All news

Your Agent Can Now Pay for Compute

June 5, 2026

For the last few issues we’ve been working one idea from different angles: don’t trust that something stayed private or stayed in bounds — prove it. First, we made the case for protecting data while it’s being computed on; then for governing what an autonomous agent is allowed to do. This week brings the third thing an agent needs to act on its own: the ability to spend.

As of today, we’re excited to announce that OpenMatter now supports x402 payments on Datavizor, enabling agents to directly buy compute on our testnet. And that’s just the beginning. Coming soon: using ZK proofs to authorize agent actions and sharding keys across nodes for robust wallet protection. But for now, let’s take a look at the foundation before we give you a glimpse into the future.



Subscribe now


Your Agent Can Now Pay for Compute

OpenMatter Is Shipping the Payment Rail First, the Proofs Are Next

x402 enables agentic payments, no human required

There’s a step almost every agent demo quietly skips: the moment money actually has to move, a human still clicks approve. We’ve automated the reasoning and left the spending manual. As of this week, that gap starts to close, as we now support x402 payments on Datavizor.

x402 revives a status code that’s sat dormant in the HTTP spec since the beginning: 402, Payment Required. It makes payment part of a request instead of a separate, out-of-band ceremony. An agent calls an endpoint; the response says, in effect, pay first; the agent pays inline and the call completes. No invoices, no pre-funded accounts, no humans — just machine-to-machine settlement at agentic speed.

Concretely, what ships now is the plumbing: an agent can use x402 to buy compute on our testnet, paying per request as it works. It’s a small, real thing — the primitive you’ve been faking with a human in the loop. And it’s the foundation for what comes next.

What Comes Next

We’re shipping the rail first on purpose. Moving the money is the easy part; the harder questions live on top of it, and two key primitives are already on our roadmap as additional security layers.

The first is authorization. Today x402 moves the money. Next, we’ll gate it, so every payment is fronted by a ZK proof that the agent was allowed to spend this, on this, right now. The goal is verifiable authorization, not a behavioral risk score that approves whatever looks normal and waves a novel action through.

The second is custody. A funded wallet sitting on a single host is a honeypot; one breach drains it. We’re working toward distributed key custody, where an agent’s signing key is never assembled whole in any one place. Instead, the key is split up across independent nodes, so breaching a single node yields nothing worth having.

Today your agent can pay. Next, it’ll be able to prove it was allowed to, all while keeping its treasury secure.

— The OpenMatter Team


If you know someone who would benefit from reading this article, please share it:

Share


Datavizor, our command layer for masked compute, is in beta. If you’re building AI systems where privacy and compliance aren’t optional, come take a look.


Industry Updates

The Approval Gap

If you want evidence we’re building the right next layer, the ecosystem just supplied it. x402 payment volume fell roughly 77% from its November 2025 peak of $5.15 million to $1.19 million by May 2026 — but transaction counts barely flinched by comparison: at 2.89 million in May, still down just 41% from their December peak, at an average of just $0.52 each (Artemis data, via CryptoSlate). Agents are making huge numbers of tiny payments for APIs, data, and compute, and the bottleneck isn’t moving the money — it’s approving it. The math: a 5-to-15-second manual confirmation on each of those transactions adds up to 4,000–12,000 human-hours a month, at $0.03–$0.10 per click — material on a $0.52 payment, absurd on a $0.01 call.

Which is why every serious team building agentic payment infrastructure is now converging on the same missing piece: authorization. Google donated its AP2 framework to the FIDO Alliance in April, built around cryptographically signed “mandates,” and Fireblocks joined the Linux Foundation’s x402 Foundation last month with an extension adding spend governance and request integrity to the protocol. Moving the money is no longer the hard part. Proving an agent was cleared to spend is — and it’s exactly the layer we’re building next.

Robinhood MCP Integration Grants AI Agents Autonomous Financial Trading Powers

This is the clearest production example yet of the compliance-capability gap in agentic AI. Robinhood has deployed real financial authority to AI systems without deterministic intent verification or cryptographic action signing. Spending caps and ‘optional’ approvals are policy controls, not architectural constraints. An adversary who can inject into a news article or analyst note has a path to unauthorized trades. The second-order problem: Robinhood is a regulated broker-dealer, which means SEC Rule 17a-4 record-keeping, FINRA supervision requirements, and best-execution obligations now apply to whatever the agent does. None of those compliance surfaces were designed for non-human actors operating at machine speed. Watch for the first regulatory inquiry into an agent-executed trade that violated suitability or best-execution rules — that’s where the legal framework will get stress-tested.


OpenMatter is building the verifiable trust layer that enables AI agents to securely collaborate on sensitive data sets. If you’re in a regulated industry and need a better way to prove that your data is secure, contact Chris to learn how masked compute can help.


Share OpenMatter Network