Agent Paywall for WordPress
AI agents pay to read what you choose. People see your site as always. No WooCommerce needed.
What it does
AI agents — assistants, research tools, crawlers — read websites for their users. With this plugin they pay you for it. When an agent opens a post you made paid, your site answers 402 Payment Required with a price; the agent pays in USDC and gets the post. The money goes to your wallet. People visiting your site see nothing different.
Set up
- Install and activate P2Flux Agent Paywall.
- Settings → Agent Paywall: paste your wallet address (a wallet on Base that receives USDC). P2Flux checks the address when you save; a mistyped one is refused.
- Choose what agents pay for and the price. Save.
No account, no API key, nothing to install on the server. Start in Test mode (Base Sepolia, test USDC) and switch to Live when you have seen it work.
What agents pay for
In lists, feeds, search and REST collections an agent sees the title and the price of a paid post, not its text. The smallest price is 0.01 USDC.
Paid files
A file in the Media Library — a PDF, a dataset, an image — can have a price too: open the file and fill in “Price for AI agents”. People download it as always; an agent gets 402 and the file after payment.
WordPress does not see requests for uploaded files; the web server answers them itself. So the plugin writes a rule into the uploads folder that sends AI agents’ requests for the priced files — those files and no others — through WordPress. Apache and LiteSpeed read it from .htaccess — nothing to do. On nginx, add one block per file you sell inside the server block, and reload nginx:
Only a Media Library file with a price is ever sent through WordPress; a request for any other file there is answered 404, so the rule must name only files you gave a price.
Without the rule a paid file still has a paid address: /?p2flux_ap_file=<id>. Images inside a paid post are not paid unless you give them a price.
Who is asked to pay
An agent is recognised by an x402 payment on the request, by a bot signature, or by its user agent. The list can be changed with the p2flux_ap_agent_signatures filter.
Web Bot Auth is how an agent proves who it is: it signs each request and publishes its keys (ChatGPT agent does). When such an agent pays, the plugin checks the signature against the keys the agent publishes and shows the agent’s name next to the payment. A signature never makes anything free.
Pay per page and prepaid
Both are offered to every agent; it uses the one it supports. Prepaid can be switched off in the settings. One payment opens one page once: the same payment presented again is refused. An agent can ask for its unused prepaid balance back once it has used at least 0.10 USDC of it, or after 24 hours without use; unused balances also come back on their own after 7 days, and an agent can always withdraw from the escrow directly. What it already spent is yours.
Earnings
The settings page shows what agents paid today, this month and in all, and the last payments with a link to each transaction. Payments per page link to the transaction on Base; prepaid ones are marked prepaid until they are paid out.
Be found
“List my site in the P2Flux directory” is ticked by default. Listed: your site name, tagline, address, price, and the titles of your ten latest paid posts. Untick it and the listing is removed. Agents search the directory at GET /x402/directory.
Caches and CDNs
A cache that stores whole pages can answer an agent with a paid post before WordPress runs. Press Check my setup on the settings page: it opens your newest paid post the way a person does and then the way an AI agent does, through whatever stands in front of your site, and says whether the agent was asked to pay.
A default Cloudflare setup does not cache HTML pages and needs nothing.
Your own assistant
On WordPress 6.9 and later the plugin registers three abilities (the WordPress Abilities API), so an AI assistant you connected to your site — for example through the MCP Adapter plugin — can answer “what did AI agents pay me this month?” and “make this post cost 0.10”.
Limits
- A bot that presents itself as an ordinary browser and does not sign its requests is not recognised and reads as a person does.
- A full-page cache or CDN that answers before WordPress runs can serve a paid post to an agent — see “Caches and CDNs”.
- Files are paid only when they have their own price, and on nginx only with the rule above.
- If P2Flux cannot be reached, agents are asked to come back later (or read free, if you chose so). People are never affected.
What is sent to P2Flux
- When an agent opens a paid page: your wallet address and the price.
- When an agent pays: your wallet address, the price, the page address and the agent’s payment.
- When you save the settings: your wallet address, and — if listed — your site address.
When an agent that signs its requests pays, the plugin reads that agent’s public keys from the agent’s own site, to check the signature. That request goes to the agent’s site, not to P2Flux.
Nothing about your human visitors is sent.