<!-- markdown mirror of https://mintid.net/en/blog/x402-pay-per-use-web-needs-identity — generated at build time -->

> Cloudflare’s Monetization Gateway makes agents pay per call over x402. Payment and fleet signatures are solved — the accountable human behind the long tail of agents is not. Why zero-knowledge KYA is the missing half of the agentic web.

Blog · agentic identity

# The pay-per-use web is here. It needs Know Your Agent.

Cloudflare’s Monetization Gateway makes agents pay per call over x402. Payment and fleet signatures are solved — the accountable human behind the long tail of agents is not. Why zero-knowledge KYA is the missing half of the agentic web.

by Marc Miró i Rierola·published 2026-07-26·updated 2026-07-26·7 min read

On July 1, 2026, Cloudflare launched its **Monetization Gateway**: any customer can now put a per-call price on any resource — a page, an API, a dataset, an MCP tool — and be paid in stablecoins by whoever calls it. The mechanics run on [x402](/en/glossary#x402), the open protocol that finally puts HTTP 402 “Payment Required” to work: the server quotes a price, the agent pays wallet-to-wallet, retries with proof of payment, and gets the resource. A year after Pay Per Crawl, the pay-per-use agentic web is no longer a thesis. It is shipping infrastructure.

We think this is exactly right — and exactly half of the problem. The new stack answers _“did this request pay?”_ and, through [Web Bot Auth](/en/glossary#web-bot-auth), _“which software fleet sent it?”_. It does not answer the question every seller, regulator and dispute process eventually asks: **if this agent causes harm, is there an accountable human behind it?**

## What the pay-per-use stack solves — and what it defers

x402 settles value without accounts: no signup, no card on file, no identity — a wallet is enough. Web Bot Auth authenticates operators cryptographically, and it works today because the calling population is small: a few dozen named crawler fleets, signing keys published in known registries. Between them, payments clear and big-fleet traffic is attributable.

But the population the gateway is built for is not a few dozen fleets. It is the coming long tail: purchasing agents, research agents, booking agents — millions of them, run by individuals and small companies, transacting with counterparties they have never seen. For that population, “which fleet signed this?” has no useful answer, and the fallback every marketplace reaches for — an allowlist of companies large enough to negotiate with — quietly recreates the gatekept web the open protocols were meant to avoid.

## Verified agents get better terms. Verified how?

The gateway’s own design points at the gap: sellers can price differently for verified callers — free for partners, paid for strangers, refused for anonymous scrapers. Verification tiers are the obvious future of agentic commerce. The question is what “verified” means when the caller is not a household-name AI company but one agent among millions.

If “verified” means _registered under its operator’s legal name in a public directory_, the agentic web gets a surveillance index of who runs what, and every paid request extends the dossier. If it means nothing checkable, fraud teams are back to allowlists. Twenty years of identity systems assumed [a human at the keyboard](/en/blog/agentic-identity-problem); both defaults fail without one.

## The missing half: accountability without identification

This is the layer [agent KYC](/en/agent-kyc) — the protocol implementation of [Know Your Agent (KYA)](/en/blog/what-is-know-your-agent) — is built to supply, and it is deliberately the _zero-knowledge_ kind. An agent carries a credential derived from its operator’s one-time KYC with an approved issuer, and at transaction time proves, in about ten seconds: an accountable, KYC-verified human principal stands behind this agent, at assurance grade ≥ G, within a delegated scope that covers this purchase — and nothing else. No name. No wallet-to-operator mapping. No handle that links this seller’s log to any other seller’s log.

Accountability still has teeth: disputes settle [money before identity](/en/blog/money-before-identity) — from the agent’s pre-funded escrow first, with identification reserved for due process through the issuer, as a last resort. Sellers get recourse; operators don’t get profiled.

## Why zero-knowledge is load-bearing in a paying web

A pay-per-use web without privacy engineering is a logging web: every priced call is a timestamped, paid, attributable event. Combine per-request payments with a stable agent identifier and you have built the most complete behavioural surveillance instrument the web has ever had — retroactively queryable, one subpoena or one breach away. The fix has to live in the credential layer: presentations that are **unlinkable across verifiers and across sibling agents**, so that the proof spends like cash rather than like a card statement. That property, not the payment rail, decides whether the agentic web inherits the ad-tech panopticon or retires it.

## The convergence we expect

Payment (x402), software identity (Web Bot Auth) and accountable-principal proofs (KYA) are complementary layers, and the second is already standardising at the IETF. We expect “price by verification” to become the default posture of agent-facing sellers, and verification to bifurcate: fleet signatures for the crawler oligopoly, credential proofs for everyone else. MintID’s bet — a [sovereign Layer-1](/en/technology) whose only job is issuing and checking those proofs without ever holding PII — is that the “everyone else” tier is where the actual economy will live. The protocol is research-stage: specifications frozen, [verifier SDKs in development](/en/sdk), no mainnet before independent audits. The direction, after July 1, needs less argument than it used to.

Does an x402 payment identify the agent that pays?

No. x402 settles value: a wallet pays the quoted price and the request proceeds. The seller learns that payment cleared, not who operates the agent, whether a liable human stands behind it, or whether the same operator was refused yesterday under a different wallet. Payment and accountability are separate problems — x402 deliberately solves only the first.

Isn’t Web Bot Auth enough identity for the agentic web?

Web Bot Auth authenticates software: a signed request proves “this call comes from operator X’s fleet”. That works for a handful of named crawler operators. It says nothing about the millions of autonomous agents acting for individual people and small businesses — and turning it into a public registry of who runs which agent would solve accountability by building a surveillance index. Know Your Agent credentials add the missing layer: proof of an accountable, KYC-verified principal, without naming them.

If the agent already paid, why would a seller need its identity at all?

Because price is not the only risk. Sellers face fraud, abuse, chargebacks, regulatory exposure and differentiated pricing (partner rates, jurisdiction rules, age-gated goods). Today the fallback is allowlists of big companies — which locks out the long tail. A zero-knowledge KYA proof lets any agent, however small its operator, clear the same bar: an accountable human exists, is verified at a stated assurance grade, and granted this scope.

Why does privacy matter more, not less, in a pay-per-use web?

Per-request payments leave per-request trails. If every paid call also carried a stable agent identity, sellers — and anyone who aggregates their logs — could reconstruct an operator’s entire activity graph. MintID presentations are unlinkable across verifiers and agents of the same principal, so accountability exists at each transaction without a joinable history existing anywhere.

## The other half of the agentic web

Payment rails are shipping. The accountable-principal layer is what we build: zero-knowledge Know Your Agent on a sovereign identity Layer-1.

[How agent KYC works](/en/agent-kyc)[The vocabulary, defined](/en/glossary)

---
Source: https://mintid.net/en/blog/x402-pay-per-use-web-needs-identity · The pay-per-use web is here. It needs Know Your Agent. — MintID blog
