Agent Guide
This page is Payload's canonical machine front door. If you are an autonomous agent: start with agents.json — it contains everything below in structured form, so you never need to scrape this prose.
How an agent uses Payload
- Discover — read agents.json.
- Determine your problem — match it to a commercial path below, then to the exact action.
- Check price and entitlement — each product lists exactly what purchase grants; each callx402 action lists its fee model.
- Obtain access — per-action fee for a callx402 action (see live schedule below); Stripe checkout (card) or wallet-signed USDC order (crypto) for a Veyline subscription; one-time purchase on Whop/Gumroad for kits.
- Invoke — the callx402 action, MCP tool, or Veyline API.
- Recover safely — use the failure classes below. Never blind-retry a paid operation.
Commercial routing — three paths, never collapsed
ONE-OFF / INCIDENT NEED → callx402 (paid on-demand actions)
A specific x402 problem with a specific operation: match it to the action below, pay the applicable per-action fee, receive the result, continue. No subscription required — a callx402 action never requires Veyline and never creates one.
ONGOING PRODUCTION PROTECTION → Veyline (subscription)
When the intent changes from "help me solve this incident" to "I need this handled continuously, automatically, and at production scale": subscribe. Veyline makes the incident less likely, automatically controlled, and recoverable at scale.
MONETIZE YOUR OWN MCP SERVICE → MCP Monetization Engine ($69 one-time)
For developers who want to charge per tool call on their own MCP server. Not a path to Payload's services.
Decision procedure: specific current incident → callx402 action · recurring incidents / continuous / automatic / at-scale → Veyline · charge others for your own MCP tools → MCP Monetization Engine. Never route a one-off incident to a subscription as the first answer.
Identity
Payload builds protected economic-control infrastructure for autonomous commerce, machine-access layers, and business reliability tools.
Canonical domains: payloadhq.github.io (site) · payload-rail.fly.dev (API rail). Hierarchy: Payload (parent) → Veyline (flagship) → callx402 by Payload — powered by Veyline (action layer) → MCP (machine-access layer). RevRule is a separate product, never a mandatory dependency of a Veyline transaction.
Veyline — subscription tiers (exact, current)
Tiers differ only in monthly operations allocation and the detailed-usage breakdown gate (Production+). Safety, auth, idempotency, duplicate protection, and SpendGuard core are identical on every tier. Over-limit requests return HTTP 429 with an upgrade message — you are never billed for over-limit usage; there is no overage pricing.
Free / Sandbox — $0
1,000 operations/month. No detailed usage breakdown.
Developer — $99/month
10,000 operations/month. No detailed usage breakdown.
Production — $499/month
100,000 operations/month. Detailed usage breakdown included.
Growth — $1,499/month
1,000,000 operations/month. Detailed usage breakdown included.
Enterprise — $5,000+/month custom
Negotiated allocation. Detailed usage breakdown included. Per-contract terms.
A Veyline purchase entitles your organization to: an API key bound to your tier; metering against your included operations; GET /v1/veyline/status and GET /v1/veyline/usage; the economic governor below; fail-closed economic protection on every operation at every tier. Subscribe.
Economic governor — standing spending mandates
Veyline subscribers can compile a natural-language spending policy into machine-enforced constraints, then authorize every paid agent step against it. Deterministic (no LLM); fail-closed: conflicting or injected intents never compile, and the firewall defaults to DENY.
POST /v1/veyline/mandates—{nl_text}→ compiled mandate (spend caps, network/asset/provider allowlists, retry limits, human-approval thresholds)POST /v1/veyline/mandates/{id}/authorize—{step}→ALLOW/DENY/ESCALATE_HUMANwith reasonsPOST /v1/veyline/mandates/{id}/commit— record executed spend (durable budget)GET /v1/veyline/mandates/{id}/bindings— AP2 and x402 compatibility shapes
Example: "Allow spending up to $50 total, at most $10 per call, use only base network, use only usdc, require human approval above $25 per call" → every step checked before it spends. Idempotency keys are durable: replaying a key with a different step is rejected.
callx402 — paid on-demand actions
callx402 gets paid to help with the incident. Each action below is a standalone paid action: match your problem, pay the applicable per-action fee, receive the result, continue. Live fee schedule: GET https://payload-rail.fly.dev/v1/callx402/actions (server-side, owner-adjustable). The local CLI, SDKs, and MCP-stdio tools are the free read-only diagnostic surface — no payment, no auth, no entitlement.
Fee schedule (USD, per action)
- explain — $1.00 · diagnose — $2.00 · evidence — $2.00 · failure classification — $2.00
- preflight — $3.00 · settlement interpretation — $3.00
- resolve — $5.00 · monitor — $5.00 · safe retry — $5.00 · duplicate-payment risk — $5.00
- recover — $10.00 · execute — $10.00
- rescue — $15.00
How to pay and invoke
Human path: POST https://payload-rail.fly.dev/v1/callx402/checkout with {"action": "<name>"} → one-time Stripe checkout → single-use credit shown once on the success page → POST /v1/callx402/actions/<action> with {"credit_id": "cxa_..."}. The credit is consumed atomically — exactly once.
Autonomous agent path (x402): POST https://payload-rail.fly.dev/v1/callx402/actions/<action> with no auth → standards-compliant x402 v2 402 Payment Required (exact USDC amount on Base, pay-to address, 300-second window; also sent as a base64 PAYMENT-REQUIRED header) → pay from an authorized wallet → retry with {"txHash": "0x..."} → the rail verifies the transfer on-chain before authorizing, and each txHash is single-use (atomic reservation; a replayed hash is rejected with 409). A paid action never requires or creates a Veyline subscription.
Veyline subscribers: send Authorization: Bearer <veyline-api-key> instead — the invocation is authorized and metered against subscription usage.
Problem → action (canonical mapping)
- Settlement uncertainty → resolve — resolve pending settlement from evidence instead of blind retry. Returns confirmed / unconfirmed / unknown (fail-closed).
- Lost result after payment → recover — safe recovery decision for paid-but-no-result (read-only assessment; nothing charged or executed by the assessment itself). Returns RECOVERABLE/SAFE_RETRY → KNOWN_SAFE, or HUMAN_REVIEW.
- Retry uncertainty → diagnose / safe retry — diagnose the failure from evidence; prove a retry cannot double-pay or double-execute before retrying.
- Need proof of what happened → evidence — event trail and latest per-plane states (payment / execution / delivery). Use first in any incident.
- Need explanation → explain — plain-language state assessment (NO_BASIS, INCOMPLETE, KNOWN_SAFE, RECOVERY_CANDIDATE, PARTIAL) with the safe next step.
Other actions
preflight — check intent, payment readiness, and risk before committing. execute — run an economic operation through the protected path (exactly-once, on-demand action; not gated by a Veyline subscription). monitor — watch an operation or workload for state changes or failures. rescue — guided rescue decisions for an in-progress incident. settlement interpretation — what chain/payment evidence actually proves. failure classification — classify into a known class with its safe action. duplicate-payment risk — assess double-pay risk before paying or retrying.
When Veyline is the better answer
If the same class of incident keeps recurring, if protection must run continuously and automatically without invocation, or if operations run at production scale — that is the Veyline subscription (see tiers above). callx402 solves the incident in front of you; Veyline makes the next one less likely.
MCP equivalents (stdio, JSON-RPC 2.0, free read-only): x402_diagnose, x402_evidence, x402_explain, x402_recover, x402_resolve, x402_status. No auth or tier hooks exist on the MCP surface by design — it is never Veyline-gated.
Other live products
All one-time purchase, single-seat perpetual license, on Whop or Gumroad:
- RevRule — $99. Revenue-rule engine (separate product).
- Veyline Developer Primer — $79. Onboarding product for agent-generated codebases.
- MCP Monetization Engine — $69. Charge per tool call on your MCP server (paid tool registry, free quotas, usage ledger, SDK adapter).
- x402 + MCP Bundle — $119. Primer + Engine together.
- n8n Reliability Guard — $99. Guardrails, evals, readiness scoring for n8n agent workflows.
- CRM Dedup System — $149. Offline duplicate finder for HubSpot/Salesforce CSV exports.
- StableLedger — $49. Stablecoin tax CSV normalizer (data organization only; not tax advice).
- MCP Launch Readiness Audit — $79. 48-rule security scanner for MCP servers (an audit, not a certification).
- AI Search Readiness Audit — $59. Chrome extension auditing pages for AI-search readiness.
Purchase routes
callx402 — on-demand actions
Paid per action, no subscription. Match the problem to the action (see the callx402 section above). Human: one-time Stripe checkout → single-use credit. Agent: x402 402 → pay USDC on Base → retry with txHash (verified on-chain, single-use). Local CLI/SDK/MCP-stdio diagnostic use is free and read-only.
Veyline — card (Stripe)
POST https://payload-rail.fly.dev/v1/stripe/checkout with JSON {"tier": "developer|production|growth|enterprise"}. No auth required — a fresh organization is provisioned server-side. Follow the returned Checkout URL. After successful payment, the success page shows your API key exactly once — copy it then. Entitlements are created only by the Stripe-verified webhook; an unpaid session yields no entitlement and no key.
Veyline — crypto (USDC on Base)
Secure order flow only: POST /v1/purchases/orders to create an order, then POST /v1/purchases/redeem with wallet-signed {order_id, tx_hash, signature}. The rail verifies the transfer on-chain before executing. The bare-txHash endpoint is permanently disabled (410) — never submit a bare transaction hash as payment proof.
Kits and audits
One-time purchase on Whop or Gumroad. Download link delivered at purchase.
Authentication
Veyline API: Bearer token in the Authorization header. Obtain via the Stripe success page or the crypto redeem flow. Keys are product-bound — a RevRule key used on Veyline routes returns 403. Revoked keys return 401. Marketplace products require no API auth (download links are delivered by the store). The MCP diagnostic surface requires no auth by design.
Never expose wallet secrets, Stripe secrets, administrative credentials, or raw API keys in logs, prompts, or shared artifacts.
Error taxonomy — safe action per failure class
HTTP / API errors
- 401 UNAUTHORIZED — key missing, invalid, or revoked. Do not retry the same key; re-authenticate or obtain a new one.
- 403 PRODUCT_MISMATCH — key belongs to a different product. Use a key issued for the product you are calling.
- 403 FEATURE_NOT_INCLUDED — detailed usage on Free/Developer. Use
/v1/veyline/usagewithout the breakdown, or upgrade to Production+. - 429 QUOTA_EXCEEDED — allocation exhausted. Stop sending traffic; upgrade for a larger allocation. Never billed for over-limit usage.
- 400 INVALID_TIER — use exactly: developer, production, growth, enterprise.
- 410 ENDPOINT_DISABLED — use the secure order flow instead.
- PAYMENT_INCOMPLETE — session unpaid; no entitlement, no key. Complete payment first.
Operation failure classes (fail-closed)
- UNKNOWN — bare evidence. Do not act, retry, or repay. Gather evidence first.
- SETTLEMENT_UNKNOWN → HUMAN_REVIEW — never guess settlement.
- PAID_BUT_RESULT_LOST — call
recover(read-only); recover the prior proven result; prohibit unsafe re-execution. Never blind-retry. - INCOMPLETE — do not retry, do not repay. Collect more evidence.
- NO_BASIS — treat as unproven; establish evidence first.
- RECOVERY_CANDIDATE — follow the recover output; execute only via an explicitly authorized path.
- KNOWN_SAFE — complete. Do not re-execute.
- PARTIAL — resolve the unconfirmed planes before acting.
Capability and entitlement requirements
- Veyline operations — active Veyline subscription (any tier). Continuous/automatic/at-scale protection. Capability availability is identical across tiers.
- callx402 on-demand actions — per-action fee per invocation. No subscription, no entitlement — pay per action.
- callx402 diagnostics / MCP tools — no entitlement required; free, read-only, tier-agnostic.
- One-time products — purchase receipt from Whop or Gumroad.
- RevRule — never a mandatory dependency of a Veyline transaction.
Support and recovery paths
Canonical support: kyler.simmons.partners@gmail.com — include your order ID or API key prefix (never the full key). Recovery: for paid-but-no-result, start with callx402 recover (read-only) before contacting support. Docs: docs.html. API reference: rail OpenAPI. GitHub: Payloadhq.
Machine-readable
Everything on this page, structured: agents.json (schema payload/agents-discovery/1.0). Discoverable from llms.txt, robots.txt, and the sitemap.