prompt
Private task context
Full prompts, chat excerpts, support tickets, retrieval chunks, and internal notes should not become payment metadata.
x402 metadata filter / payment privacy
x402 and Pay.sh make paid API calls easy for agents. This local checker looks for prompts, user identifiers, emails, phones, query tokens, wallet context, and secret-like strings in payment metadata before receipts, facilitators, providers, or public chains can see them.
rules
prompt
Full prompts, chat excerpts, support tickets, retrieval chunks, and internal notes should not become payment metadata.
pii
Email, phone, names, customer ids, account ids, and location strings should be replaced with compact purpose labels.
url
URLs can carry query tokens, emails, session ids, and search terms. Keep the origin/path or a neutral resource label.
secret
API keys, bearer tokens, JWTs, private keys, webhook secrets, and seed-like strings should never appear in receipts.