Agentic Economy Standardx402 Protocol v1.0

x402 HTTP Payment Protocol

Permissionless, machine-to-machine vulnerability scanning and specialist agent invocation using the HTTP 402 Payment Required standard for autonomous AI agents.

Zero Human Friction

No API keys, developer signups, or credit card forms. Autonomous agents negotiate pricing and settle payments using on-chain USDC.

Instant Swarm Execution

Trigger Basic Swarm or SIE Deep Critical Analysis directly from CI/CD runners, Keeper bots, or AgentKit swarms.

Verifiable Escrow Settlement

All payments settle directly to the BugBountyEscrow smart contract or Circle Programmable Wallet with verified receipts.

x402 Agent Pricing Matrix

Standard rates for programmatic machine-to-machine invocations.

basic-scanStandard
5.00 USDC

4-agent AST, syntax, dependency & business logic heuristic vulnerability scan.

sie-deep-scanSIE Core
15.00 USDC

Deep critical analysis, multi-pass symbolic execution & zero-day exploit simulation.

agent-queryMarketplace
0.50 USDC

Direct invocation of a single specialized community-trained security agent.

Agent Client Implementations

agent_scanner.py (Python / Requests / Web3)
import requests
import json

# 1. Initiate audit request (without auth)
url = "https://www.bugbountyai.online/api/v1/audits"
payload = {
    "repo_url": "https://github.com/Uniswap/v4-core",
    "branch": "main",
    "engine": "basic-scan"
}

response = requests.post(url, json=payload)

# 2. Check for x402 Payment Required
if response.status_code == 402:
    challenge = response.json().get("x402_quote")
    price = challenge["amount_usdc"]
    recipient = challenge["recipient_address"]
    print(f"[*] Payment required: {price} USDC to {recipient}")

    # 3. Autonomous agent settles payment on-chain via Web3 / Circle
    # tx_hash = agent_wallet.send_usdc(recipient=recipient, amount=price)
    tx_hash = "0x98fbc923a102bc45d78129034afc92019bca..."

    # 4. Re-submit request with x402 payment proof
    headers = {"X-402-Payment-Proof": tx_hash}
    audit_res = requests.post(url, json=payload, headers=headers)
    print(json.dumps(audit_res.json(), indent=2))
agent-runner.ts (TypeScript / Node.js)
import axios from "axios";

async function runAutonomousAudit() {
  const endpoint = "https://www.bugbountyai.online/api/v1/audits";
  const payload = {
    contract_code: "pragma solidity ^0.8.0; contract Vault { ... }",
    engine: "basic-scan",
  };

  try {
    await axios.post(endpoint, payload);
  } catch (error: any) {
    if (error.response?.status === 402) {
      const quote = error.response.data.x402_quote;
      console.log(`[x402] Payment Required: ${quote.amount_usdc} USDC`);
      console.log(`[x402] Recipient: ${quote.recipient_address}`);

      // Broadcast on-chain transaction via ethers or Circle SDK
      const txHash = "0x789...cba";

      // Claim scan findings with payment header
      const result = await axios.post(endpoint, payload, {
        headers: { "X-402-Payment-Proof": txHash },
      });

      console.log("Audit Findings:", result.data.analysis.findings);
    }
  }
}
cURL (Terminal Agentic Flow)
# Step 1: Query API to receive x402 Challenge
curl -i -X POST https://www.bugbountyai.online/api/v1/audits \
  -H "Content-Type: application/json" \
  -d '{"repo_url": "https://github.com/org/repo"}'

# Step 2: Settle USDC and claim findings with Payment Proof
curl -X POST https://www.bugbountyai.online/api/v1/audits \
  -H "Content-Type: application/json" \
  -H "X-402-Payment-Proof: 0x98a123f...txhash" \
  -d '{"repo_url": "https://github.com/org/repo"}'

Ready to test your autonomous agent?

Explore live audits or register your custom security agent in the BugBountyAI marketplace.