Networks & assets
Two environments on two chains, one asset. All of it is pinned into the deployment rather than chosen per request.
Networks
P2Flux runs two environments on two chains. Production is live on Base Mainnet and settles real USDC. The test environment is the same API on Base Sepolia, for building and rehearsing without real money at stake.
Value moved on Base Sepolia is not real money: the tokens come from a faucet. Value moved on Base Mainnet is real — treat every production request as spending or receiving actual dollars.
Hosts
Each environment is a pair: an API and a hosted checkout. They are not interchangeable — a capability issued by one environment is refused by the other, by construction — so pick a pair and use both halves of it.
The hosted checkout is where <checkout> refers to elsewhere in these docs: open https://pay.p2flux.com/#/pay/<intent> and the buyer completes the payment there. P2Flux hosts one checkout release per environment rather than shipping a copy to every merchant, so a wallet or security fix reaches every buyer at once instead of waiting for each integration to update. Companies that need the page on their own domain can host it themselves; then <checkout> is their address.
Every checkout route puts the token after the #. A fragment is never sent to any server, so it cannot reach an access log or a Referer header — which is exactly why it is safe to put a capability in a link at all. The checkout also clears it from the address bar once it has read it.
Assets
One asset. The token address is bound into the contract at construction and checked on every charge, so a deployment is USDC-or-nothing — passing a different token is not a configuration option, it is a different deployment.
Requests take a decimal string — "100.00" — and responses echo both that and the base-unit integer. 1 USDC is 1,000,000 base units on either chain. Amounts accept at most six decimal places and at most twelve digits before the point.
Contracts
Seven contracts on Base Mainnet, all immutable once deployed: not upgradeable, not proxied, no delegatecall, and no owner function that can move funds. The four below hold no balance between calls.
AI agent payments (x402) use three more, deployed 2026-10-01 and immutable in the same way. A seller’s vault holds what agents paid until anyone calls flush, which pays the seller and the fee in one transaction; P2Flux cannot move it anywhere else.
Base Sepolia runs the same four: P2FluxSplitter 0x3120aa022437db5c6d0439ac7f7852ce8b38e70f, P2FluxRecurring 0x394c3fe285168f333ebf29e8f3585039328f2a73, P2FluxSponsoredSplitter 0x876f7b98e8c06291ec916a3223a92038b0a8774f, P2FluxGasSponsor 0x2dc51643040d7c396f1199a0664ac095d4b89ec5. For AI agent payments it runs P2FluxX402Splitter 0x12Ae2c266014EB2A181024D12be9C4e5F468f7c8 and P2FluxBatchVaults 0x08EbEb85c53895F752bdAc9C115aF33FCff04F3E.
All seven Mainnet contracts are source-verified on Sourcify with an exact match — the deployed bytecode is byte-identical to the published source. Every API response that needs an address also returns it: /v1/payments returns the splitter in its pay block, and the subscription endpoints return the recurring contract. Read the address from the API rather than pinning a constant — that is also what keeps an integration correct across environments.
Source, ABIs and the EIP-712 definitions are public: github.com/P2Flux/contracts.
Confirmation policy
How deep a transaction must be before P2Flux calls it settled. These are operator settings, not request parameters — a caller cannot ask for a weaker one.