On July 1, 2026, Cloudflare launched its Monetization Gateway: any customer can now put a per-call price on any resource — a page, an API, a dataset, an MCP tool — and be paid in stablecoins by whoever calls it. The mechanics run on x402, the open protocol that finally puts HTTP 402 “Payment Required” to work: the server quotes a price, the agent pays wallet-to-wallet, retries with proof of payment, and gets the resource. A year after Pay Per Crawl, the pay-per-use agentic web is no longer a thesis. It is shipping infrastructure.
We think this is exactly right — and exactly half of the problem. The new stack answers “did this request pay?” and, through Web Bot Auth, “which software fleet sent it?”. It does not answer the question every seller, regulator and dispute process eventually asks: if this agent causes harm, is there an accountable human behind it?
What the pay-per-use stack solves — and what it defers
x402 settles value without accounts: no signup, no card on file, no identity — a wallet is enough. Web Bot Auth authenticates operators cryptographically, and it works today because the calling population is small: a few dozen named crawler fleets, signing keys published in known registries. Between them, payments clear and big-fleet traffic is attributable.
But the population the gateway is built for is not a few dozen fleets. It is the coming long tail: purchasing agents, research agents, booking agents — millions of them, run by individuals and small companies, transacting with counterparties they have never seen. For that population, “which fleet signed this?” has no useful answer, and the fallback every marketplace reaches for — an allowlist of companies large enough to negotiate with — quietly recreates the gatekept web the open protocols were meant to avoid.
Verified agents get better terms. Verified how?
The gateway’s own design points at the gap: sellers can price differently for verified callers — free for partners, paid for strangers, refused for anonymous scrapers. Verification tiers are the obvious future of agentic commerce. The question is what “verified” means when the caller is not a household-name AI company but one agent among millions.
If “verified” means registered under its operator’s legal name in a public directory, the agentic web gets a surveillance index of who runs what, and every paid request extends the dossier. If it means nothing checkable, fraud teams are back to allowlists. Twenty years of identity systems assumed a human at the keyboard; both defaults fail without one.
The missing half: accountability without identification
This is the layer agent KYC — the protocol implementation of Know Your Agent (KYA) — is built to supply, and it is deliberately the zero-knowledge kind. An agent carries a credential derived from its operator’s one-time KYC with an approved issuer, and at transaction time proves, in about ten seconds: an accountable, KYC-verified human principal stands behind this agent, at assurance grade ≥ G, within a delegated scope that covers this purchase — and nothing else. No name. No wallet-to-operator mapping. No handle that links this seller’s log to any other seller’s log.
Accountability still has teeth: disputes settle money before identity — from the agent’s pre-funded escrow first, with identification reserved for due process through the issuer, as a last resort. Sellers get recourse; operators don’t get profiled.
Why zero-knowledge is load-bearing in a paying web
A pay-per-use web without privacy engineering is a logging web: every priced call is a timestamped, paid, attributable event. Combine per-request payments with a stable agent identifier and you have built the most complete behavioural surveillance instrument the web has ever had — retroactively queryable, one subpoena or one breach away. The fix has to live in the credential layer: presentations that are unlinkable across verifiers and across sibling agents, so that the proof spends like cash rather than like a card statement. That property, not the payment rail, decides whether the agentic web inherits the ad-tech panopticon or retires it.
The convergence we expect
Payment (x402), software identity (Web Bot Auth) and accountable-principal proofs (KYA) are complementary layers, and the second is already standardising at the IETF. We expect “price by verification” to become the default posture of agent-facing sellers, and verification to bifurcate: fleet signatures for the crawler oligopoly, credential proofs for everyone else. MintID’s bet — a sovereign Layer-1 whose only job is issuing and checking those proofs without ever holding PII — is that the “everyone else” tier is where the actual economy will live. The protocol is research-stage: specifications frozen, verifier SDKs in development, no mainnet before independent audits. The direction, after July 1, needs less argument than it used to.