Guide · x402

A procedure for keeping API keys, wallet keys, tokens, and cookies out of an agent's pr…

A procedure for keeping API keys, wallet keys, tokens, and cookies out of an agent's prompts, repos, logs, and tool outputs: inventorying and classifying secrets by owner/scope/expiry, routing agents through a broker that issues short-lived scoped capabilitie…

by Saylor Innovations Knowledge Base · verified provider · updated 2026-09-22

What it does

A procedure for keeping API keys, wallet keys, tokens, and cookies out of an agent's prompts, repos, logs, and tool outputs: inventorying and classifying secrets by owner/scope/expiry, routing agents through a broker that issues short-lived scoped capabilities instead of raw credentials, constraining scope and lifetime, redacting before serialization (not after), scanning repos/CI/runtime with canary tests, and exercising a full revoke-and-rotate incident drill rather than trusting an untested plan.

Capabilities

  • Agent Secret-Handling Guide — a 8-minute technical guide

Tags: security & opsec · advanced · secrets-management · agent-security · credential-scoping · key-rotation · leak-detection

Use with an agent

  1. Discover. Agents find this listing with GET https://bazaar.saylorinnovations.com/discovery/search?query=…, the MCP tool search_resources, or /discovery/resources.
  2. Inspect. Fetch /resources/agent-secret-handling.json for the price and payment options.
  3. Pay. Call GET https://saylorinnovations.com/api/kb?id=agent-secret-handling. The provider answers 402 with its payment requirements. An x402 client signs one of the options below and retries with PAYMENT-SIGNATURE.
  4. Execute. The provider returns 200 with the data. Agent Bazaar is not in the request path and never sees your payment.

For humans

You don't need an account or an API key; you need a wallet holding a small amount of USDC or USDT on Solana, Base, Polygon, Arbitrum One, and an x402-capable client (see the examples below). Call the endpoint unpaid first to see exactly what it asks for.

Pricing & payment

Price
$0.01 / request
Protocol
x402 v2
Auth
No account or API key. Pay per request.
Networks
Solana, Base, Polygon, Arbitrum One

x402 payment requirements

SchemeNetworkAssetAmountPay toTimeout
exactSolana
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
USDC$0.017LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7120s
exactSolana
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
USDT$0.017LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7120s
exactBase
eip155:8453
USDC$0.010xf8A376eBF123D7252cd7b66bcD77A727a4def22f120s
exactPolygon
eip155:137
USDC$0.010xf8A376eBF123D7252cd7b66bcD77A727a4def22f120s
exactArbitrum One
eip155:42161
USDC$0.010xf8A376eBF123D7252cd7b66bcD77A727a4def22f120s
accepts[] (raw JSON)
[
  {
    "scheme": "exact",
    "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
    "payTo": "7LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7",
    "asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
    "amount": "10000",
    "amountUsd": 0.01,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
    "payTo": "7LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7",
    "asset": "Es9vMFrzaCERmJfrF4H2FYD4KCoNkY11McCe8BenwNYB",
    "amount": "10000",
    "amountUsd": 0.01,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "eip155:8453",
    "payTo": "0xf8A376eBF123D7252cd7b66bcD77A727a4def22f",
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "amount": "10000",
    "amountUsd": 0.01,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "eip155:137",
    "payTo": "0xf8A376eBF123D7252cd7b66bcD77A727a4def22f",
    "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
    "amount": "10000",
    "amountUsd": 0.01,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "eip155:42161",
    "payTo": "0xf8A376eBF123D7252cd7b66bcD77A727a4def22f",
    "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
    "amount": "10000",
    "amountUsd": 0.01,
    "maxTimeoutSeconds": 120
  }
]

Examples

curl
curl "https://saylorinnovations.com/api/kb?id=agent-secret-handling"
# -> 402 Payment Required, accepts[] lists how to pay
# retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paid
JavaScript
const res = await fetch("https://saylorinnovations.com/api/kb?id=agent-secret-handling");
if (res.status === 402) {
  const { accepts } = await res.json();
  // pay one of accepts[] via an x402 client, then retry with the payment header
}
Python
import httpx
res = httpx.get("https://saylorinnovations.com/api/kb?id=agent-secret-handling")
if res.status_code == 402:
    accepts = res.json()["accepts"]
    # pay one of accepts[] via an x402 client, then retry with the payment header

Details

Provider
Saylor Innovations Knowledge Base
Endpoint
https://saylorinnovations.com/api/kb?id=agent-secret-handling
License
LicenseRef-Saylor-Agent-Use-1.0
Machine-readable
/resources/agent-secret-handling.json