// Blog

Technical notes for AI agent builders

Tutorials, comparisons and design patterns for building autonomous agents that self-fund, call 345+ models and orchestrate MCP Tools.

Sign-In-With-X: what paying once for an x402 route buys

Sign-In-With-X lets a wallet that already paid for an x402 resource get back in without paying again. We read the spec and all three reference implementations. The grant is keyed by URL path, never expires, and the replay defence is optional — implemented by default in Go, absent by default in TypeScript, and unreachable in Python because a startup guard checks for a method that does not exist.

14 min read →

AgentCore Payments: AWS ships a managed x402 buyer

Amazon Bedrock AgentCore payments went GA on 18 August 2026: the buyer half of x402 as a managed AWS service, with server-side signing, session budgets enforced before signature, and MPP alongside x402. We read the docs line by line. The convenience is real, and so is the narrowing: canonical USDC only, two schemes, one challenge per call, and a wallet-operation fee that inverts the economics of sub-cent calls.

14 min read →

97 field names, zero agreement: the OAuth agent delegation drafts

OAuth has no way to say "this token is an agent acting for a user". Eighteen active Internet-Drafts are trying to fix that, none of them adopted by the working group. We counted 97 new field names across 423 pages; 96 of them appear in exactly one draft. Meanwhile the MCP authorization spec, which actually ships, contains zero occurrences of the word delegation.

14 min read →

CIMD in the wild: agent identity without registration

The 2026-07-28 MCP revision made Client ID Metadata Documents the preferred way for an agent to identify itself, and deprecated Dynamic Client Registration. We diffed all three revisions of the IETF draft, then crawled all 87,160 entries in the MCP registry and resolved 3,450 authorization servers. Only 17.2 percent advertise CIMD support; 93.7 percent still advertise a DCR endpoint; and 88.5 percent of the CIMD adopters kept DCR running alongside it.

15 min read →

One signature, fifty invocations: auditing x402's two-phase gap

x402 separates payment verification from on-chain settlement, and that window has been the subject of three independent security papers this year. We ran the attacks against @x402/express 2.24.0 and audited the monorepo at HEAD. The duplicate grant is closed. The duplicate work is not, and cross-resource substitution still succeeds on the first try.

16 min read →

Who pays your agent's gas? An on-chain audit of Circle Paymaster

An agent that holds only USDC still needs gas. Circle Paymaster is the permissionless way to pay it in USDC, and it is a different trust model from the x402 facilitator that eats the fee for you. We audited every mainnet deployment and measured a full day of traffic: the price of gas is set by the user operation, not by the chain, and in the window we measured accounts paid 202,307 USDC for transactions that cost 358 dollars to include.

14 min read →

AIPREF at the deadline: auditing the vocabulary agents are supposed to read

The IETF AIPREF working group has two standards-track drafts due at the IESG on 31 August 2026. One of them says, on its own cover, that its contents do not reflect working group consensus. We read every revision, implemented the resolution algorithm, and ran it against a fresh crawl of the top 10,000 domains. Exactly one domain emits a preference the specification can read.

16 min read →

Agentic week: x402 grew a payment lifecycle

Between 21 and 28 August, three merged changes in x402 attacked the same assumption: that a payment is one request, one signature, one settlement. auth-capture became a full authorize/capture/void/refund lifecycle with onchain authorizer binding, settlement_pending stopped being the caller's problem, and the exact scheme learned to settle before it serves. MCP, meanwhile, published its post-2026-07-28 roadmap.

9 min read →