xAPGX Protocol Agent Payment GatewayTESTNET · NO REAL FUNDS

Security

Policy enforcement before settlement

XAPG separates authorization, verification, and settlement so an institution can reject non-compliant payment intent before any transaction is submitted.

Authorization integrity

EIP-712 and ERC-3009 bind the payer, recipient, USDC amount, validity window, and nonce to a cryptographic signature. XAPG verifies the recovered signer and rejects expired, replayed, malformed, or mismatched authorizations.

Policy controls

  • Public HTTPS merchant checks and exact x402 challenge binding
  • Per-payment limits plus wallet-enforced Agent budgets
  • Chain ID, asset contract, payTo, amount, and decimal validation
  • USDC balance checks and pre-settlement transaction simulation
  • No fallback from x402 to an unstructured direct transfer
  • Idempotent references and auditable transaction hashes

Key isolation

The LLM receives payment capabilities and policy results, never wallet private keys. Production deployments should isolate signing in HSM or MPC infrastructure, apply least-privilege service identities, and authenticate /verify and /settle as backend-only operations.

Testnet and production boundary

This service is isolated on Base Sepolia and does not process real funds.