x402 Service Terms
Last updated: September 2026
Scope: the 7 pay-per-use x402 API endpoints under /api/x402/* (signing, sealing, provenance, decision notarization, CBOM sealing, agent-identity verification, and proof verification). This is separate from the general FractalAI Terms of Service governing the FRAC token, staking, and the wider platform — those do not by themselves describe what a payer of these specific API calls is buying. This page does.
1. What you are paying for
Each endpoint, on receipt of a valid x402 payment (USDC on Base), returns a cryptographic proof — an ML-DSA-65 (NIST FIPS 204, Dilithium-3) signature over a specific, documented message. Full technical detail, current pricing, and machine- readable schemas for every endpoint are published live at /.well-known/x402.json. Each route also states its own “honest scope” in its response — read it before relying on the proof for anything consequential.
This is the entire product: a signature over your data, issued in exchange for payment. It is not a review of your data's truthfulness or a guarantee about anything you or a third party do with the signed record.
2. What is cryptographically guaranteed
A valid response proves: (a) the exact bytes you sent (or their hash) were signed by FractalAI's receipt-signing key at the stated time, and (b) the record has not been altered since. Anyone can verify this offline, without trusting our servers or our TLS certificate, using only the public key published and signed at /.well-known/x402-receipt-keys and the open-source verifier (@fractalai/pqc-agent-receipts-conformance). This is the part we do not ask you to take on trust — check it yourself.
3. What is NOT guaranteed
- Not a truth or quality claim. A signature over your declared input proves you declared it — it does not verify the input was accurate, lawful, or fit for any purpose. See each endpoint's “honest scope” for exactly what is and is not attested.
- Not a specific numeric uptime commitment. This is an early-stage, pre-pilot service. We publish real, live, unedited uptime and incident data at /status (rolling 7-day history) and root-caused writeups of what has actually gone wrong at /postmortems. We would rather you look at that real track record than trust a number we have not yet earned the right to promise.
- Rate limits apply. Each endpoint enforces a published per-IP rate limit (currently 30 requests/minute) and a request-size cap, to keep the service available for everyone. A request rejected for exceeding either is not charged.
- On-chain anchoring status varies by endpoint and is stated per response. Where a response says an anchor is pending or not yet live, treat the served signature as TLS-plus-key-directory trust until that changes — not as independently anchored on a public chain. We say so explicitly rather than let the distinction blur.
4. Payment, refunds, and failed calls
Payment is atomic with the response: our anti-replay ledger reserves your payment authorization before verifying it and only marks it consumed after a response is actually returned. If verification or settlement fails after your funds moved on-chain, the reservation is released so the same payment can be retried — you are not charged twice for one proof, and a failed attempt should not consume your payment. If you believe you were charged without receiving a valid, verifiable signature, contact us at helloinvestor@fractalai.net.co with the transaction hash; we will investigate and, if our system is at fault, refund the payment.
5. Limitation of liability
These endpoints are provided on an “as is” and “as available” basis, without warranties of any kind beyond the specific cryptographic guarantee in Section 2. To the maximum extent permitted by law, FractalAI's aggregate liability for any claim arising from use of these endpoints is limited to the amount you paid for the specific call giving rise to the claim. We are not liable for indirect, incidental, or consequential damages, including decisions made by you or a third party in reliance on a signed record's content (as opposed to its cryptographic authenticity, which Section 2 covers).
6. Changes to these terms
We may update this page as the service matures — in particular, we expect the uptime and anchoring caveats in Section 3 to get stronger, not weaker, as the track record in /status and /postmortems grows. Material changes will update the date above.
7. Contact
Questions about these terms, a specific call, or a dispute: helloinvestor@fractalai.net.co.