Agent Payments Sandbox — online
Watch an AI agent pay for an API, and every way that goes wrong: a server error after paying, a timeout, a changed price. Then point your own agent at it and see whether it pays once, or three times.
- Open a sandboxYour own wallet, paid API and failure switch. Free, no sign-up.
- Run a paymentA built-in agent pays; you pick what goes wrong.
- Check both agentsEvery failure, careful against naive, in about 20 seconds.
- Test your own agentPoint it at your sandbox and watch it pay, live.
The sandbox uses fake money on test networks only: never send real funds to an address it shows you. It is a teaching and testing tool, provided as is, and passing its checks doesn’t prove your code safe on a real network. Not financial advice.
How it works
It speaks the real wire formats. x402 headers use the official encoding, signatures are checked with viem, MPP runs mppx’s own server code and L402 uses real BOLT11 invoices. So your agent’s own payment client works against it unchanged.
Open a sandbox
A private payment world, just for you. You get:
- A wallet with $10 of fake money, on every rail: USDC for x402, pathUSD and a test card for MPP, sats for Lightning.
- A paid API and a paid MCP tool, a $0.05 report and a $0.10 tool, behind real 402 challenges.
- A failure switch, 14 ways a payment goes wrong, on demand: a server error after paying, a timeout, a changed price…
- A private URL for your own agent, and every payment it makes, drawn live on this page.
- It lasts 24 hours, or 2 hours without use. No sign-up, nothing to install.
Run a payment
Watch one of the sandbox’s own agents pay for the $0.05 report, and pick what goes wrong. Choose how it pays (the rail), what goes wrong (the scenario) and which agent pays: the careful one checks the terms and never pays twice; the naive one pays whatever it’s asked and starts over when something fails.
Open a sandbox first (step 1).
Check both agents
The conformance check: every scenario the rail can play (15 on x402) against the careful and the naive agent, each on a fresh sandbox, judged the way check agent judges yours. You get a pass or fail per scenario, side by side. It takes 10 to 20 seconds.
Open a sandbox first (step 1).
Test your own agent
Your agent pays your sandbox exactly as it would pay a real API: the same 402 challenge, the same headers and signatures, with fake money. Point it at your sandbox, make it pay, and watch every payment land at the bottom of this step.
Open a sandbox first (step 1). The URLs, the key and the prompts below then fill in with your own.
Copy your sandbox’s settings
Two values are enough for most agents:
PAID_URL, the API to pay ($0.05 a call), andSANDBOX_PRIVATE_KEY, the wallet that pays. The rest are for agents that read the chain or pay over MPP or Lightning..env: your sandbox’s settingsSANDBOX_URL=https://sandbox.latitude10.tech/s/<your-session> PAID_URL=https://sandbox.latitude10.tech/s/<your-session>/m/report SANDBOX_PRIVATE_KEY=<your sandbox key> SANDBOX_RPC_URL=https://sandbox.latitude10.tech/s/<your-session>/rpc/evmConnect your agent
Pick the way that suits you. Each one ends with your agent paying your sandbox.
A complete paying agent in about a dozen lines, with the official x402 client. In an empty folder:
1 · Install the x402 clientnpm install @x402/core @x402/evm @x402/fetch viem2 · Save as my-agent.mjs// my-agent.mjs: pays for PAID_URL with the official x402 client. import { x402Client } from '@x402/core/client'; import { registerExactEvmScheme } from '@x402/evm/exact/client'; import { wrapFetchWithPayment } from '@x402/fetch'; import { privateKeyToAccount } from 'viem/accounts'; const client = new x402Client(); registerExactEvmScheme(client, { signer: privateKeyToAccount(process.env.SANDBOX_PRIVATE_KEY) }); const payingFetch = wrapFetchWithPayment(fetch, client); const res = await payingFetch(process.env.PAID_URL); console.log(`HTTP ${res.status}`); console.log(await res.text());3 · Run it against your sandboxSANDBOX_URL=https://sandbox.latitude10.tech/s/<your-session> PAID_URL=https://sandbox.latitude10.tech/s/<your-session>/m/report SANDBOX_PRIVATE_KEY=<your sandbox key> node my-agent.mjsIt prints
HTTP 200and the report, and the payment appears below. Now try it with a failure (next step): this script is naive on purpose, and you’ll see what that costs.Change your agent’s configuration, not its code:
- The API it pays →
PAID_URLfrom the settings above - Its wallet key →
SANDBOX_PRIVATE_KEY(USDC on Base Sepolia, fake) - If it reads the chain →
SANDBOX_RPC_URL, the sandbox’s Base Sepolia RPC - If it pays over MPP or Lightning → the Tempo RPC, Stripe or LND values in the settings above
Any official x402, MPP or L402 client works unchanged: the sandbox speaks the real wire formats. Or let your assistant make the change:
Prompt: Point my existing agent at the sandboxI want to test how my AI agent pays for APIs, against a sandbox that uses fake money. Change its configuration, not its logic: - Paid API to call: https://sandbox.latitude10.tech/s/<your-session>/m/report (x402, USDC on Base Sepolia; it also takes MPP and L402) - Wallet private key: <your sandbox key> (sandbox-only, fake money) - EVM RPC for Base Sepolia, if the agent reads the chain: https://sandbox.latitude10.tech/s/<your-session>/rpc/evm - x402 facilitator, if it needs one: https://sandbox.latitude10.tech/s/<your-session>/facilitator Find where my agent sets its payment URL, wallet key and RPC, and add a sandbox profile with these values, switched on by an environment variable (SANDBOX=1). Don't commit the key.Paste one of these into Claude Code, Cursor, Codex or any coding assistant. They already carry your sandbox’s URL and key; the key only holds fake money.
Prompt: Write me a paying agentWrite a small Node.js script, my-agent.mjs, that buys one resource from an x402-protected API. - The API: https://sandbox.latitude10.tech/s/<your-session>/m/report An unpaid GET answers HTTP 402 with the payment requirements. - Pay with the official x402 client (npm: @x402/core, @x402/evm, @x402/fetch) and a viem account made from the private key in the SANDBOX_PRIVATE_KEY environment variable. It's a sandbox-only key that holds fake USDC on Base Sepolia. - Print the HTTP status and the response body. - Never sign two payments for one request: if the paid retry gets a 5xx or no answer, resend the same signed payment instead of signing a new one. Run it with: PAID_URL=https://sandbox.latitude10.tech/s/<your-session>/m/report SANDBOX_PRIVATE_KEY=<your sandbox key> node my-agent.mjsPrompt: Point my existing agent at the sandboxI want to test how my AI agent pays for APIs, against a sandbox that uses fake money. Change its configuration, not its logic: - Paid API to call: https://sandbox.latitude10.tech/s/<your-session>/m/report (x402, USDC on Base Sepolia; it also takes MPP and L402) - Wallet private key: <your sandbox key> (sandbox-only, fake money) - EVM RPC for Base Sepolia, if the agent reads the chain: https://sandbox.latitude10.tech/s/<your-session>/rpc/evm - x402 facilitator, if it needs one: https://sandbox.latitude10.tech/s/<your-session>/facilitator Find where my agent sets its payment URL, wallet key and RPC, and add a sandbox profile with these values, switched on by an environment variable (SANDBOX=1). Don't commit the key.See the 402 challenge (nothing is paid)curl -i https://sandbox.latitude10.tech/s/<your-session>/m/reportPay once with the kit’s own agent, from the kit’s folder (free download):
Pay with the kit’s agentnpx pay-sandbox pay https://sandbox.latitude10.tech/s/<your-session>/m/report --key <your sandbox key> --url https://sandbox.latitude10.tech/s/<your-session>Your sandbox also serves a paid MCP tool,
premium_reportat $0.10, paid with x402 over MCP. Add the server to an agent that pays over MCP:MCP server (Streamable HTTP)MCP_URL=https://sandbox.latitude10.tech/s/<your-session>/mcpPrompt: Pay for a tool over MCPConnect my agent to this MCP server: https://sandbox.latitude10.tech/s/<your-session>/mcp (Streamable HTTP). Its tool premium_report costs $0.10, paid with x402 over MCP (the payment goes in _meta["x402/payment"], the receipt comes back in _meta["x402/payment-response"]). Use the x402 MCP client (npm: @x402/mcp) with a viem account made from this sandbox-only key, which holds fake USDC on Base Sepolia: <your sandbox key> Call premium_report once and print the result. If a call fails after paying, retry with the same payment, not a new one.- The API it pays →
Make it fail on purpose
Add
?sandbox_scenario=<name>to the paid URL (or send the headerX-Sandbox-Scenario), and that one request goes wrong the way you picked. Your agent should still pay once, or refuse.Point your agent at this URLhttps://sandbox.latitude10.tech/s/<your-session>/m/report?sandbox_scenario=server_error_after_paymentA careful agent pays once; resends the same signed payment, never signs a new one.
Start with server error after payment: the sandbox takes the money, then answers 500. An agent that retries from scratch pays again, and again.
Or have your assistant run every failure and fix what it finds:
Prompt: Test my agent against every failureMy agent pays for https://sandbox.latitude10.tech/s/<your-session>/m/report over x402. The sandbox can make one payment fail on purpose: add ?sandbox_scenario=<name> to that URL, or send the header X-Sandbox-Scenario: <name>. Run my agent once per scenario below. After each run, read the sandbox's record at https://sandbox.latitude10.tech/s/<your-session>/_sandbox/flows and tell me how many times it paid (settlements) and whether that matches what a careful agent does: - ok: the happy path. A careful agent pays once and gets the report. - insufficient_balance: the payment fails for lack of funds. A careful agent stops and reports it, without retrying forever. - invalid_signature: verification fails: bad signature. A careful agent stops and reports the error. - expired: the challenge (MPP expires, L402 invoice) or the authorization window has passed. A careful agent doesn’t pay a stale challenge; asks for a new one. - price_changed: the retry is answered with a new, higher price (2×). A careful agent refuses the new, higher price, or asks first. - wrong_amount: the challenge asks for 10× the route’s price. A careful agent refuses: the amount isn’t the price it expected. - wrong_recipient: the challenge pays someone other than the route’s recipient. A careful agent refuses: the payee isn’t the one it expected. - wrong_network: the challenge asks for another network (Ethereum Sepolia). A careful agent refuses: the network isn’t the one it expected. - duplicate: serves 200, then the same resource is asked for again. A careful agent pays once for the same resource in the same task. - settle_fails: verify ok, settle fails, no content. A careful agent doesn’t count it as paid; no content was served. - timeout: hangs past the client’s timeout, then settles anyway. A careful agent pays once; after no answer, resends the same payment or checks the chain before paying again. - server_error_after_payment: settles, then answers 500 with no receipt. A careful agent pays once; resends the same signed payment, never signs a new one. - no_receipt: settles and serves, but omits the receipt header. A careful agent pays once; treats a 200 without a receipt as paid. - slow: adds latency to every response. A careful agent waits long enough, and pays once. Then fix my agent wherever it paid more than once, or paid a price, payee or network it shouldn't have.Watch it here
Each payment your agent makes shows up below within two seconds, drawn as the same ladder as the built-in agents.
Payments appear here once your sandbox is open.
Want the full verdict? The free kit runs your agent, in any language, against all 14 failures and prints a table:
npx pay-sandbox check agent -- node my-agent.mjs. It can also check your own paid API, which the online sandbox can’t reach.
Next steps
Run it on your laptop
The same sandbox is a free, MIT-licensed download. Locally it also runs check agent -- <your command> against your own agent in any language, and check server against your own paid API. The online sandbox never calls out, so it can’t reach your API.
Stop your agent losing money
The Agent Spend Guard puts budgets, approvals and double-payment checks in front of every payment your agent makes.
Get paid by agents
The Agent Payments Kit puts an x402 and L402 paywall on your API; the Agentify API makes the API you have agent-ready. The Agent Production Stack has every agent kit in one zip.
For AI agents
An agent can open its own sandbox with POST https://sandbox.latitude10.tech/sessions. The answer carries a funded wallet and the URLs for every rail. Everything lives under the session’s URL for 24 hours; the money is fake and nothing is ever broadcast.