Thirty years of 402
HTTP reserved a status code for payment in 1997 and then left it empty. The history of why nobody used it is a history of what a payment needed to cost before a request could carry one.
Open the HTTP/1.1 specification from 1997 and scroll to the 4xx codes. Between 401 Unauthorized and 403 Forbidden sits 402 Payment Required, with the shortest definition in the document: "This code is reserved for future use."
It stayed that way through every revision. The 2014 rewrite kept the sentence. The 2022 rewrite kept it again. For most of the web's life, 402 has been the status code that browsers know the name of and nothing knows what to do with.
The people who put it there were not being careless. They could see that a network of documents would need a way to charge for some of them, and that the natural place to say so was in the response to the request. What they could not do was specify how the payment would happen, because in 1997 there was no way to move a small amount of money between two strangers inside the time it takes to serve a page.
The economics that kept it empty
A card transaction has a fixed cost. Interchange, network fees, and the processor's margin add up to something like thirty cents plus a percentage. A payment of ten cents on those rails loses money for everyone involved. So the web built around the constraint: bundle content into subscriptions large enough to absorb the fee, or give it away and sell attention instead.
Micropayments were proposed repeatedly. Digital cash schemes in the nineties, the W3C's own Micropayment Markup working group, a wave of startups in the 2000s that each promised to make a cent-sized payment viable. Every one ran into the same two walls. Settlement was expensive, because it ultimately ran through the banking system. And onboarding was worse, because each scheme needed both reader and publisher to hold an account with it before the first payment could happen.
The second wall is the one people forget. Even if a payment costs nothing to settle, a system where the reader has to sign up before reading is a login wall with extra steps. The promise of 402 was that the payment would be part of the request. That requires a form of money that a client can spend without a prior relationship with the server or with any intermediary the server chose.
What changed
Two things, about a decade apart.
Public blockchains made it possible to move value between two parties who share nothing but a network. That solved the relationship problem. The first generation did not solve the cost problem, because a transfer on Ethereum's main network could cost dollars, and the value being moved was volatile.
Stablecoins on low-cost networks solved the rest. A dollar-pegged token on a chain where a transfer costs a fraction of a cent and confirms in seconds is, for the first time, money that fits inside an HTTP request. The amount is stable enough to price a page. The fee is small enough that a ten-cent payment is still mostly ten cents. And the standards around those tokens, particularly the authorisation scheme that lets a holder sign a transfer for someone else to submit, mean a client can pay without holding anything but a key.
x402 is the protocol that finally puts something behind the reserved sentence. A 402 with a header describing acceptable payments, a retry with a signature, a receipt on the way back. The structure is what the 1997 authors would have written if they had had a way to fill in the middle.
What is still open
Filling in 402 answers "how does a request pay". It does not answer the questions that grew up around it while it was empty. Who is paying, in the sense a publisher cares about? What does a reader who has paid a hundred times deserve that a first-time reader does not? How does a refund work when there is no account to credit?
Those questions used to be handled by the relationship that the subscription created. With per-request payment there is no relationship by default, and the industry is now working out which parts of it are worth rebuilding on top of the payment, and which were only ever there because the payment could not stand on its own.
The rest of this paper covers that work. But it starts here, with a status code that waited thirty years for money to get cheap enough to use it.