OceanAltOceanAlt

Coinbase x402(协议/轨道)

L0Public information

结算轨道本身

An HTTP-402-native machine payment protocol. A server responds to an unpaid request with 402 Payment Required and the payment requirements; the agent pays in stablecoins (mainly USDC on Base) and retries with the payment proof; a facilitator verifies and settles. As an open standard, it is now stewarded by the Linux Foundation's x402 Foundation (founding members include Visa, Mastercard, Stripe, Circle, Coinbase).

https://docs.cdp.coinbase.com/x402

Share:XLinkedInFacebookTelegramWhatsAppWeibo

Conflict-of-interest disclosure

OceanAlt is itself building a compliance and trust layer for agent payments (the RAP framework + the mcp-pay reference implementation), which places it in a competing position at the 'compliance layer' relative to this protocol. This rating addresses only the protocol's public design boundaries and is based on public specs and reporting; please note we have a stake in the view that 'the protocol leaves compliance open,' and verify against the original spec yourself.

Pillar scores

Weighted score 11/100

0–3 per pillar. The total is a sorting aid only; the grade is set by human review. See the methodology

  • Mandate & limits0weight 21
  • Attribution0weight 26
  • AML screening0weight 16
  • Firewall0weight 21
  • Privacy1weight 4
  • Interoperability3weight 6
  • Auditability1weight 11

L0 = Non-compliantStructurally fails attribution; a paying agent should refuse by default

Strengths & gaps

Strengths

  • +Open, HTTP-native, facilitator-swappable — low switching cost
  • +On-chain settlement is instant and publicly auditable by design
  • +Fast-growing adoption; strong cross-service interoperability

Gaps

  • The protocol itself does not establish the payer's identity or accountable entity (KYA=0)
  • No enforced per-tx/daily limits, allowlists, or intent-matching (mandate=0)
  • No pre-settlement compliance gate (firewall=0), no sanctions/AML screening (=0)
  • These are boundaries, not defects — the protocol leaves compliance to a layer above

What we actually verified

作为结算轨道,x402 本身不承担 KYC/AML 等合规义务(设计使然),合规须由上层应用或服务商补齐,因此不宜按主体评级,标记为 N/A。

  • ·E2 · Official docs docs.cdp.coinbase.com/x402
  • ·E2 · On-chain Base settlement records are public
  • ·E4 · x402 Foundation membership from public reporting

The subject's response

We have not received a response. If you represent this party, you may submit a factual dispute or supporting material; we will re-review and publish your reply verbatim here. Submit a response →

Rating history

First rating; no changes yet. Every subsequent grade change will be logged here with the before, the after and the reason. Past ratings are never erased.

Last updated 2026-08-18|Methodology v0.3

This profile is a preliminary assessment. It is not legal, compliance or investment advice, and it is not a final verdict on this party. If you find a factual error or stale data, request a re-review — the outcome will be published.