
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
@peac/adapter-x402
Advanced tools
x402 offer/receipt verification, term-matching, and PEAC record mapping
x402 offer verification, receipt extraction, and PEAC interaction record mapping for the x402 Offer/Receipt extension.
pnpm add @peac/adapter-x402
@peac/adapter-x402 is a Layer 4 adapter that verifies x402 offer and receipt artifacts, extracts receipt data from HTTP response headers, and maps the results into canonical PEAC interaction records. It implements a verification-first architecture with layered checks: wire validation, term-matching (including the scheme identifier), offer-receipt consistency, and opt-in cryptographic verification. The adapter reads both PEAC-Receipt and upstream x402 response headers (v1 and v2) with priority-based fallback.
The adapter is scheme-agnostic at the verification layer. It preserves and
term-matches the x402 scheme identifier (exact, upto, or any future
upstream scheme) as a required string alongside network, asset, payTo,
and amount. The raw signed artifact is stored verbatim at
proofs.x402.offer, so downstream auditors retain the full scheme-level
payload for review.
The adapter does not enforce scheme-specific invariants. In particular,
for upto it does not enforce:
validAfter / validBefore)Those invariants are the x402 scheme layer's responsibility and are enforced on-chain or by the facilitator, not by PEAC. PEAC captures and surfaces the scheme identifier so downstream auditors can reason about phase semantics at review time.
For current upstream truth and the PEAC-tested compatibility matrix, see
docs/compatibility/x402-scheme-coverage.md
and docs/specs/X402-PROFILE.md § 3.0.
import { verifyOffer } from '@peac/adapter-x402';
const result = verifyOffer(signedOffer, acceptEntries);
if (result.valid) {
console.log('Matched accept entry:', result.matchedAccept);
console.log('Used hint:', result.usedHint);
} else {
console.log('Verification failed:', result.errors);
}
import { extractReceiptArtifactFromHeaders } from '@peac/adapter-x402';
// Dual-header read: checks PEAC-Receipt, then PAYMENT-RESPONSE (v2),
// then X-PAYMENT-RESPONSE (v1)
const artifact = extractReceiptArtifactFromHeaders(responseHeaders);
if (artifact) {
console.log('Source:', artifact.source); // 'peac' | 'x402_v2' | 'x402_v1'
console.log('Is PEAC receipt:', artifact.isPeacReceipt);
console.log('Raw artifact:', artifact.rawArtifact);
}
import { fromOfferResponse, X402CarrierAdapter } from '@peac/adapter-x402';
// Extract from an x402 402 response (offer)
const extraction = fromOfferResponse(response);
console.log('Carriers:', extraction.receipts);
console.log('Transport:', extraction.meta.transport);
// Or use the CarrierAdapter interface
const adapter = new X402CarrierAdapter();
import { toPeacRecord } from '@peac/adapter-x402';
const record = toPeacRecord(challenge, settlementResponse);
// record.proofs.x402.offer -- raw offer preserved for audit
// record.proofs.x402.receipt -- raw receipt preserved for audit
// record.evidence.resourceUrl -- from signed offer payload
// record.evidence.payer -- from signed receipt payload
@peac/adapter-core (Layer 4): Shared Result types and validators@peac/kernel (Layer 0): Wire constants and evidence carrier types@peac/schema (Layer 1): Receipt ref computation and carrier validation@peac/crypto (Layer 2): JWS parsing utilitiesIf you are building an AI agent that makes paid API calls via x402:
extractReceiptArtifactFromHeaders() to capture receipt evidence from HTTP responsesverifyOffer() and verifyReceipt() to validate x402 artifacts before accepting themtoPeacRecord() to map verified x402 flows into signed PEAC interaction recordsApache-2.0
PEAC Protocol is an open source project stewarded by Originary and community contributors.
FAQs
x402 offer/receipt verification, term-matching, and PEAC record mapping
We found that @peac/adapter-x402 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.