๐Ÿ“… Historical page. This content reflects minia2a as of its publication date and is kept for the record. Current model: x402 pay-per-call in USDC on Base only, 5 free trial calls per signed wallet, no credits and no top-up rail. โ†’ See current

The 402 Beta Is Open. The Roadmap Says "Discovery."

September 30, 2026

Cloudflare's Monetization Gateway left the waitlist today. The changelog entry is dated September 30, 2026 and reads: "Monetization Gateway is now available in closed beta." The product was announced on July 1, 2026 with a waitlist. Between those two dates it went from a description to four named customers running it in production.

We track this because the gateway is built on the same primitives we are: HTTP 402 Payment Required, the x402 protocol, and a stablecoin settlement rail. Here is what actually shipped, what it means for anyone building on x402, and the one line in the announcement that we think matters most โ€” including a measurement problem we can show you from our own catalog.

What shipped, precisely

None of that is surprising on its own. Per-request payment at the CDN edge has been the obvious direction since 402 stopped being a joke status code. What is new is that it is now a product with a customer list rather than a demo.

The line that matters

At the end, where the post lists what comes next, it says this:

"we plan to help sellers make their services discoverable to agents"

That is a roadmap item, not a shipped feature โ€” the beta does not include it. Read the July announcement next to it and the delta is visible: in July the framing was reach as an aspiration ("the smallest new API can reach the same buyers, on the same terms, as the largest company on the web"). Today it is a named item on a roadmap, with a beta behind it and named customers in front of it.

Why this is the interesting half. Accepting a payment and finding something worth paying for are different problems, and only the first one gets easier when it moves into the edge. Once settlement is a commodity โ€” and it is heading there fast, across several independent implementations โ€” the buyer's remaining cost is entirely the second problem: out of everything that will accept my money, which endpoint do I call, what will it actually cost me, and is it still alive?

What a discovery layer has to get right โ€” measured, not theorized

We run a pay-per-call catalog of x402 endpoints, so we get to watch these failure modes from the inside. Three of them, all from the last two weeks, all specific:

1. A published field that is not what it looks like

Our 402 challenge carries a discovery extension field whose value is an internal service identifier. It is a bare token like x402-time โ€” not a path, and in fact not a valid x402 route template, which must begin with a slash. Our own challenge-validation guard was green, because it checks the payment terms: amount, payee, signature domain. Nothing checked whether the discovery extension was well-formed as a discovery extension.

A third-party health monitor read that field and did the reasonable thing: joined it onto our published URL. Every request landed on a path that is not a route, and our gateway answered 404. Over the window we measured, 765 of that monitor's 4,067 requests landed on 153 distinct paths with a shape that named its own cause:

/x402/<endpoint>/<the same identifier again>

The endpoints were never down. Every one of them answers 402 with valid payment terms. The monitor was recording a failure that existed only in the joining.

2. Prices in a catalog are snapshots

We audit the prices advertised for our listings in a third-party discovery directory against what our live endpoints actually charge. Of 154 listings, 20 advertise a price the endpoint no longer charges โ€” every one of them an under-quote rather than an over-quote, the largest by a factor of 300. The directory rows are written at settlement time and never expire, so a price change on the seller's side never propagates back. An agent that budgets from the catalog and pays at the endpoint gets a different number than it planned for.

3. "Is it live?" is not answerable from a catalog

One of our listings is an endpoint we delisted. Its row still exists in the third-party directory โ€” there is no withdrawal path for a settle-time snapshot โ€” and the endpoint itself now answers 404 with no payment challenge. But nothing in the directory row says that. A buyer reading the catalog sees a live-looking offer; a buyer calling the endpoint gets nothing to pay.

Discoverable โ‰  payable โ‰  live
Three properties, three different sources of truth, and only the third one changes without anyone announcing it. A catalog that does not separate them will be wrong in a way that costs the buyer a failed call โ€” or a payment against terms that no longer exist.

What we are doing about it

Not launching a competing settlement layer โ€” settlement is going to be a race to near-zero either way, and there is no defensible position in winning it. The work on our side is all in making the discovery facts checkable rather than asserted:

If you are a seller who just turned on per-request pricing at the edge, the useful question is not whether the gateway can take the money โ€” it is whether an agent that has never heard of you can find you, price you, and tell that you are still up. That part is still open.


Sources: Cloudflare's Monetization Gateway closed-beta changelog (September 30, 2026) and the original Monetization Gateway announcement (July 1, 2026). Request counts, path shapes, listing counts, and price-drift figures are measured from our own gateway logs and our own catalog audits, not estimated.

โ† More posts ยท minia2a.uk