Who controls the payment address on an x402 gateway route?
The short answer
The route does not say. On the gateways read, the payment address in a quote belonged to the gateway whatever company the route was named for, or was one that neither the quote nor the catalogue attributed to anyone.
As published in the issue
On three payment gateways — Locus, Tempo and Sponge — all 134 routes that quoted a price in September used gateway-level payment addresses, not addresses unique to the company named on the route; on a fourth, Orthogonal, 541 quoting routes under 54 names used 42 addresses, and neither the quotes nor the route catalogues identified who controlled them.
(2) The OBSERVED population: every route on probe402's September route list — 16,118 routes on 1,950 hosts, fixed on 3 September — and every graded reading of it inside the sealed window of 4–30 September 2026, less the rows of endpoints a published correction of ours scopes; a gateway, movers or address figure is a count over those readings, a comparison with a third party's label joins the exact route we read to the label its surface returned for it, and an endpoint we did not read is counted rather than dropped.
The sentence above is quoted from a published issue and is not re-written here. Its date, its population and the record behind it are below.
Why it matters
A buyer paying a route named for one company may be paying someone else. Without a merchant identity in the payment challenge, the name on a route is a label rather than a counterparty.
What we measured
Every route that quoted a price under the gateways the issue names, on the September route list and across the sealed window, with the payment address in each quote grouped by gateway and by the name on the route. The exact population rule is quoted beside the figure below.
What the evidence shows
- Sealed days behind the archive figures
- 27
- Observations in that window
- 315,315
- Issue
- Machine Commerce Reality Index: #002 — September 2026
- Published
2026-09-04 · 2026-09-05 · 2026-09-06 · 2026-09-07 · 2026-09-08 · 2026-09-09 · 2026-09-10 · 2026-09-11 · 2026-09-12 · 2026-09-13 · 2026-09-14 · 2026-09-15 · 2026-09-16 · 2026-09-17 · 2026-09-18 · 2026-09-19 · 2026-09-20 · 2026-09-21 · 2026-09-22 · 2026-09-23 · 2026-09-24 · 2026-09-25 · 2026-09-26 · 2026-09-27 · 2026-09-28 · 2026-09-29 · 2026-09-30
27 of the 27 sealed days behind these figures are on the head table at /chain (9 re-derived from an off-vendor replica and 18 anchored from the archive as stored). Each day's manifest is served at /chain/<date>.
What this does not say
- These are each supplier's statements about its own arrangements, not a measurement of authorisation; two other suppliers on Orthogonal show Orthogonal's logo on their own home pages (read 2 October).
Method and reproduction
The runs behind the figures, the record each one produced, and the terms this question uses.
What ran, when, and the record it produced.
| What ran | When | Record |
|---|---|---|
| The gateway fold over the mirrored window: every route on the September list under one of the four gateways by a stated classifier, which of them returned a payable quote, the payment addresses quoted per gateway, per rail and per name, whether any changed, the in-band fields each quote carried, and the second rail's partition. | 098161c7c6243d3f3909257f40b3b28f808e883f26bda1b6c739f2d15a60c807 |
The terms
The terms this question uses are defined in the glossary.
Corrections and disputes
This answer names a party we measure. The route to dispute a reading is on the corrections page.
Corrections to this issue are on the corrections register, and this answer reads from the record rather than from a copy.