Back to Skills

okx-agent-payments-protocol

Use when an agent hits HTTP 402 / payment-required, or the user mentions x402, x402Version, X-PAYMENT, PAYMENT-REQUIRED, PAYMENT-SIGNATURE, WWW-Authenticate: Payment, permit2, upto, metered billing, a payment channel / voucher / session, channelId / channel_id, opening / closing / topping up / settling / refunding a channel, a paymentId or a2a_ link, or creating / checking a payment link. Covers x402 (exact, exact+Permit2, upto, aggr_deferred), MPP (charge / session), and a2a-pay paymentId flows

292stars56forksUpdated 6/27/2026

Security Assessment

Medium Risk(50/100)

Detected risks:

Secret Exposure([references/multi-scheme.md] token=, [references/accepts-schemes.md] PRIVATE_KEY)
Sensitive File Access([_shared/preflight.md] .env, [references/accepts-schemes.md] .env)
Security Score50/100

About okx-agent-payments-protocol

Acts as a dispatcher for agent-driven onchain payments, triggered when an agent encounters an HTTP 402 / payment-required response or when payment-related terms (x402, X-PAYMENT, PAYMENT-REQUIRED, WWW-Authenticate: Payment, permit2, channelId, paymentId, a2a_ links, and many bilingual variants) appear. It distinguishes three payment paths by HTTP signature: an accepts-based 402 carrying the challenge in the body (v1) or a PAYMENT-REQUIRED header (v2); a WWW-Authenticate: Payment 402 that is channel-capable with intent 'charge' or 'session'; and a2a-pay, a paymentId-based flow with no 402. Shared steps of detect, decode, confirm, and wallet check precede dispatch to a specific reference file.

Two behavioral guarantees dominate the skill. First is zero-text-on-trigger: between detecting a 402 (or any trigger word) and emitting the first user-facing card, no user-visible text is produced — no acknowledgements, no enumeration of schemes, networks, tokens, or amounts, and no progress narration that leaks internal routing. Second is never-skip-user-gates: exactly one confirmation card runs per payment, either the Step A3.5 recommendation card when there are multiple candidates and the user picks the option, or the Step A4 confirmation card for a single candidate, and that gate cannot be skipped under any claimed past preference. Terminology rules require always naming it the bolded 'OKX Agent Payments Protocol' in any language, keeping internal detection and dispatch silent, exposing scheme literals only inside the expanded alternatives list, and keeping externally defined protocol literals and headers byte-for-byte exact.

Command routing maps each signal to a CLI command and a reference. A v2 success path replays the returned authorization_header directly and deliberately loads no reference; the accepts-schemes reference is loaded only on error or legacy v1 paths, where an output field indicates whether the scheme is exact, exact+Permit2/upto (permit2Authorization), or aggr_deferred (sessionCert). Charge and session intents route to dedicated references, with any close, topup, settle, voucher, or refund near a channel_id treated as a mid-session MPP operation. The paymentId and create/check payment-link flows route to the a2a-pay reference, and pre-flight checks are read from a shared wallet preflight file.

FAQ

What triggers this skill?

An HTTP 402 / payment-required response, or any of a long bilingual list of payment terms such as x402, X-PAYMENT, PAYMENT-REQUIRED, WWW-Authenticate: Payment, permit2, channelId, paymentId, a2a_ links, and create/check payment link. Any close, topup, settle, voucher, or refund near a channel_id is treated as a mid-session MPP operation.

What is the zero-text-on-trigger rule?

Between detecting a 402 (or trigger word) and emitting the first user-facing card, the skill outputs no user-visible text — no acknowledgement, no enumeration of schemes, networks, tokens, or amounts, and no narration of internal routing. The skill-load tool call may run but emits no surrounding prose.

How many confirmation cards run per payment?

Exactly one: the Step A3.5 recommendation card when there are two or more candidates and the user picks the option, or the Step A4 confirmation card for a single candidate. This user gate is mandatory every time and cannot be skipped on the pretext of a past preference, which the skill says does not exist.

How should the protocol be named to the user?

Always as the exact English phrase 'OKX Agent Payments Protocol' wrapped in markdown bold, regardless of the user's language, even inside otherwise-Chinese sentences. Internal protocol literals, headers, and identifiers are reserved for CLI invocations, HTTP headers, JSON, and code, and are never spoken to the user.

When does the skill load the accepts-schemes reference?

Not on the x402 v2 success path: when the pay command returns an authorization_header, the skill replays it directly per Step A6 and loads no reference. It loads references/accepts-schemes.md only on a failure or legacy v1 path, where an output field (permit2Authorization, sessionCert, or authorization) indicates the scheme.

All Files

8 files
_shared/preflight.md5.1 KB
View
references/charge.md4.1 KB
View
references/a2a_charge.md10.3 KB
View
references/multi-scheme.md5.7 KB
View
references/session.md16.8 KB
View
_shared/amount-display.md0.8 KB
View
references/accepts-schemes.md7.7 KB
View
SKILL.md19.7 KB
View

Install okx-agent-payments-protocol

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill