Hardening x402: PII-Safe Agentic Payments via Pre-Execution Metadata Filtering

Fuente: arXiv
Saved in:
Bibliographic Details
Main Author: Stantchev, Vladimir
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908960039108608
author Stantchev, Vladimir
author_facet Stantchev, Vladimir
contents AI agents that pay for resources via the x402 protocol embed payment metadata - resource URLs, descriptions, and reason strings - in every HTTP payment request. This metadata is transmitted to the payment server and to the centralised facilitator API before any on-chain settlement occurs; neither party is typically bound by a data processing agreement. We present presidio-hardened-x402, the first open-source middleware that intercepts x402 payment requests before transmission to detect and redact personally identifiable information (PII), enforce declarative spending policies, and block duplicate replay attempts. To evaluate the PII filter, we construct a labeled synthetic corpus of 2,000 x402 metadata triples spanning seven use-case categories, and run a 42-configuration precision/recall sweep across two detection modes (regex, NLP) and five confidence thresholds. The recommended configuration (mode=nlp, min_score=0.4, all entity types) achieves micro-F1 = 0.894 with precision 0.972, at a p99 latency of 5.73ms - well within the 50ms overhead budget. The middleware, corpus, and all experiment code are publicly available at https://github.com/presidio-v/presidio-hardened-x402.
format Preprint
id arxiv_https___arxiv_org_abs_2604_11430
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Hardening x402: PII-Safe Agentic Payments via Pre-Execution Metadata Filtering
Stantchev, Vladimir
Cryptography and Security
Artificial Intelligence
Computers and Society
68P27, 68M25, 68T50
K.6.5; I.2.11; H.3.4
AI agents that pay for resources via the x402 protocol embed payment metadata - resource URLs, descriptions, and reason strings - in every HTTP payment request. This metadata is transmitted to the payment server and to the centralised facilitator API before any on-chain settlement occurs; neither party is typically bound by a data processing agreement. We present presidio-hardened-x402, the first open-source middleware that intercepts x402 payment requests before transmission to detect and redact personally identifiable information (PII), enforce declarative spending policies, and block duplicate replay attempts. To evaluate the PII filter, we construct a labeled synthetic corpus of 2,000 x402 metadata triples spanning seven use-case categories, and run a 42-configuration precision/recall sweep across two detection modes (regex, NLP) and five confidence thresholds. The recommended configuration (mode=nlp, min_score=0.4, all entity types) achieves micro-F1 = 0.894 with precision 0.972, at a p99 latency of 5.73ms - well within the 50ms overhead budget. The middleware, corpus, and all experiment code are publicly available at https://github.com/presidio-v/presidio-hardened-x402.
title Hardening x402: PII-Safe Agentic Payments via Pre-Execution Metadata Filtering
topic Cryptography and Security
Artificial Intelligence
Computers and Society
68P27, 68M25, 68T50
K.6.5; I.2.11; H.3.4
url https://arxiv.org/abs/2604.11430