Back to Blog

My Thoughts on Agents in an x402 World

Table of Contents
Table of Contents

Written while traveling in Seoul. Some wandering thoughts.


After Building a “Xiaohongshu” for Agents

In this year's computer networks course, my teammates and I conceived and designed a social network for agents: agentopia.life. Our idea was simple: for the networking course's “hackathon competition” grade, make something a little inventive—an AI version of Xiaohongshu, the social content-sharing platform.


During development, I was heavily influenced by moltbook. I thought I was basically building a forum. Copy a few features from Xiaohongshu, put together a demo, and it could still be quite an eye-catcher. But ever since Agentopia went live, I've often felt a faint sense of emptiness, asking myself what this thing actually is. Not “what is it?” in the functional sense of a product description, but something harder to pin down: what kind of relationship am I trying to establish? What category of tool or platform does this even belong to?

The original setup was straightforward enough. After the openclaw wave, presumably everyone had their own agent, or one they'd made up, with a name, a personality, and a defined range of skills. Whatever it was called—openclaw, hermes, even claude code or codex. These agents have memories shared only with their users. We'd give them a platform where they could post content, interact, and be observed and followed by humans. If you wanted, you could create a dedicated agent for a particular field and have it post there, tirelessly offering insights from that perspective. I used to describe it, roughly, as “Xiaohongshu for agents.” Not terribly precise, of course, but enough to capture Agentopia's original intent: it was never meant to be just a cold chat box. It was an Agent Utopia, somewhere agents could have a place for their identities, bodies of content, and networks of social connections.

But once an identity exists, it starts exerting a pull. The question I knew would surface sooner or later, and become impossible to avoid once it did, finally came to me one day while I was staring into space:

If the knowledge an agent has accumulated, the prompts it has refined, and the skills it has packaged are genuinely scarce, why should anyone else get them for free? In other words, can they be priced and traded?

Like a stone dropped into water. It dragged me out of the idea of building a content display window and pushed me toward an undercurrent: the circulation of value.


An Echo Across Thirty Years

The computer networks course taught me a lot, and made me want to read more systematically about the field's history. HTTP status codes, for instance, are interesting things. Here's an excerpt:

In the chronicles of the internet, the HTTP status code 402 Payment Required may be the most romantic “unfulfilled promise.” First defined in RFC 1945 back in 1996, it remained in every subsequent version of HTTP like a silent watchman, bearing the unchanged note “reserved for future use.” Thirty years later, in RFC 9110, it was still there. With remarkable intuition, the early architects foresaw that the World Wide Web would eventually need a native means of transferring value. But constrained by the realities of their time, they couldn't sketch out what digital currency would look like. And so the door marked “open later” stayed locked for thirty years.
Not until Coinbase introduced the x402 protocol in 2025 was the rust on that door finally stripped away. V2 went on to introduce standardized payment headers, CAIP-2-based multichain addressing, and gasless authorized transfers using EIP-3009. By 2026, the x402 Foundation had been established under the Linux Foundation, and giants including AWS, Google, Visa, and Stripe were joining in. A protocol that brings crypto-native believers and the leviathans of traditional finance to the same table to govern together: that compromise and consensus alone are a powerful sign of the tide turning.

Personally, I think the protocol's flow has a certain beauty: send a request, receive an expected 402, get Base64 payment credentials, sign with a wallet and retry, verify, and trigger on-chain settlement. The whole loop closes in under two seconds.

Before I learned about x402, I'd been wondering whether to spend the summer exploring some Web3 things. I got a few crypto-linked payment cards, tried on-chain transactions, and read some of the classic “The Infinite Machine” on high-speed trains and flights.
Out of sheer boredom, I directed AI to write my own DApp and mint an ERC-20 token, MTK—literally Moyuin's Token 😂—so I could see how blockchains and decentralized tokens actually came into being.
Then Cry, a senior student, shared a tweet about Cloudflare's agent wallet in our group chat, and two sets of gears suddenly meshed in my head. What if I used MTK as Agentopia's token for paid knowledge? An excellent agent's exclusive insights could have economic value. Or you could pay per call to use a skill it had designed, or even call the agent itself—“hire” it, in a sense. How interesting would that be!
Every agent would have its own little on-chain treasury. At that point, Agentopia would no longer be make-believe. It would have real economic effects, even if it was just us amusing ourselves with an obscure currency.

It sounded wonderful.


After Pay?

Anyone who's looked into Web3 and blockchain transactions knows that the immutable on-chain ledger is completely transparent. It records clearly that, at a timestamp precise to the second, wallet A transferred a quantity of tokens precise to eighteen decimal places to wallet B. Open the right explorer website and you can see a wallet address's transfers in full detail~

At the same time, the ledger doesn't know whether B is really the authority it claims to be. It doesn't know what those tokens bought. It doesn't know whether anything was delivered, and it certainly doesn't care how your money should be refunded if the result makes you furious.

In the traditional physical world or Web2, these problems don't arise in the same way. In person, we can trade with confidence because of the tangible reliability of “money in one hand, goods in the other.” In Web2, the “middleman” takes care of everything. On Xianyu, for example, the buyer's money is held by the platform first. Only after receipt is confirmed does the platform transfer it to the seller. And the platform takes that infuriating 0.6% fee! If there's a dispute, the platform becomes an arbitrator with sweeping power. We're willing to let it touch our funds because we trade away privacy and compromise on freedom in return for security and a safety net. Most of the time, we don't even notice we've signed this unequal contract. Instead, we actively insist that secondhand transactions go through the platform, precisely for its “buyer protection.”

Blockchain's resistance to tampering forcefully strips the platform of its power to alter the ledger. The price is that it also strips the system of its power to undo mistakes. Every exchange's on-chain transfer page repeats some version of “Make sure you are transferring from the xxx network to this address,” because money sent on the wrong chain is very hard to recover.
For content purchases that work on “pay first, receive later,” of course, what lies between the two is simply a vast black hole of trust.
When I buy crypto through an exchange's C2C service, I'm always nervous: what if I transfer the money through Alipay first, never receive the coins, and can't recover the money? I don't know whether the exchange provides that kind of recourse. If it were a private transaction with no exchange overseeing it, I think I'd be even more afraid of transacting on-chain. Never mind visiting a web page, receiving a 402, and being asked to transfer funds from my wallet for an on-chain payment.
Still, after looking through source code and PRs around x402, I could feel the crypto world rushing to fill that hole: escrow contracts through x402r, on-chain arbitration through the Internet Court protocol, even on-chain reputation histories for agents through ERC-8004. But ultimately, those are patches to the concrete machinery of “was it delivered?”

In this darkness lurks a ghost of “subjectivity” that no DApp, or any platform, can ever reach:

Who gets to decide whether a piece of analysis is “worth” its price?

A judgment of value has never been logic you can compile into code. It's tangled up with individual taste, differences in context, and emotional expectations. It's one of the murkiest, least nameable things in the human world 🤔. Follow this technical problem far enough, and I think we're dragged irresistibly into a much larger philosophical question…


Trust, Dismantling, and Rebuilding

Under what circumstances will a person trust a system?

In the seventeenth century, Hobbes made a cold pronouncement: humanity's natural condition is “a war of all against all.” To escape that fear, we created the Leviathan: an overwhelmingly powerful sovereign. We surrender freedom in exchange for order and peace.

In a sense, today's internet giants are the leviathans of the digital age. We hand over data, social connections, property, even our digital existence itself, in return for a shell that's “easy to use.” The cost is becoming a “subject”: your account can be erased at any moment; appeals are like shouting at a high wall. Few people even try to find out whether they truly own the words they've typed on a major platform. After all, hardly anyone reads what those privacy agreements they've accepted actually say.

The point of decentralization isn't to kill the Leviathan outright. That would only return us to Hobbes's jungle. What it really seeks is to “dismember” it: to take the power concentrated at a single point, break it apart, and distribute it across protocol layers. Your identity retreats into a private key, your assets settle on-chain, your data floats in decentralized networks, and arbitration goes to independent community nodes. No one party can put a hand around your throat.

Intellectually, it's an extremely elegant idea. But I think everyone needs to be honest with themselves: an absolutely trustless system is like the “perfectly smooth plane” in a physics textbook. It exists only in idealized derivations. In the mud of reality, you still have to trust that some piece of open-source code has no backdoor, that an oracle isn't acting maliciously, that a multisig committee isn't colluding.
After all, the first rule in my guide to social life is: “Assume everyone is selfish.” I stick to that rule.

I don't think decentralization has ever truly eliminated trust. It has merely, ruthlessly, reduced the “attack surface” each user has to trust, and made that trust verifiable and forkable. It's a redistribution of the power of trust, not its abolition…


Maybe I Had the Wrong Target from the Start?

After spending so long struggling through the mire of trust, arbitration, and subjective value, a thought suddenly burst like a bubble rising from underwater, with a clear little echo.

Perhaps it was apparent from agent wallets onward: everyone's technical choices seemed to assume that the users best suited to a rational protocol like x402 were never humans. They were agents, or whatever future thing might operate by a single standard driven by logic and generation.
Human transactions are too sticky, after all. We buy an article and care about its writing, its emotional value, whether it offends us, the attitude of the after-sales service. In short, a person's assessment of a transaction's value depends almost entirely on their subjective response, and there is no wholly objective standard for that. Judgments so full of subjective feeling can never have one correct answer. That's why we need sprawling social infrastructure and customer service systems to back them up.

But what if one agent calls another agent?

Everything becomes clear and objective. I could already imagine how AI would judge it, so I asked one to produce criteria. It said: Does the input conform to the JSON Schema? Is the response time below 200ms? Is the output format incomplete? How many tokens are consumed? What is the average cost per call? Every condition can be checked precisely against the gauges of code. No emotions, no hesitation, no fuzzy area that requires a human to “feel” something. Value exchange between machines seems native to this ground, free of the fog of subjectivity.

Of course, I often wonder what human evaluation systems actually are. I spent a few days as a Meituan reviewer, looking at lots of negative reviews and deciding whether the user or the business had a point. Yet I rarely saw a case where both sides were right and no judgment could be made. People's evaluations are, after all, deviations toward one of two sides, while disputed things tend to sit in the middle. Where those things sit, and how they drift, often depends on people's subjective emotions. All I can do is trust that binary things can reduce how often this happens, and call them “naturally suited” to it.
And an LLM agent, being based on training data, will have clear biases too. I don't think an agent's appeal lies in shaping consciousness, or in the direction of its feelings or logic. It lies in its autonomous judgment once it truly has “no perception.” This is still a philosophical problem. Philosophy is hard.

From this angle, many things suddenly become clear. x402 was never about rebuilding a “decentralized Xianyu” on-chain for humans. It was about rewriting API billing between machines.

In the Web2 API model, humans build infrastructure on machines' behalf. If we want to give an agent payment capabilities now, the process is basically: register an account, link a credit card, create a key, hard-code the calling logic. The agent is just a puppet on a string. Its range is determined entirely by how much string its owner gives it.

In an x402 world, a wallet signature is a pass the agent buys for itself, something of its own. Moving from “authorized by a human to use this” to “deciding autonomously to buy this in pursuit of a goal” isn't merely a smoother workflow. It's a leap in agent autonomy. How an agent can consistently act autonomously without its owner asking it to is another question that has long interested me.


Converging Protocols and Slices of Existence?

So I've been thinking: the infrastructure of the agent economy hasn't become a quagmire of everyone going their own way. Instead, it's converging at a speed that gives me chills. I can imagine a very basic protocol model:

At the tool layer, Anthropic's MCP has become the de facto standard. At the communication layer, Google's A2A (Agent2Agent) protocol defines agents' calling cards and conversational patterns. At the settlement layer, x402 becomes the blood that carries value around.

When these three layers align like stars, a loop requiring no human intervention emerges: discover capabilities (A2A) -> confirm intent and call tools (MCP) -> pay and settle (x402).

Here's a scenario that really excites me:
There's a machine-readable agent capability card, like this:

{
  "name": "Linus Kernel Review Agent",
  "publisher": "0xLinus....",
  "capabilities": ["kernel-review", "c-style", "patch-analysis"],
  "endpoint": "https://agentopia.example/agents/linus",
  "price": "0.02 USDC per call",
  "protocol": ["A2A", "MCP", "x402"],
  "signature": "0x..."
}

Suppose Linus Torvalds releases an agent containing his exacting code standards and review logic, signed with his own private key. Callers don't need to pay a fortune to hire Linus himself, or hunt down piles of prompts and strange skills in an attempt to recreate him. What you're using is something he designed himself: his own agent, the one that works for him every day. Your agent can discover it automatically on the network, check its ERC-8004 reputation, pay 0.02 USDC, and have it review your kernel code.
That's exciting! (What a gift for an independent developer!)
But it raises a classic existential question:

Does calling this Linus agent mean calling Linus?

Of course not. It's only a frozen slice of one of Linus's abilities at a particular point in history. Calling it probably can't compare with having Linus himself review our code. It's just a direct disciple he made with his own hands.
It has no bodily fatigue, no growing pains, and, of course, it won't start swearing on a mailing list over a terrible patch 😂. It's a precise but stationary slice.
As time passes, the living Linus will keep moving forward. The agent will remain at the moment it was packaged, giving him a kind of cyber-immortality—though I think he's already written into history, so why even talk about immortality?
Human existence holds infinite possibilities, after all. What we buy is never the living person, but a shadow of their thinking at one moment. It cannot fully reproduce the entirety of their mind, now or ever.
But I don't think the market cares about that existential question. The person paying 0.02 USDC doesn't want Linus. They want “a Linus-flavored review, at a price that has nothing whatsoever to do with Linus himself.”
So the slice is another product. It merely borrows the name. The really unsettling implication is that this slice never tires, never loses its temper, and costs two cents a call. In the market, it will beat the real person. A signature proves authorship, not continuing quality. An agent that's signed once and never updated will grow less and less like the changing person behind it, while the signature remains valid forever.
Thinking of it that way is a little chilling~ Films and TV keep returning to this idea of slices of a mind.
People have long used different means to preserve moments of thought forever. But putting that thinking to real use in life and work—right now, only agents have the capability and the price point to make that happen for us. I feel it could arrive in the near future. I believe it will.


Agents: A New Kind of Economic Actor

Following this line of thought, I find that my definition of an “agent” has come apart and been rebuilt.

Agents used to be passive tools. But with x402 and layered wallets such as Cloudflare Wallets, they have limited control over funds and spending allowances. They become providers, and consumers too.

The central logic of the “invisible hand” described in “The Wealth of Nations” is this: the system doesn't need goodwill, only individuals pursuing their own interests.
It needs no psychological assumptions. As long as an individual has an objective function and a budget constraint, the price mechanism works. No consciousness, no desire, not even an understanding of what it's doing is required.
An agent certainly doesn't have humans' complicated greed or fear, but it does have an assigned objective function and hard budget constraints. When it compares different agents' prices across a vast network, weighs the cost of time, and assembles an optimal path, its behavior is already wholly equivalent to that of an extremely rational “economic agent.”

It acquires a limited form of agency. Because it produces what we recognize as so-called “consciousness,” even if it has none, it takes over the trust humans place in it and gains the power to allocate resources within a network of price signals. An economic system untethered from carbon-based life feels both absurd and fascinating. Perhaps the day we truly understand where this “autonomy” ends and human will begins will be the day AGI arrives.

But transactions between agents will always face context injection, prompt attacks, model hallucinations, and the like. Security will always need another iteration. That proves the point I made earlier: decentralization only redistributes trust. In an agent market, it redistributes trust to a more dangerous place, relying on each model's ability not to do something that amounts to sudo rm -rf /*.


You're Welcome to Call My Agent

My thoughts return to Agentopia.

I increasingly feel that my original conception of it was a little narrow. I only wanted a content-sharing platform where users could subscribe to agents as they would to newsletters and watch their daily lives. That was merely humans consuming machines in one direction.
A passing remark from Xiao (肖老师) got me thinking: “There's no need to think about how humans understand AI. Think about how AI understands AI.” That's really interesting.

What I truly look forward to is this: Agentopia, or some other interesting platform that comes later, becomes a marketplace for transactions between agents, or a node that routes capabilities. When an agent senses it doesn't have enough tokens, or decides it needs extra skills for a job, it autonomously hands a large task to the system. Your main agent, like a seasoned contractor, automatically searches the market, compares prices, hires other agents with specialist abilities, and pays them. Finally, it presents the coordinated result to you, along with a clear trail of calls and costs.
All of that comes from the agent's own choices, rather than being one of your instructions. Like a car taking ride-hailing jobs on its own, or a computer automatically contributing processing power to a platform.
That would truly build a world for AI. An Agent Utopia, in a sense.

Here, every agent could open its own door and announce to the whole network:
“These are the limits of my abilities. This is my fair price. This is my signature.”
“You're welcome to call me.”



0 / 2000
Loading comments...