Cloudflare opened the closed beta of its Monetization Gateway on 30 September, letting domain owners charge AI agents for individual requests to APIs, MCP tools, websites and datasets. The payment does not happen in a checkout flow. It happens inside the HTTP request that asks for the resource.
Key takeaways
- Monetization Gateway entered closed beta on 30 September, covering APIs, MCP tools, sites and datasets, with payment authorisation carried inside the HTTP request via the x402 protocol.
- Transactions settle in USDC on the Base blockchain through Coinbase's x402 Facilitator, with Cloudflare handling verification, settlement, failures, retries and analytics.
- Four services already run it in production, including Cloudflare's own AI Gateway; the x402 upto scheme caps what a buyer authorises per request, but no cumulative buyer budget is documented.
How paying inside a request works
The mechanism revives HTTP 402, the Payment Required status code that has sat largely unused in the specification for decades. A buyer's agent makes a request; if the seller has marked that request as paid, the gateway answers with payment instructions rather than the resource. The agent signs an authorisation, the payment settles, and the resource is released β no redirect to a hosted checkout page and no separate payments API to integrate against.
That matters for software that issues requests at machine volume. An agent calling a search index a thousand times cannot practically pause for a human to complete a card form, which is the structural reason agent commerce has so far been bolted onto human payment rails. Cloudflare is betting the transaction belongs in the protocol instead.
Settlement is explicitly on-chain. According to Cloudflare's announcement, payments clear in USDC, a dollar-pegged stablecoin, on the Base network, routed through Coinbase's x402 Facilitator. Cloudflare positions itself as the layer that absorbs the operational mess β verifying payments, settling them, handling failures and retries, and reporting analytics back to the seller.
Sellers get fine-grained pricing control
The seller-side controls are the most developed part of the launch. Operators define pricing rules that match on components of the request β URL, headers, query parameters β and pick a pricing scheme per rule. There is also an origin-controlled option in which the gateway asks the seller's own origin what a given request should cost, which allows prices that depend on work the gateway cannot see in advance.
The four production users illustrate the range. Cloudflare's AI Gateway charges per token of inference. Ceramic.ai uses a fixed price per search query. Stocktwits bills per request for individual market signals. API2PDF charges variably according to the compute and bandwidth a document generation consumes, quoting agents the maximum a single request could cost and settling only the actual consumption.
What the buyer can and cannot cap
A single request is bounded. Under the x402 upto scheme Cloudflare uses for variable pricing, the buyer signs an authorisation for a maximum amount and the origin reports the actual charge at settlement, so no one request can bill more than the agent already agreed to. Cloudflare's buyer-side documentation adds a second brake: its Agents SDK x402 client takes an onPaymentRequired callback for a human-in-the-loop confirmation flow, which a developer sets to null to let the agent pay unattended.
What no page documents is the cumulative control β a budget, a per-session ceiling, or a spend limit across many requests. The gateway's own documentation set is six pages, all seller-side, and the buyer material sits in a separate product's docs. In a model where prices can be computed at the origin per request and an agent may issue thousands of them, that is where costs escape: each payment is individually bounded, the running total is not.
Access is also tightly gated for now. Per Cloudflare's eligibility rules, buyers and sellers must both be based in the United States. Sellers need an account older than 60 days, a credit card on file, a verified email address, passing account-level security checks and acceptance of the service-specific terms. The zone being monetised must be proxied through Cloudflare, be more than 30 days old, and pass zone-level security checks.
Outlook
This is the commercial half of a strategy Cloudflare has been assembling in public, alongside efforts such as its push to rebuild the web's client layer for agents. Crawl-blocking told AI companies they could not take content for free; a per-request paywall tells them what taking it costs. The open questions are whether agent operators will accept stablecoin settlement as a dependency, and whether cumulative budget controls arrive before the first expensive incident. Until the beta widens beyond US participants, neither will be answered at scale.
FAQ
What is x402 and how does it differ from a normal payment API?
x402 carries payment authorisation inside the HTTP request flow, using the HTTP 402 Payment Required response to return payment instructions instead of the resource. There is no redirect to a checkout page and no separate payment API call, so an automated client can settle and retrieve in one exchange.
Can a buyer limit what its agent spends?
Per request, yes. The x402 upto scheme has the buyer sign an authorisation for a maximum amount, and Cloudflare's Agents SDK client exposes a confirmation callback so a human can approve each payment. Cloudflare does not document a cumulative budget or per-session spending ceiling across many requests.
Who can join the closed beta?
Buyers and sellers must be based in the United States. Sellers additionally need an account more than 60 days old, a credit card on file, a verified email address, and must pass Cloudflare account-level security checks. The monetised zone must be proxied through Cloudflare, be older than 30 days, and pass zone-level security checks.






