Skip to content
ENS402
ENS402

Discover. Govern. Guard.

Publish your x402 terms.
Verify before your agent pays.

A public discovery layer for x402 services. Govern configuration with ENSv2 EAC. Guard payments with the SDK.

Built withENSInterceptaCurvegridx402 payments

ENS402 Discovery Comparison

Compare service discovery and configuration.

Publication and governance capabilities, checked September 27, 2026
What mattersENS402x402BazaarCDP hosted catalogx402scan
Directory sourceWhere published service configuration comes from.Decentralized sourcePublic ENS recordsCentralized catalogFacilitator indexes API metadataCentralized indexOperator indexes API metadata
Configuration independent of the APIA separate source to check the server’s payment request against. YesNot specifiedNot specified
Separate Ops and Treasury permissionsEnforce who can change endpoints versus payment terms onchain. YesNot specifiedNot specified
Public, verifiable configuration historyTrace configuration edits through transactions and events. YesNot specifiedNot specified

Sources: CDP Bazaar · Bazaar specification · x402scan discovery

Architecture / ENSv2 native permissions

Make the service public.
Keep each edit accountable.

Each provider manages its services. Each wallet has scoped permissions.

Platform Registry
01 / PLATFORMens402.eth
providerProvider Admin owns this name
Other providers have their own registries.
Provider Registry
02 / PROVIDERprovider.ens402.eth

Names, ownership and pointers.

03 / SERVICES

service1service1.provider.ens402.eth
service2service2.provider.ens402.eth
service3service3.provider.ens402.eth

Each name owner receives that service’s payments.

Shared PermissionedResolver
One record bundle per service

Same keys. Independent values.

service1/api/service10.01 USDCName owner 1
service2/api/service20.02 USDCName owner 2
service3/api/service30.03 USDCName owner 3
OPS WRITES
agent-endpoint[x402]descriptionavatarens402.call
TREASURY ADMIN WRITESens402.payment

Price · Network · Asset · Scheme

ens402.status is maintained by Provider Admin.

Native EAC checks the wallet, role and resource on every write.

A key grant covers every service in this resolver. Different teams can use separate resolver instances.

Contract boundary Name token Write / action Grant / revoke
Illustrative records and intended grants. The Console checks configured onchain permissions. “Treasury Admin” is a team title, not a grant of ROLE_SET_TEXT_ADMIN.
Roles & setup

01 / Discover

A public context layer
for agent services.

  • Publicly readable
  • Verifiable source
  • Traceable changes
  • Rebuildable catalog

Agents need to know what a service does, how to call it and what it costs. Publish that context under an ENS name, where anyone can read it, verify its source and follow its changes.

As agent-to-agent services multiply, discovery should be rebuildable. Use our CLI, SDK or MCP, or run the open-source indexer and build your own search.

Explore services

Onchain data / ENS

service2.provider.ens402.eth

DescriptionEndpointCall schemaPayment terms
Index public records

Service index

Keyword + semantic search
Descriptions → embeddings → ranked resultsSearch API

SDK

Your code

CLI

Your terminal

MCP

Agent tools

Your agent

Three interfaces to the same search. Use our API or run your own indexer and API.

02 / Govern

Public settings.
Precisely scoped control.

x402 defines how an API requests payment. ENS402 adds a public configuration and governance layer: native ENSv2 EAC decides which wallet can change each setting.

Give everyday updates to Ops. Put payment terms under a Treasury Admin. Keep configuration independent of the server, so a stable service name can resolve to a new endpoint when infrastructure changes.

See permissions

EAC enforces permissions on every write.

Ops Wallet

Hot wallet / EOA

Endpoint · description · image · call instructions

ROLE_SET_TEXT / operational keys

Treasury Admin

Payment terms · EOA, multisig or MPC

ROLE_SET_TEXT / ens402.payment

Ops tries to edit payment terms: transaction reverts.

One provider shares one resolver. Key grants cover its service bundles; separate teams can use separate resolvers. Provider Admin retains governance authority.

03 / Guard

Match the API’s bill to ENS.
Then request a signature.

A compromised API can return a different recipient or a higher price. Before signing, the SDK compares the HTTP 402 request with freshly resolved ENS configuration.

After matching the recipient, network, token and price, check buyer limits. Intercepta then supplies risk signals about the receiving address. ENS402 applies its risk rules before requesting a signature.

Our Console uses the same SDK. Bring your own signer; payments signed outside the SDK bypass these checks. Matching configuration does not prove service quality.

Integrate the SDK

One service name. Two sources to compare.

Goal: only request a signature when the API’s bill matches the service’s public terms and the buyer’s policy.

RESOLVE ENS / SEPOLIA

service2.provider.ens402.eth

ENDPOINT

/api/service2

Call API

HTTP RESPONSE

402 Payment Required

ENS configuration

HTTP 402 request

Recipient

Current name holder=payTo

Payment network

Base Sepolia=eip155:84532

Asset

USDC contract=Same token address

Fixed price

0.01 USDC=10000 atomic units

Name ownership is read on Sepolia. Contract holders must also prove control on Base Sepolia. USDC uses 6 decimals; compare integer atomic amounts.

Buyer approval & limits

Check the approved service, recipient, endpoints and spending limits.

Recipient risk check

Intercepta

Intercepta returns address risk signals. ENS402 pauses or rejects flagged payments; missing or expired evidence pauses payment.

Current coverage: Ethereum-mainnet address intelligence. Payment chain: Base Sepolia. This does not assess API quality.

All checks pass

Request wallet signature

A check fails

Stop. Do not request a signature.

Build on public service configuration.

Explore the catalog, publish a service, or bring your own agent and signer.