basically perform the transaction on blockchain.
  185. 15:49And then you can do this a couple of times and eventually refund the rest of the money like sort of like release the escrow, right?
  186. 15:56So actually this looks really cool, very exciting.
  187. 15:59We'll we're currently working on implementing it now, so we'll see.
  188. 16:03But so how did we resolve like all this to make it work, right?
  189. 16:06So we didn't really want to create like new new endpoints for different payment services.
  190. 16:12We didn't want to like the like hack the variable usage, you know, to our services.
  191. 16:15And also, we really don't want to like tweak too much our API because we have like tens of thousands of customers depending on that API.
  192. 16:22So we just can't like sort of like, you know, do whatever like new agentic payment standard is out there, just implement it right away.
  193. 16:30So so kind of to fix these problems, let me introduce you let me introduce our newest service on Appify, which is called agi.appify.com.
  194. 16:40And AGI is not what you mean it is.
  195. 16:44It's actually it stands for agent general interface.
  196. 16:46So instead of like application programming interface, we have agent general interface that can change anytime but because it's used by agents, so they're flexible, right?
  197. 16:54And on AGI, it's just a simple website with like one markdown document.
  198. 17:00It's not designed for people, so it kind of looks ugly, but it's okay.
  199. 17:04And there's instructions for agents like, "Hey, how can you actually buy things on Appify yourself through Xapo 2, MPP?"
  200. 17:12We can iterate quickly on this on this on this website or on this service because, you know, agents can pick up new version.
  201. 17:18It's not like fixed like API needs to be basically, you know, backwards compatible all the time.
  202. 17:25And the way it works is like the agent comes to agent.apify.com gets basically can buy a prepaid token.
  203. 17:34So basically they say like, "Hey, here's $5.
  204. 17:36Give me Give me a Apify token."
  205. 17:38We give them like Apify token back and then they can use the Apify token through our normal API or through MCP to run our jobs and services, you know,
  206. 17:47normally.
  207. 17:48And it it works pretty well.
  208. 17:50There is like no skill required.
  209. 17:52You just like point your agent to agent.apify.com.
  210. 17:54It picks it up.
  211. 17:56And I have here like a short demo.
  212. 17:59We're running out of time.
  213. 18:00So this is just like example how it works like.
  214. 18:03Actually, the X road ecosystem is like really early so that even, you know, we have to build our own like local wallet tool which you can like create like local like cryptographic key to charge, you know, with money and show QR code.
  215. 18:17Like I mean these things are still not not not not existing.
  216. 18:19I mean the ecosystem is like super super early.
  217. 18:22So I have local wallet with $10.
  218. 18:25Then I call like IGI.apify.com allocate like token with $1.
  219. 18:30I get back 402 payment required.
  220. 18:33So there is like this like super long like payment required signature.
  221. 18:37I use Apify I use the I use our MCPC just like MCPC client to sign the payment and then I can send the Oh.
  222. 18:52Oh oh oh.
  223. 18:54This demo didn't work as expected.
  224. 18:58Here we go.
  225. 19:01Mhm.
  226. 19:06Well, anyway, I have 1 minute left.
  227. 19:08[laughter]
  228. 19:10Demo more come later.
  229. 19:11Sorry about that.
  230. 19:12So, to conclude my presentation, like really like try it out and like try to build try try to use it like actually I try I tried to use it for the first time like a couple of weeks ago because I always thought that oh my god it's somehow complicated, you know, there is a lot of this like
  231. 19:25weird crypto lingo, you know, like I have I like I don't know what it what it means.
  232. 19:28But actually it's really really simple to to play with it.
  233. 19:31You can you know, get to get up and running in like 10 minutes.
  234. 19:34And uh it's still super early.
  235. 19:36Uh I think there's like $1 million transaction volume like per month.
  236. 19:40Like this is nothing, right?
  237. 19:41Like the economy is much much bigger.
  238. 19:42But I think it will sooner ramp up.
  239. 19:44And I think once uh really this like era of like uh token subsidies will end, I mean when the when you really will have to pay for the tokens, you know, that your agents consume,
  240. 19:55I think suddenly this decision whether to build or buy will, you know, make more economic sense actually to buy external, you know, services for a lot of things rather than build from scratch.
  241. 20:04And I think at this time really the agentic payments will explode and uh very soon uh um uh the agentic commerce might uh overtake the normal commerce.
  242. 20:14Thanks a lot for your attention and please come uh to join us uh in our booth.
  243. 20:20And actually I have another talk coming up in 2 hours uh about MCP and CLI, so you can check that one as well in Expo stage two.
  244. 20:29Thank you.
  245. 20:29[applause]