fastly-x402
v0.1.0
Published
Fastly Compute x402 payment gateway.
Maintainers
Readme
x402 gateway (Fastly edition)
An x402 v2 payment gateway for the Fastly CDN that puts any HTTP origin behind a 402 Payment Required flow.
Unpaid callers receive a PAYMENT-REQUIRED challenge.
A payer signs an x402 payment, retries with PAYMENT-SIGNATURE, and the Compute app verifies with a facilitator, proxies the protected origin, settles, then returns the origin response with PAYMENT-RESPONSE.
Configuration
Create Config Store items with these keys:
| Key | Meaning |
| ------------------------------------------------- | ------------------------------------------------------------------------ |
| X402_ORIGIN_URL | Protected origin base URL, for example https://example.com. |
| X402_PAY_TO | Wallet address that receives payment. |
| X402_NETWORK | CAIP-2 network id. Default: eip155:84532 (Base Sepolia). |
| X402_ASSET | Token contract address. |
| X402_ASSET_NAME, X402_ASSET_VERSION | Token EIP-712 domain fields, e.g. USDC / 2. |
| X402_AMOUNT | Price in atomic units. Default: 10000. Alias: X402_PRICE. |
| X402_MAX_TIMEOUT | Seconds a signed payment remains valid. Default: 120. |
| X402_FACILITATOR_URL | Facilitator base URL. Default: https://www.x402.org/facilitator. |
| X402_FACILITATOR_AUTH | Optional Authorization header for facilitators that need one. |
| X402_RESOURCE_DESCRIPTION, X402_RESOURCE_MIME | Resource metadata advertised in the challenge. |
| X402_FREE_PATHS | Comma-separated path prefixes served for free. /health is always free. |
| X402_PROTECT_PATHS | If set, only these prefixes are protected; all others are free. |
| X402_ACCEPTS | JSON array of full payment requirements; overrides shorthand keys. |
Deploy to Fastly
Install dependencies and build:
npm install
npm run buildCopy fastly.example.toml to fastly.toml and adjust it before deploying:
- Set
[setup.backends.origin].addressto your origin host. - If your facilitator is not
https://x402.org/facilitator, set[setup.backends.facilitator].addressto that facilitator host. - Deploy with
fastly compute publish. The manifest declares required backends and theconfigConfig Store.
After the service exists, add or update the Config Store items above.
The backend host and Config Store X402_ORIGIN_URL must describe the same origin.
For example, if origin points at example.com:443, set X402_ORIGIN_URL=https://example.com.
A deployed gateway exposes:
curl https://YOUR-SERVICE.edgecompute.app/health
curl -i https://YOUR-SERVICE.edgecompute.app/The second command should return HTTP 402 and a PAYMENT-REQUIRED header until a client retries with a valid x402 payment.
