Before you start
Complete Prerequisites and Testnet Funds first. You need:- Node.js 20 or later, and Git.
- A Fireblocks API key and PEM secret from a scoped API user, plus a vault account ID.
- Testnet USDC for the payer, and testnet ETH for gas in both the payer (for non-
eip-3009runs) and the facilitator’s vault.
examples/, so a single clone covers all three pieces.
Step 1: Start the facilitator
config/facilitator.json and fill in your Fireblocks credentials:
Step 2: Install the CLI and mint an admin token
In a second terminal, build thex402 CLI and put it on your PATH:
Step 3: Activate the vault and import USDC
Activate the vault wallets the facilitator needs and cache the receiver addresses:Step 4: Declare a product and mint a merchant key
Declare the paid endpoint as a product, priced at one US cent:product_id it prints (prod_…). Then mint an API key the merchant server will use to call the facilitator:
Step 5: Allow the facilitator to settle
The facilitator settles by submitting aCONTRACT_CALL transaction from your vault. For that transaction to go through without a manual approval each time, add a Fireblocks Policy rule that auto-approves a CONTRACT_CALL from your receiver vault using the network’s gas asset (for example, ETH_TEST5 on Sepolia). See Set Policies.
Without an auto-approving Policy rule, settlement transactions wait for manual approval in the Fireblocks Console, and the quickstart will appear to hang at settlement.
Step 6: Run the example merchant
In a third terminal, configure and start the example merchant with the key and product ID from step 4:examples/merchant/.env:
/premium and leaves /hello free. A request to /premium without payment now returns a 402.
SETTLEMENT_MODE controls whether the merchant settles synchronously before serving the response (settle-first) or serves first and settles in the background (optimistic). It is an important production choice with a latency-versus-risk tradeoff; see When to settle.
Step 7: Pay for the resource
In a fourth terminal, set up the test client. It signs payments with a local development wallet, so you do not need a second Fireblocks vault for the payer./premium, receives the 402, signs an EIP-3009 authorization, retries with a payment-signature header, and prints the merchant’s response plus the settlement transaction hash from the PAYMENT-RESPONSE header.
Step 8: Confirm settlement
Check the payment landed, from the CLI terminal:completed status with a transaction hash means the USDC moved on-chain into your vault’s receiver address. You have run a full x402 payment.
Run every mechanism at once
The repo ships an end-to-end harness that exerciseseip-3009, permit2, and erc7710 in sequence, polling until each payment reaches completed:
Troubleshooting
- Settlement hangs. You are likely missing the auto-approving Policy rule from step 5, so the
CONTRACT_CALLis waiting for manual approval in the Console. insufficient_fundsor a fund-me block. The payer address is short on USDC, or short on gas ETH for a Permit2 or ERC-7710 first run. Top it up from a faucet.- Server refuses to boot citing mainnet. You imported a mainnet asset. The facilitator is testnet-only by default. Use a testnet asset, or see Network policy.
What to read next
- Integration — replace the example merchant with your own server.
- Build an Agentic Product Catalog — add more products and publish them to agents.
- x402 Agent — pay for resources from a Fireblocks vault instead of a local wallet.