Nevermined Payments
LeoYeAI/openclaw-master-skills
Integrates Nevermined payment infrastructure into AI agents, MCP servers, Google A2A agents, and REST APIs.
Write code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet.
$ npx skills add coinbase/cdp-sdk --skill build-x402-client -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install coinbase/cdp-sdk build-x402-client --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/build-x402-client .claude/skills/build-x402-client && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "build-x402-client" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-client into .claude/skills/build-x402-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "build-x402-client", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-clientType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add coinbase/cdp-sdk --skill build-x402-client -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install coinbase/cdp-sdk build-x402-client --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/build-x402-client .agents/skills/build-x402-client && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "build-x402-client" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-client into .agents/skills/build-x402-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "build-x402-client", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add coinbase/cdp-sdk --skill build-x402-client -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install coinbase/cdp-sdk build-x402-client --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/build-x402-client .cursor/skills/build-x402-client && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "build-x402-client" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-client into .cursor/skills/build-x402-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "build-x402-client", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/coinbase/cdp-sdk.git --path skills/build-x402-client--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add coinbase/cdp-sdk --skill build-x402-client -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install coinbase/cdp-sdk build-x402-client --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/build-x402-client .gemini/skills/build-x402-client && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "build-x402-client" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-client into .gemini/skills/build-x402-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "build-x402-client", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install coinbase/cdp-sdk build-x402-clientInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add coinbase/cdp-sdk --skill build-x402-client -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/build-x402-client .github/skills/build-x402-client && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "build-x402-client" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-client into .github/skills/build-x402-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "build-x402-client", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add coinbase/cdp-sdk --skill build-x402-client -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install coinbase/cdp-sdk build-x402-client --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/build-x402-client .opencode/skills/build-x402-client && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "build-x402-client" agent skill from https://github.com/coinbase/cdp-sdk/tree/main/skills/build-x402-client into .opencode/skills/build-x402-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "build-x402-client", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
build-x402-clientWrite code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet.
Build X402 Client is an agent skill from coinbase/cdp-sdk. Write code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet. Covers TypeScript and Python. Use when the user wants to call a paid endpoint from their own application or agent, add x402 payments to an HTTP client, hit an API that charges per request, migrate an existing x402 client off a raw private key, or is stuck on an unexpected 402 response.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires a CDP API key and wallet secret. Node.js = 22 (TypeScript) or Python = 3.10.
It sits in Backend & APIs, covering REST APIs. It works with x402, Python and TypeScript. The repository describes itself as: Client libraries for managing EVM and Solana wallets while relying on CDP to secure private keys. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 993de49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and python).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
x402.vercel.appAlso links to:
docs.cdp.coinbase.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CDP_WALLET_SECRETCDP_API_KEY_IDCDP_API_KEY_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires a CDP API key and wallet secret. Node.js >= 22 (TypeScript) or Python >= 3.10.
From compatibility in the SKILL.md frontmatter.
Build X402 Client loads about 3k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 1,120 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from coinbase/cdp-sdk at commit 993de49, republished under its MIT licence (© coinbase). 1,120 words, ~2,995 tokens.
.claude/skills/build-x402-client/SKILL.md (or your agent's skills folder).Take the user from nothing to one successful paid API call: resolve a CDP-managed wallet, wrap
their HTTP client so it answers 402 automatically, fund the wallet on testnet, verify with a
200.
Resolve the Decisions table below before writing any code, then read only the language subsection you resolved to in step 3. This file covers TypeScript and Python; reading both will blend them.
awal CLI. It is the nearest neighbour to this skill and the most likely
mis-selection.build-x402-server skill.signX402Payment, custom retry
logic). Out of scope here; see
Client configuration.Resolve every row before writing code. Detect first; only ask when detection is ambiguous.
| Decision | How to detect | Ask only if | Default |
|---|---|---|---|
| Language | package.json -> TypeScript. pyproject.toml / requirements.txt -> Python. | Both present, or neither | Ask |
| HTTP client | TS: axios in deps -> axios, else fetch. Python: httpx or any async def -> httpx, requests -> requests. | No HTTP client in deps | TS fetch, Python httpx |
| Network | environment: "development" selects Base testnet. | Never assume mainnet | development |
| Transport | An MCP server URL or an existing MCP client -> MCP variant. A plain URL -> HTTP. | Unclear what the target is | HTTP |
| Starting point | An existing x402 client holding a raw private key -> migration path. | — | Fresh integration |
The network row is a hard rule, not a preference: never move the user to Base mainnet unless they ask for it in the current turn, because mainnet payments spend real USDC.
Before installing anything, check that the environment has all three of CDP_API_KEY_ID,
CDP_API_KEY_SECRET, and CDP_WALLET_SECRET. The API key authenticates the caller to CDP; the
wallet secret is what lets the SDK sign payments. Missing either one fails at runtime, and it is a
worse experience to discover that three steps in. Send the user to
API key authentication if they have
no key yet. Also confirm the runtime: Node.js 22 or later, or Python 3.10 or later.
Pick the dependencies matching the Decisions table. @x402/core, @x402/evm, @x402/svm, and
@x402/extensions are optional peer dependencies of the CDP SDK, so they are not installed for you,
and all four are needed even for an EVM-only integration because @coinbase/cdp-sdk/x402 imports
them at module load.
For TypeScript, use the package manager already configured in the project. If none is configured, use npm. Install:
@coinbase/cdp-sdk, @x402/core, @x402/evm, @x402/svm,
@x402/extensions, and @x402/fetch@x402/axios instead of @x402/fetch, plus axios@x402/mcp instead of @x402/fetch, plus
@modelcontextprotocol/sdkFor Python, use the package manager already configured in the project. If none is configured, use pip. Install:
cdp-sdk and x402[evm,svm,httpx]cdp-sdk and x402[evm,svm,requests]Read only the subsection matching the language resolved above.
CdpX402Client is the whole point of the TypeScript path. It provisions the wallet, registers the
payment schemes, and already satisfies the signer interface the x402 wrappers expect, so it drops
into any of them unchanged.
import { CdpX402Client } from "@coinbase/cdp-sdk/x402";
import { wrapFetchWithPayment } from "@x402/fetch";
const client = new CdpX402Client({ environment: "development" });
// The wallet lives inside the client, so print the address to know what to fund.
const { evmAddress } = await client.getAddresses();
console.log(`Paying from ${evmAddress}`);
const fetchWithPayment = wrapFetchWithPayment(globalThis.fetch, client);
const response = await fetchWithPayment("https://x402.vercel.app/protected");
console.log(`HTTP ${response.status}`);There is no key to store anywhere — that is the reason a developer reaches for CDP here, so say so rather than burying it.
Three things that break first:
await needs ESM or an async main(). In a CommonJS project this is the first error.environment means Base mainnet and real USDC.getAddresses() also returns svmAddress for Solana. The field is svmAddress, not
solanaAddress.axios: same client object, different wrapper — wrapAxiosWithPayment(axios.create(), client)
from @x402/axios, which returns a wrapped axios instance.
MCP: paying for tool calls rather than routes, with wrapMCPClientWithPayment(mcpClient, client) from @x402/mcp. See clients/mcp/simple.ts below.
Migration: swap whatever signer the existing x402Client holds for CdpX402Client; the call
sites stay where they are. See x402DevMigration.ts below.
There is no CdpX402Client in Python, so assemble the pieces by hand rather than hunting for a
one-liner that does not exist.
import asyncio
from cdp import CdpClient
from cdp.evm_local_account import EvmLocalAccount
from x402 import x402Client
from x402.http.clients import x402HttpxClient
from x402.mechanisms.evm import EthAccountSigner
from x402.mechanisms.evm.exact import ExactEvmScheme
async def main() -> None:
async with CdpClient() as cdp:
account = await cdp.evm.get_or_create_account(name="x402-client-wallet-1")
signer = EthAccountSigner(EvmLocalAccount(account))
print(f"Paying from {signer.address}") # this is the address to fund
payment_client = x402Client()
payment_client.register("eip155:84532", ExactEvmScheme(signer))
async with x402HttpxClient(payment_client) as http:
response = await http.get("https://x402.vercel.app/protected")
await response.aread()
print(f"HTTP {response.status_code}")
asyncio.run(main())EvmLocalAccount and the x402 signer protocol declare sign_typed_data differently, and
EthAccountSigner is what reconciles them. Writing the wrap explicitly is a readability choice
rather than a requirement: ExactEvmScheme already auto-wraps anything that is an eth_account
BaseAccount, which EvmLocalAccount is, so passing the account directly works too. Keep the
explicit form so the adaptation is visible. A type checker may flag it, since EvmLocalAccount
subclasses BaseAccount rather than LocalAccount; at runtime it is correct.
Three things that break first:
CdpClient is an async context manager. Resolve the account inside async with.await response.aread() before touching the body."eip155:84532" is Base Sepolia. Changing it is a deliberate network change.requests: the sync alternative for a project with no async entry point. x402_requests(client)
from x402.http.clients is a function that returns a requests.Session, and it needs
x402ClientSync rather than x402Client — mixing the two raises a TypeError.
MCP: see clients/mcp/simple.py below.
Run the client once. With no USDC it fails, and it prints the address to fund. Send Base Sepolia USDC there:
import { CdpClient } from "@coinbase/cdp-sdk";
await new CdpClient().evm.requestFaucet({
address: evmAddress,
network: "base-sepolia",
token: "usdc",
});await cdp.evm.request_faucet(address=signer.address, network="base-sepolia", token="usdc")The CDP faucet funds the same wallets the CDP Facilitator settles against, so there is no second faucet to find. Wait for the transfer to confirm before re-running — requesting and paying in the same run fails on an empty balance.
Re-run. HTTP 200 is the success signal, and it proves the whole path: the payment was verified,
settled onchain, and the protected resource came back. If the user has no endpoint of their own
yet, https://x402.vercel.app/protected charges $0.01 on Base Sepolia.
| Symptom | Cause | Fix |
|---|---|---|
402 no matter how often you retry | Wallet holds no USDC, or the faucet transfer has not confirmed | Check the balance of the printed address before retrying |
Python TypeError on the client | A sync client paired with async pieces, or the reverse | x402_requests needs x402ClientSync; x402HttpxClient needs x402Client |
| Wallet authentication error | CDP_WALLET_SECRET missing or wrong | It is separate from the API key secret; check both |
| No scheme registered for network | Registered chain ID differs from the one the server asks for | Match the network in the 402 response |
| Payment exceeds balance | — | Report the shortfall in USDC, not atomic units: 10000 is $0.01 |
TypeScript, under https://github.com/coinbase/cdp-sdk/blob/main/examples/typescript/x402/clients/:
payForApi.ts, payForApiWithAxios.ts, payForApiWithSpendControls.ts, x402DevMigration.ts,
mcp/simple.ts.
Python, under https://github.com/coinbase/cdp-sdk/blob/main/examples/python/x402/clients/:
pay_for_api.py, pay_for_api_with_requests.py, mcp/simple.py.
environment: "development", fund with real USDC, and confirm with the user first© coinbase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/build-x402-client of coinbase/cdp-sdk.
Open the folder on GitHubat commit 993de49
Build X402 Client next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Build X402 Client this skillcoinbase/cdp-sdk | 203 | — | ~3k | Automated safety check: Pass | MIT | |
| Nevermined PaymentsLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.5k | Automated safety check: Notes | MIT | |
| Neon Postgresaiskillstore/marketplace | 430 | 4 repos | ~4.2k | Automated safety check: Notes | Apache-2.0 | |
| Fathom SDK Patternsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| OpenAPI to MCP Servermcp-use/mcp-use | 11k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Zhihu Searchitwanger/toBeBetterJavaer | 18k | — | ~1.5k | Automated safety check: Pass | None |
LeoYeAI/openclaw-master-skills
Integrates Nevermined payment infrastructure into AI agents, MCP servers, Google A2A agents, and REST APIs.
aiskillstore/marketplace
Guides and best practices for working with Neon Serverless Postgres.
jeremylongshore/tons-of-skills-marketplace
Production-ready Fathom API client patterns in Python and TypeScript.
mcp-use/mcp-use
Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.
itwanger/toBeBetterJavaer
Search Zhihu for content using the searchv3 API. An agent skill from itwanger/toBeBetterJavaer.
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
coinbase/cdp-sdk
Write code that charges for an HTTP route with the x402 protocol and receives USDC in a CDP-managed wallet.
coinbase/cdp-sdk
Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…
Works with
Categories
Write code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet. Build X402 Client is an agent skill from coinbase/cdp-sdk. Write code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet.
Build X402 Client fits situations like: the user wants to call a paid endpoint from their own application; add x402 payments to an HTTP client; hit an API that charges per request; migrate an existing x402 client off a raw private key.
Run `npx skills add coinbase/cdp-sdk --skill build-x402-client -a claude-code`. Or copy the skill folder (skills/build-x402-client in coinbase/cdp-sdk) into .claude/skills/build-x402-client in your project. Claude Code loads it when a task matches its description.
Run `npx skills add coinbase/cdp-sdk --skill build-x402-client -a codex`. Or copy the skill folder (skills/build-x402-client in coinbase/cdp-sdk) into .agents/skills/build-x402-client in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coinbase/cdp-sdk --skill build-x402-client -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/build-x402-client, .gemini/skills/build-x402-client, .github/skills/build-x402-client and .opencode/skills/build-x402-client in your project.
Going by SKILL.md and its folder, Build X402 Client needs credentials named CDP_WALLET_SECRET, CDP_API_KEY_ID and CDP_API_KEY_SECRET. Our summary lists: Python 3; Node.js; A credential in CDP_API_KEY_SECRET; A credential in CDP_WALLET_SECRET. Compatibility (from SKILL.md): Requires a CDP API key and wallet secret. Node.js >= 22 (TypeScript) or Python >= 3.10..
SKILL.md names 2 domains. In commands or code: x402.vercel.app; the agent is likely to contact it when it follows the instructions. As links in the text: docs.cdp.coinbase.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Build X402 Client is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Build X402 Client: Nevermined Payments (LeoYeAI/openclaw-master-skills, 2.2k stars), Neon Postgres (aiskillstore/marketplace, 430 stars), Fathom SDK Patterns (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
coinbase (a GitHub organization) maintains it in coinbase/cdp-sdk, which has 203 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.
Source: coinbase/cdp-sdk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.