~3 min readgrounded in docs/ENV.md §payments · apps/web/lib/config.ts · apps/web/app/api/wallet/route.ts · apps/worker/wrangler.toml
Payments·
Payments are off by default, and off means 404: until PAYMENTS_ENABLED is exactly "true" on both the Vercel app and the worker, /api/wallet*, /api/x402/*, /api/chain/* and /api/erc8004/* answer 404 {"error":"payments disabled"} before touching the worker or any chain, every worker /pay/* route does the same, and the 1-minute cron skips the reconcilers. GET /api/health reports paymentsEnabled so you can see which state you are in.
What turns on·
| Surface | Routes | What it does |
|---|---|---|
| Wallet | wallet, wallet/faucet, wallet/withdraw |
a USDC balance per user with a ledger; faucet credit on test networks; withdrawals |
| x402 | x402/pay, x402/chat/[slug] |
pay-per-message chat with a priced tiny over the open x402 protocol; quotes, settlement proof in x-tiny-x402-settled |
| Chain | chain/join, chain/status |
joining and reading the deployment's own network when PAYMENTS_NETWORK=tiny |
| ERC-8004 | erc8004/registration/[slug] |
on-chain agent registration record for a tiny |
Agent tools: wallet (read-only), set_price, pay_x402, make_payment. The two that move money return a quote; only the user can execute it, by confirming in the UI. The agent cannot approve on their behalf.
Networks·
PAYMENTS_NETWORK on the worker: base (real USDC on Base mainnet), base-sepolia (testnet trial credit; the default in wrangler.toml), or tiny (your own self-hosted chain — needs TINY_CHAIN_ID, TINY_CHAIN_RPC_URL, TINY_CHAIN_USDC_ADDRESS, TINY_CHAIN_EXPLORER_URL on the app). Running that network — Besu QBFT, a facilitator, an RPC proxy — is not part of this template; chain/multinode/genesis-8470.json is kept only as a sample to replace.
Other worker variables: DEPOSIT_ADDRESS (checksummed 0x…, deposit claiming refuses without it), BASE_RPC_URL / BASE_SEPOLIA_RPC_URL (default to the public endpoints, which are rate-limited), RECONCILE_ALARM_USER (who gets paged when a reconciliation row stays blocked across two ticks). App side: X402_PAY_ALLOWLIST (extra payable hosts beyond your own app and worker), X402_FACILITATOR_URL, and the signer keys documented inline in app/api/x402/pay/route.ts and app/api/wallet/withdraw/route.ts — refused when they are Anvil's well-known development keys outside a dev network.
The full table is in Environment variables.