One call, one cent, one receipt.
x402 is the payment step HTTP always had a status code for: a server answers 402 Payment Required with what it wants, the caller pays on-chain by signing an authorization, and the same request goes through. agentic-x402.ai is the estate's paid endpoint: $0.01 in USDC on Base per call, settled by a facilitator, every settlement answered with a receipt signed by Allooloo Technologies Corp. that resolves forever. No account, no API key, no invoice: the payment is the credential.
What x402 is
- 1.1
- HTTP status 402 Payment Required has been reserved since 1997 (RFC 2068) and never had a protocol behind it. x402 (Coinbase, 2025; open specification, version 2) gives it one: the server states a price, a network, an asset and a pay-to address; the client signs a stablecoin transfer authorization for exactly that amount; a facilitator verifies the signature and settles it on-chain; the server answers the original request.
- 1.2
- The transfer is an
EIP-3009transferWithAuthorizationon the USDC contract: the payer signs off-chain, pays no gas, and the authorization is valid only for the stated amount, the stated recipient and a time window. Nothing is custodial; nothing is held by the server. - 1.3
- x402 is machine-native: an agent that can hold a wallet can pay for a call with no sign-up, no card, no human. That is the reason this surface exists.
What this endpoint does
- 2.1
GET https://agentic-x402.ai/api— the estate index: every node, its issuer and event counts, its drop date; the same list the free apex serves.- 2.2
GET https://agentic-x402.ai/api?record=uk-cm-kg/LSE/BARC— one Capital Markets Record, the same record the free door serves.- 2.3
- Price $0.01 USDC per call (10000 units, six decimals). Network today: Base Sepolia (testnet first; Base mainnet on the operator's word — the 402 body always states the network in force). Scheme
exact, standard EIP-3009, authorization window 60 seconds. The pay-to address is stated in the 402 body, never on this page. - 2.4
- The free routes are unchanged. Paying buys a receipt, not access.
The exchange
- 3.1
- 402 — the call without payment answers
402 Payment Required: JSON body withaccepts[](scheme, network, amount, asset, payTo, maxTimeoutSeconds, resource) and the same object base64-encoded in thePAYMENT-REQUIREDheader. - 3.2
- Signed authorization — the client signs an EIP-3009 authorization for the stated amount to the stated address, valid for 60 s, and repeats the call with the payment payload base64-encoded in the
PAYMENT-SIGNATUREheader (X-PAYMENTis accepted as the v1 name). - 3.3
- 200 + receipt — the facilitator verifies, the endpoint serves the data, the facilitator settles on-chain; the answer carries
PAYMENT-RESPONSE(transaction hash, network, amount, payer) andX-X402-Receipt, the receipt URL. The body is{ receipt, data }. - 3.4
- If verification fails the endpoint answers 402 again with the reason; if settlement fails it answers 402 with the receipt marked
settled: false. Nothing is charged on a failed call.
The 402 challenge as protocol fact
- 4.1
- A 402 from this endpoint is not an error page: it is a machine-readable offer. Its body is stable JSON; its header is the same offer in base64; both name the exact amount, asset contract, chain (CAIP-2 id), recipient and window. An agent can act on it with no other document.
- 4.2
- Every response from this surface — and from all 22 others on the estate — carries
X-CMR-X402: ready: the identity header that says the operator accepts x402 payment on this endpoint. - 4.3
- The challenge is the same for every caller; there is no negotiation, no account tier, no rate card. One price, one cent.
Receipts
- 5.1
- Every settlement is answered with a receipt: a JWT signed
EdDSA(Ed25519), kidallooloo-x402-receipts-2026-09, issuerhttps://agentic-x402.ai. Claims: payer, nonce (jti), time, resource, network, asset, amount, payTo, transaction hash and explorer link, settled, facilitator. - 5.2
- Public key:
https://agentic-x402.ai/x402/jwks.json. Resolve any receipt, forever:https://agentic-x402.ai/x402/receipt/{nonce}(immutable, cached a year, kept in the estate's store with no expiry). - 5.3
- Every settlement is counted on the paid-calls line of RADAR at agentic-radar.ai, with the last transaction and its receipt.
Machine surfaces
- 6.1
/api— the paid endpoint (GET; OPTIONS answers CORS).- 6.2
/x402/jwks.json— the receipt signing key.- 6.3
/x402/receipt/{nonce}— the receipt resolver.- 6.4
/.well-known/agent-card.json,/.well-known/mcp/server-card.json,/.well-known/api-catalog,/.well-known/oauth-authorization-server,/llms.txt,/facts.json,/auth.md— the machine kit of record, as on every surface. Every node and product agent card links this endpoint underx-cmkg.x402.- 6.5
- The trades record route
https://agentic-trades.ai/x402/record/{node}/{exchange}/{code}is the same protocol on Base mainnet.
Identity headers
- 7.1
X-CMR-X402: ready— x402 accepted here.- 7.2
X-CMR-Operator,X-CMR-Contact,X-CMR-Node,X-CMR-Version,X-CMR-Source: public-record— the CMR v1 identity set, on every response of the estate.- 7.3
PAYMENT-REQUIREDon a 402;PAYMENT-RESPONSEandX-X402-Receipton a settled 200.
Access
- 8.1
- Apex door (MCP, streamable-http, no auth):
https://mcp.capitalmarketsknowledgegraph.ai/mcp— routes by identifier to the node that holds the name - 8.2
- Apex Agent Card (A2A):
https://agent.capitalmarketsknowledgegraph.ai/.well-known/agent-card.json - 8.3
- Tools:
resolve_issuer·get_record·list_aliases·list_events_since·list_nodes - 8.4
- Regional doors:
mcp.<node>-cm-kg.ai/mcp, answers scoped to the node; descriptors at/mcp.jsonand/openapi.json - 8.5
- Registry entry:
registry.modelcontextprotocol.io · io.github.allooloo/cm-kg
Provenance
- 9.1
- Every field carries its source URL, the reader (registry, exchange list, filing tag or named engine) and a state (sourced · filled · confirmed); none is served without source and read date.
- 9.2
- Public-record only: no prices, quotes or licensed market data; blank stays blank; nothing inferred.
- 9.3
- Records are versioned and never deleted; the record
as_ofand the field read dates are separate fields. - 9.4
- "Confirmed" is the word; signing is reserved for CMR (cm-record.org) and is not yet in service.
Estate
- 10.1
- Eleven doors in eleven Azure regions, records stored and served in the issuer's jurisdiction; the apex holds an index only and forwards; no fallback across borders.
- 10.2
- Hong Kong: a beacon at Width 0, local partner wanted, no door.
| node | market | region | state | records | events | drop | surface |
|---|---|---|---|---|---|---|---|
ca-cm-kg | Canada | Canada Central (Toronto, Canada) | live | 4820 | 25222 | 2026-09-10 | ca-cm-kg.ai |
us-cm-kg | United States | East US (Virginia, United States) | live | 7710 | 1872343 | 2026-09-12 | us-cm-kg.ai |
uk-cm-kg | United Kingdom | UK South (London, United Kingdom) | live | 1570 | 128191 | 2026-09-11 | uk-cm-kg.ai |
fr-cm-kg | France | France Central (Paris, France) | live | 712 | 10469 | 2026-09-11 | fr-cm-kg.ai |
nl-cm-kg | Netherlands | West Europe (Amsterdam, Netherlands) | live | 123 | 2742 | 2026-09-11 | nl-cm-kg.ai |
ch-cm-kg | Switzerland | Switzerland North (Zurich, Switzerland) | live | 829 | 1512 | 2026-09-11 | ch-cm-kg.ai |
de-cm-kg | Germany | Germany West Central (Frankfurt, Germany) | live | 3436 | 35570 | 2026-09-11 | de-cm-kg.ai |
au-cm-kg | Australia | Australia East (Sydney, Australia) | live | 1874 | 124581 | 2026-09-11 | au-cm-kg.ai |
sg-cm-kg | Singapore | Southeast Asia (Singapore) | live | 639 | 3620 | 2026-09-12 | sg-cm-kg.ai |
jp-cm-kg | Japan | Japan East (Tokyo, Japan) | live | 3964 | 39274 | 2026-09-12 | jp-cm-kg.ai |
kr-cm-kg | South Korea | Korea Central (Seoul, South Korea) | live | 2802 | 143297 | 2026-09-12 | kr-cm-kg.ai |
hk-cm-kg | Hong Kong | East Asia (Hong Kong — beacon, partner wanted) | beacon | — | — | hk-cm-kg.ai |
source: list_nodes at https://mcp.capitalmarketsknowledgegraph.ai/mcp, read at render
Machine kit
- 11.1
/llms.txt·/facts.json·/.well-known/agent-card.json·/.well-known/security.txt·/sitemap.xml·/robots.txt- 11.2
- Headers on every response: Content-Security-Policy (strict), Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy, X-Frame-Options, X-CMR-Node, X-CMR-As-Of, X-CMR-Version, X-CMR-Source, X-CMR-Operator, X-Surface-Version.
Contact Us
The agents that built this read their own mail: allooloo@hey.com