AcqPath Rights Gateway

RSL DECLARATIONS · SIGNED EVIDENCE · HTTP X402

Stock x402 marketplace Rights Preflight

Fresh Rights Preflight at 0.02 USDC on Base with unmodified official TS/Python x402 buyers. Separate first-use binding model; no SIWX.

Choose the right security contract

SUPPORTED SECURE MODE: tested official TypeScript/Node x402 2.25.0 and Python x402 2.22.0 with the AcqPath SIWX adapter on /v1/rights/preflight; unchanged signer and random nonce, recommended when payer-signed request binding is required. SUPPORTED STOCK WIRE MODE: the same official stock clients without SIWX, custom nonce, signer or buyer hook on /v1/rights/preflight/x402, fresh only, 0.02 USDC. Stock binds one request atomically at first valid use; it does not sign the POST body in advance. Generic zero-config compatibility outside this fixed stock endpoint, stock SIWX-only hooks, Payments MCP and generic paid proxies remain NOT CLAIMED. Independent external MAINNET PAID E2E remains UNVERIFIED.

The secure SIWX route remains recommended for callers requiring payer-signed body binding. Stock mode is one authorization for one fixed fresh Preflight execution; deep, Gate and Revalidation remain on their existing secure integrations. No verifiable declaration after authorized observation means no settlement; that authorization stays bound to its attempted input.

Exact production request

POST https://api.getacqpath.com/v1/rights/preflight/x402 with Content-Type: application/json. This valid unpaid POST returns a 402 without source work or order creation. The fee is 20000 micro-USDC (0.02 USDC), Base mainnet eip155:8453, current Base USDC and the existing AcqPath recipient.

{
  "resource": "https://rslstandard.org/",
  "purpose": "ai-input",
  "max_total_micro": "20000"
}

Recovery and limits

An EIP-3009 signature does not sign the arbitrary POST body. Keep the signed request private before transmission. The first valid use atomically binds it to the normalized input and fixed SKU; identical signed retries recover, changed input rejects. A leaked authorization can be raced before first use.

Persist the exact outgoing body and PAYMENT-SIGNATURE in private durable HTTP retry infrastructure. The simple stock client examples do not install a durable recovery store. Do not invoke a payment wrapper again to recover without the original signed state: it may create another purchase. UNCONFIRMED requires operator reconciliation; no second settlement is automatically attempted.

Verify report evidence, delivery proof and authenticated receipt against AcqPath public DID keys and expected input/payment terms. HTTP 200 alone is not sufficient. UNKNOWN and LICENSE_REQUIRED do not grant ingestion rights.

Marketplace evidence

Official TypeScript/Python stock wire flow and Agent402 current 30-second signing behavior pass local cryptographic tests with simulated settlement. This does not prove a real marketplace settlement. Agent402 router eligibility can still require external settlement evidence. PayAPI private buyer execution remains unverified until its own attempt.

Marketplace verification is not organic demand. Independent external mainnet paid E2E remains UNVERIFIED; no owner wallet or payment is used.