x402 receipt authorization

x402 for machine payments —
OMATrust for machine trust

OMATrust ties x402 Signed Receipts to your service, preventing identity attacks that can impact your online reputation.

Agent
x402 payment
Verified receipt
OMATRUST AND X402

x402 receipts need authorization

01 / 05Receipt Proofs
X402 SERVICE
no receipt
no receipt
no receipt
receipt filter

How do you know which reviews are legitimate?

x402 receipts prove a service transaction. Reviews without receipts are filtered out.

VERIFICATION IS NOT AUTHORIZATION

A valid signature only proves the math

x402 receipts are powerful because they are portable proof of interaction. OMATrust makes them trustworthy by checking the signer against the service's authorization record.

Signature verification

Confirms that some private key signed the receipt payload.

Authorization verification

Confirms that the signer was allowed to represent the service.

Forged receipt rejection

Rejects valid-looking receipts from keys outside the trust profile.

PROGRESSIVE AUTHORIZATION

Three levels of key authorization

Each level addresses a specific failure mode. Start with Level 1 and add layers as your security requirements grow.

LEVEL 1

Your domain proves your keys

Create a DNS TXT record or host a DID document at your domain listing your authorized signing keys. Any receipt signed by an unlisted key fails authorization — even if the signature is valid.

Prevents unrelated signers from claiming a service identity. Gives verifiers a live ownership check.

LEVEL 2

Durable key authorization

A Controller Witness creates a historical authorization record on the blockchain. Verification continues even when your own endpoint is unavailable or you rotate your keys.

Receipts remain verifiable during CDN outages or DNS issues. Past signatures are still valid even when the key is not listed anymore.

LEVEL 3

Revoke a compromised key instantly

Enterprise key binding lets you broadcast revocation. Every verifier in the ecosystem rejects the compromised key immediately.

Supports regulated environments, security policy enforcement, and key lifecycle management.

Receipts become attestations

Reviews, disputes, and audits can reference portable proof of service interaction.

Keys bind to service identity

Receipts resolve through DNS/DID, witnesses, and key lifecycle controls.

Agents inherit better signals

Machine clients can evaluate reputation without trusting raw wallet volume.

Protect your x402 service reputation

Turn signed receipts into verified trust signals with service identity, authorized signing keys, witness continuity, and revocation controls.