For builders who already hold USDC on Base

Sell a file for USDC from one Cloudflare Worker.

A tested Worker template for selling a digital download: an x402 v2 402 challenge, a human checkout with order codes, one-time claims in D1 and a written threat model. No server, payment processor or facilitator keys.

ZIP · 14 files · Workers free plan + D1 · one-time payment

Free starters exist. Here’s what this adds.

Cloudflare’s x402-proxy-template and the x402 seller quickstart are free. Use them if a facilitator flow is all you need.

Free startersx402 Seller Kit
Return an x402 v2 402 challengeYesYes, with Bazaar discovery metadata
Agents auto-pay through a facilitatorYes, with a facilitator configuredNo. Agents use /order and /claim instead
Human checkoutSome include a browser-wallet paywall; exchange withdrawals can’t sign itAny wallet or exchange: order → send USDC → paste hash
Safe if someone copies a public tx hashNot relevant (facilitator flow)Yes: secret order code + unique exact amount
One-time claimsNot relevantYes, atomic in D1, re-download up to 5×
Threat model, buyer copy, directory listNoYes
PriceFree$29 USDC

What’s in the ZIP

x402-seller-kit-v1/ ├── README.md quickstart, how a sale works, honest limits ├── docs/ │ ├── HOW-IT-WORKS.md threat model: replay, front-running, fake token… │ ├── PLAYBOOK.md free x402/agent directories tested Oct 2026 │ └── BUYER-COPY.md "how to pay with USDC on Base" page text ├── template/ │ ├── worker.js storefront, /order, /claim, x402 402, llms.txt │ ├── orders.js order + claim engine │ ├── config.js the only file you must edit │ ├── schema.sql D1: orders, claims, rate │ ├── wrangler.toml.example │ ├── product.b64.js placeholder for your file │ └── scripts/ │ ├── embed-file.py embed your file │ └── smoke-test.sh 10 checks against your live store ├── LICENSE.md └── CHANGELOG.md

Threat model, row by row

From docs/HOW-IT-WORKS.md:

  • Replay: each tx hash is a primary key; inserts must change exactly one row.
  • Front-running: a secret order code plus a unique exact amount, and amount slots aren’t reused while older windows are open.
  • Fake “USDC”: only logs from the real USDC contract count.
  • Old or split payments: one transfer, exact amount, mined after the order.
  • RPC down: 5 fallbacks, then a “try again”, never a false “not paid”.
See the full README and file list

Buy the x402 Seller Kit · $29

You pay in USDC on Base, using the same checkout the kit gives you. New to it? How to pay, step by step.

Step 1. Get your order. It gives you an exact amount, about 29 USDC plus a few thousandths of a cent, so the store can tell your payment apart from anyone else's.

Step 3. Paste your transaction hash. Your order code fills in automatically on this device. Keep it: it's your receipt.

USDC on Base (chain 8453), contract 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913. Keep your order code and transaction hash as your receipt.

Questions

Aren’t there free x402 starters?

Yes. Cloudflare’s x402-proxy template and the x402/Coinbase seller quickstarts are free and good if you want agents to pay through a facilitator. This kit is for selling a file to humans and agents today without a facilitator. It includes a front-running-safe order flow, one-time claims, a threat model and a tested directory list.

What do I need?

A Cloudflare account (the free plan works), a Base address to receive USDC, Node.js for wrangler, and a file under about 5 MB (bigger files can be served from R2).

Do I need a facilitator or API keys?

No. Payments are checked by reading the transaction receipt from public Base RPCs. If you later want x402 auto-settlement for agents, you can add a facilitator alongside the order flow.

How does it stop someone claiming a buyer’s payment?

Each buyer first gets an order with a secret 128-bit code and a unique exact amount, such as 29.004271 USDC. A claim needs both the code and a transfer of exactly that amount, mined inside the order’s window, and each transaction hash works once.

What if a buyer’s exchange takes its fee out of the amount?

Then the amount won’t match exactly and the buyer is told to email you with the order code and hash. The buyer copy in the kit explains how to avoid this. It is the main trade-off of exact-amount matching.

Is it tested?

The order and claim engine runs this store and Solo Newsletter OS. Before release it was tested locally against real Base mainnet transactions, with the store address set to each transfer’s recipient. The tests covered a valid payment, replay, wrong amount, a transaction older than the order, a transfer to another address, and rate limits. Live checks cover the 402, orders, fake hashes and replay refusal. The kit includes a smoke-test script for your own store.

What licence do I get?

Use and modify it for as many of your own stores as you like, personal or commercial. You may not resell or redistribute the kit itself.

Refunds?

Payments are on-chain and final, so look at the free preview first. If the download fails, submit the same order code and hash again. If you still have a problem, email soloearn@agentmail.to.

Built with this kit: Solo Newsletter OS, a $39 template pack for solo newsletter writers, sold with the same order flow.

See it live

For agents

POST https://x402-seller-kit.soloearn.workers.dev/order returns an orderId and an exact amount. Send it in USDC on Base to the payTo address, then POST https://x402-seller-kit.soloearn.workers.dev/claim with {"orderId","txHash"}. GET /download returns the x402 v2 terms; facilitator settlement isn’t enabled. See llms.txt.