Legal
Disclaimer
x402card is an open-source hackathon project running in a sandbox. No real money moves, and nothing here is a financial product.
- Sandbox only. Cards, balances, payments and approvals run on a card program's test environment. Amounts shown are not real funds and can't be withdrawn, spent or redeemed.
- Not a card issuer, bank or payment provider. x402card is a naming and policy layer. It doesn't issue cards, hold funds, transmit money or extend credit. Any real card would be issued by a licensed card program under that program's own terms.
- ENS records are public. Names under x402card.eth resolve on Ethereum mainnet, and anyone can read their spend-policy records. They never contain card numbers, CVCs or card IDs.
- Not advice. Nothing on this site is financial, legal, tax or security advice.
- No affiliation. x402card isn't affiliated with, endorsed by or sponsored by Airwallex, ENS Labs, Safe, Cloudflare, Visa, Mastercard, Coinbase, Anthropic or any other company mentioned on this site or in its code. Their names and marks belong to their owners and are used only to describe compatibility.
- Software as is. The code is provided under the MIT License, without warranty. Smart contracts and gateways can have bugs; review the source before relying on it.
Privacy
This site has no accounts, cookies, analytics or ad trackers. Here is everything that touches data.
When you visit this site
- Hosting. The site is static files on IPFS, usually served through a gateway such as eth.limo. The gateway you use receives your IP address and request details under its own policy.
- Fonts. Pages load the Geist fonts from Google Fonts, so Google receives your IP address and browser details.
- Live data. The home page asks the x402card API (a Cloudflare Worker at x402card.dmpay.workers.dev) for public card records and the public activity feed. Cloudflare processes these requests, including your IP address, under its own policy. We don't store your IP address or build a profile of you.
- Approvals page. If you sign in, your admin token is kept only in this browser tab's session storage, is sent only to the x402card API, and is cleared when you close the tab or sign out.
What the x402card service stores
- Public policy records for each name (limits, currencies, merchant categories, status, approver). These are public by design and can be read by anyone over ENS.
- Activity events for the public feed: payments, blocks, top-ups, escalations, approvals and freezes, with the merchant name, amount and the name of the person who decided an approval. The most recent 50 per card are kept.
- Approval requests, including the purpose an agent gave.
- Private card references (card program IDs, last four digits), never served publicly.
- Agent tokens, stored only as one-way hashes.
Don't put personal information in a card's approver field, a funding purpose or a merchant name: some of it appears in the public feed or in public ENS records, and anything written to a blockchain can't be deleted.
Card programs
Cards are created through a card program (in this demo, the Airwallex sandbox). The cardholder details x402card sends are placeholders, not personal data. A real deployment would share cardholder data with the card program, which processes it under its own privacy policy.
Questions and requests
Open an issue on GitHub to ask what is stored about a name, or to have off-chain records or feed events removed. On-chain data can't be removed.
Terms of use
By using this site, the x402card API or the MCP server, you agree to these terms.
- What this is. A demonstration of a naming and policy layer for AI agent cards, provided for evaluation, testing and development. It runs in a sandbox and may change, reset or go offline at any time without notice.
- No real payments. Don't use the service to make or receive real payments, or connect real card numbers, bank accounts or funds to it.
- Acceptable use. Don't attack, overload or scrape the service; try to get around authentication, token scopes or spend policies; impersonate others; or use it for anything unlawful. We may revoke tokens or remove names that are misused.
- Tokens. You're responsible for keeping admin and agent tokens secret. Anyone holding a token can act within its scope.
- Names. Names under x402card.eth are subnames controlled by the project. Using one doesn't give you ownership of it, and names may be reassigned or removed.
- Open source. The code is licensed under the MIT License. These terms cover the hosted demo, not your own deployments of the code.
- No warranty. The service is provided "as is" and "as available", without warranties of any kind, express or implied, including fitness for a particular purpose and non-infringement.
- Limitation of liability. To the fullest extent the law allows, the project and its contributors aren't liable for any indirect, incidental, special, consequential or punitive damages, or for any loss of data, funds or profits, arising from your use of the service.
- Third parties. Gateways, RPC providers, card programs, wallets and other third-party services are governed by their own terms.
- Changes. We may update these terms; the date at the top of this page shows the latest version. Continuing to use the service means you accept the update.