Fund an agent by name. Never handle a card number.
x402 Card issues virtual cards to AI agents, addressed by ENS name. Policy lives in text records. Humans approve the exceptions.
A name is the whole interface.
Type an ENS name and a virtual card is issued against it. The 16-digit number exists, but your agent never sees it. It pays by name.
Limits are just text records.
Spend rules are stored on the name itself and served by a signed ENS gateway. Change a record and the card’s controls follow. No dashboard, no redeploy.
In-policy charges clear. The rest bounce.
Every authorization is checked against the card’s controls in real time. A decline tells the agent exactly which rule it hit, so it can adapt instead of retrying.
The agent asks. A human says yes.
When an agent asks for more than its policy allows, the request pauses. The approval is bound to that exact name, amount and currency. Approve once; the allowance and the ENS record update together.
Anomaly in. Card frozen.
Bursts of authorizations, repeated blocked merchants. The engine freezes the card and writes the status to ENS, so every resolver sees it at once. Only a human can unfreeze.
Every agent, every charge, by name.
One feed across your fleet. Declines carry their rule, holds wait for a human, freezes show up the moment they happen.
Showing sample events. Real sandbox events appear here as agents use their cards.
Real names. Real resolver. Sandbox money.
*.x402card.eth resolves on Ethereum mainnet through an ENSIP-10 offchain resolver. Cards and charges run on the Airwallex sandbox. Agents connect over MCP and never see a card number or an API key.
OffchainResolver
Every lookup reverts with an EIP-3668 OffchainLookup. The contract checks the gateway’s signature before returning a record.
0xf11eb8f6…792a0 ↗Signed CCIP-Read
A Cloudflare Worker answers text() lookups from the card’s policy and signs each answer for five minutes. Card numbers and IDs are never stored in records.
x402card.dmpay.workers.dev/gatewayFive tools, one token per card
issue_card, get_card, request_funding, freeze, list_transactions. An agent’s token only works for its own name.
// MCP client config { "x402card": { "type": "http", "url": "https://x402card.dmpay.workers.dev/mcp", "headers": { "Authorization": "Bearer x4c_…" } } }
Give your agent a name, not a number.
Pick a name, set three records, and it can pay. Takes about a minute in the sandbox.