谁授权了这个?x402 的灰色地带

marsbit2026-04-27 tarihinde yayınlandı2026-04-27 tarihinde güncellendi

文章作者: David Christopher

文章编译: Block unicorn

x402 的成功离不开原生集成者。未经授权的封装程序可能会将潜在合作伙伴变成对手。

上周,Coinbase 推出了 agentic.market,这是一个展示 x402 端点的平台,旨在让 x402 生态系统更容易被发现。

浏览 agentic.market,你会发现各种服务的实时、按需访问,从链上工具到主流 API 应有尽有。部分端点由原始提供商直接提供。许多端点则来自第三方:一些公司将现有的 API 封装成 x402(和/或 MPP),并将其打包成可供代理使用的工具包,用户只需支付少量费用即可通过单一连接访问。

第二种方式使情况变得复杂。在 Agentic Market 上展示的第三方端点中,包括 Wolfram Alpha、Google Flights 和 Amadeus(一个广泛使用的旅行数据平台)的服务。我之所以重点关注这三个平台,是因为它们自身都没有宣布过 x402 集成,而且它们的服务条款也表明它们不太可能授权第三方代表它们构建集成。

Agentic Market 上索引的每个端点都可能是第一方(原始提供商直接提供其 API)、第三方授权(获得明确许可的经销商,通常是通过正式认证或合作伙伴计划),或者未经授权的第三方(公司未经许可转售其付费获得的 API 访问权限)。

在整个市场以及整个 x402 生态系统中,我们无法立即区分哪些是第一方,哪些是第三方,许多端点似乎都属于最后一类。


合同条款

如前所述,这三个提供商的条款使得未经授权的第三方安排显得很可能,在某些情况下甚至完全排除了其他方案。

Wolfram Alpha 明确禁止“经销商和聚合商”,禁止以任何方式进行数据抓取或挖掘,并且禁止未经许可出售或转授服务。这些条款似乎完全没有为授权的第三方路径留下任何空间。而且,查看该端点的快速入门指南后,很明显这不是第一方集成。

(Wolfram Alpha 服务条款中的 API 禁止内容)

Amadeus的主订阅服务协议仅允许客户出于内部业务目的访问,并禁止任何“出租、租赁、分发、出售、转售、转让或以其他方式转移”其访问权限的行为。任何第三方连接都需要 Amadeus 的认证,并以正式的服务订单形式记录。这意味着这是获得第三方授权的唯一途径,而任何现有端点是否符合此要求,从外部是无法查看的。

(Agreement 中的限制 Amadeus 主订阅服务协议中的限制)

Google 的情况最为典型。Google Flights 没有公开的 API,而且 Google 对其数据采取了严格的保护措施。

然而,第三方封装程序正在打包对 Google Flights 数据的访问,这些数据来源于 SerpApi——一家 Google 正在积极起诉的公司,指控其抓取搜索结果并转售访问权限。Google 的诉状称,SerpApi 开发了绕过访问控制的工具,每天发送“数亿”条虚假请求进行抓取,并将嵌入搜索结果中的受版权保护的内容转售。

因此,Google 起诉 SerpApi 转售受版权保护的内容并绕过其访问控制。与此同时,SerpApi 的服务却被一家代理工具包提供商封装,该提供商将其提供给代理商并收取费用。这值得深思。

(通过 StableTravel 端点访问 SerpApi 的详细信息)


合规性如何体现

无需法律专家也能看出,这些动态“错综复杂”。好消息是,一种更清晰的模式已经存在。

MPP 是 Tempo 在其主网上线时推出的代理支付协议,在上线首日就提供了 100 多种兼容服务。直接集成 MPP 的供应商——例如 Parallel、Stripe Climate、Browser Base 等——在其卡片上以绿色圆圈标记,表明其为第一方供应商。

(通过 mpp.dev 查看的服务目录)

大约两周前,热门 AI 研究工具 Exa 宣布在其搜索和内容端点中原生支持 x402 协议——成为第一方供应商,并与 Coinbase 达成合作。Exa 表示,选择 x402 而非专有协议,是因为它受到 Linux 基金会的监管。


不可避免的结果

目前,外部无法得知某个端点是第一方、第三方授权还是未经第三方授权。这是一个可以解决的问题,而 MPP 的服务目录——它清晰地展示了每个集成的来源——正是朝着这个方向迈出的一步。

未经授权的抓取行为已经给服务提供商带来了诸多可衡量的压力:服务器负载、带宽成本以及他们从未同意提供的流量。第三方将抓取的数据封装在 x402 协议中并收取费用,更是雪上加霜。服务提供商承担了所有成本,却分文未得。

因此,有必要明确问题的根源所在。x402 是一个开放协议——就像任何开发者都可以基于 HTTP 进行开发一样,任何开发者都可以基于 x402 进行开发。支付机制无法追踪上游数据是否经过授权获取。责任在于那些将这些端点打包供用户使用的开发者。

如果缺乏问责机制,可能会对 x402 的整体发展造成负面影响——潜在的原生集成者可能会变成反对者,而不是参与者。这些收入本应属于服务提供商。原生集成是他们声称拥有这些收入的方式,也是 x402 获得发展所需合法性的方式。

注意:截至 4 月 25 日,Google Flights 已不再被 Agentic Market 收录。

İlgili Okumalar

GPT-5.6 Countdown: Abandon the Illusion of a Single API, Computational Iteration Can't Outpace a Single Page of Compliance

In mid-June, three seemingly independent industry events—the compliance-driven throttling of Fable 5, the open-sourcing of GLM-5.2, and the leaked release timeline for GPT-5.6—are pushing the global AI industry toward a watershed moment. These shifts signal a fundamental restructuring of the industry's underlying logic. First, **"usability" has substantially overtaken "advanced capabilities"** as the primary weight, pushing the global large language model (LLM) supply chain into a "dual-track" phase of controlled closed-source and local open-source coexistence. Second, **the competitive moats of closed-source giants are shifting**. Their technical focus is moving from "language intelligence" toward "spatial intelligence (world models)"—a domain heavily reliant on computing power. Third, faced with常态化 transnational compliance risks, **a "model-agnostic" decoupled design has become a survival necessity for application-layer developers to maintain business continuity.** The article details how Anthropic's Fable 5, despite its advanced engineering feats, was restricted for non-U.S. citizens within 72 hours of launch, highlighting how geopolitical compliance can instantly limit even the most advanced models. In response, the open-source camp, exemplified by Zhipu AI's MIT-licensed GLM-5.2, is gaining market share by offering stable performance improvements and significant cost advantages (up to 70% savings for enterprises), while achieving full adaptation with domestic semiconductor platforms. Meanwhile, closed-source leaders like OpenAI are pivoting. The anticipated GPT-5.6 reportedly shifts focus from language to spatial intelligence and world models, aiming to rebuild a generational gap in areas like 3D understanding, simulation, and industrial design that demand immense compute. The core conclusion is that the LLM supply chain's logic has changed. Enterprises must now evaluate infrastructure based on a composite of technical performance and policy compliance. For developers, complete reliance on a single closed-source API poses unacceptable risk. Implementing a truly model-agnostic architecture—enabling swift switches to compliant, locally deployable open-source alternatives—is no longer just good practice but a fundamental baseline for business continuity.

marsbit1 saat önce

GPT-5.6 Countdown: Abandon the Illusion of a Single API, Computational Iteration Can't Outpace a Single Page of Compliance

marsbit1 saat önce

Is the 'Token Subsidy War' Among AI Giants Almost Over?

The article discusses the ongoing "token subsidy war" among AI giants like OpenAI and Anthropic, questioning whether it's nearing its end. It reveals that current AI subscription prices are heavily subsidized, with some plans offering tokens at up to 70 times the actual cost to attract and retain heavy users, especially developers and enterprises. This strategy mirrors past internet-era subsidy battles, but with a key difference: AI tokens lack "lock-in" effects. Unlike ride-hailing or food delivery apps, users can easily switch between AI providers as APIs become standardized, making it difficult for companies to raise prices post-subsidy. The piece highlights a structural asymmetry in the competition. Giants like Google, with massive advertising revenue, can afford to subsidize tokens indefinitely, akin to using "tokens as a weapon." In contrast, venture-backed companies like OpenAI and Anthropic face pressure to become profitable, especially as they approach IPO. The article cites Google Ventures founder Bill Maris, who suggests Google could slash token prices by 80%, putting immense pressure on competitors. Two potential endgames are presented: the "internet service" model (subsidize, monopolize, then raise prices) and the "utility" model (tokens become a standardized, low-margin commodity like electricity). Given the low switching costs, the latter seems more likely. The competition may not have a single winner but could instead accelerate AI's evolution into a foundational, infrastructure-level technology, akin to a public utility. For now, users continue to benefit from heavily subsidized token costs.

marsbit1 saat önce

Is the 'Token Subsidy War' Among AI Giants Almost Over?

marsbit1 saat önce

Beyond the Stadium: The Profitable Games Surrounding the World Cup

"Beyond the Pitch: The Profit Game Around the World Cup" The FIFA World Cup transcends being a sporting spectacle, evolving into a massive global arena for speculation and profit-seeking. The 2026 tournament has amplified this dynamic, creating a multi-layered ecosystem of financial opportunism alongside the football. **Prediction markets** have surged into the mainstream. Platforms like Polymarket and Kalshi saw trading volumes for World Cup contracts soar, attracting new users with their financial trading model and high-profile, chain-based wealth stories that overshadow traditional sports betting in terms of growth and narrative. However, **traditional sportsbooks** remain the dominant force, leveraging established user habits, legal markets, and comprehensive product offerings to handle the vast majority of speculative wagers, with projections suggesting record-breaking betting volumes. Capital markets also react. **"Concept stocks"** in countries like South Korea and Japan experience volatile price swings based on team performance and anticipated fan spending on items like chicken, beer, and viewing parties, effectively becoming a stock market reflecting fan sentiment. The **ticket resale market** has become a sophisticated arena for arbitrage. Prices fluctuate wildly based on team draws and star power, with sellers sometimes listing tickets they don't yet own in a practice akin to short-selling, while FIFA's own "Right to Buy" tokens add another layer of speculative trading. **Collectibles and merchandise** offer another avenue. Panini sticker albums, with their inherent scarcity and nostalgic value, can become high-value collectibles. Limited-edition or locally themed jerseys command significant premiums on secondary markets, and even counterfeit vendors profit from fans' desire for affordable match-day identity. The **cryptocurrency** space has seen a frenzy of speculative, unauthorized World Cup-themed meme coins on chains like Solana. These tokens, often exploiting team names and player imagery, experience extreme pump-and-dump cycles, creating stories of massive gains for a few early entrants and steep losses for many others. Finally, an entire industry thrives on **providing information and tools** to other speculators. Developers create platforms like SeatSidekick to track ticket inventory and prices, while paid Telegram groups and subscriptions sell betting tips and predictions, monetizing the widespread desire for an informational edge. In essence, the World Cup has become a compressed, global laboratory for speculation. While the games determine champions on the field, a parallel, complex network of financial transactions—spanning prediction contracts, bets, stocks, tickets, collectibles, crypto, and information services—settles its own scores in the global market.

marsbit2 saat önce

Beyond the Stadium: The Profitable Games Surrounding the World Cup

marsbit2 saat önce

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

This article explains the three primary methods for Codex to interact with a computer, each with distinct use cases, permission boundaries, and trust levels. **1. Computer Use:** This offers the broadest access, allowing Codex to visually control and interact with the graphical user interface of authorized macOS/Windows apps, system settings, and even iOS simulators. It's ideal for tasks lacking APIs or structured tools, such as operating legacy software or multi-app workflows. However, it's the slowest method and has the widest permission scope, requiring careful supervision for sensitive actions. **2. Chrome Extension:** This grants Codex access to the user's logged-in Chrome browser state, including cookies, profiles, and open tabs. It's best for tasks requiring user identity across websites like Gmail, LinkedIn, Salesforce, or internal dashboards. Its key advantage is multi-tab control for complex workflows. While more powerful for browser-based tasks than Computer Use, it carries higher sensitivity as actions are performed under the user's identity. **3. In-App Browser:** This is a browser isolated within the Codex thread, separate from the user's personal browsing data. It excels in web development and debugging scenarios—previewing local servers, testing responsive layouts, or annotating designs directly on the page. Its isolation is a strength for development but a limitation for tasks requiring login sessions. The core principle is to choose the narrowest, safest, and most structured interface for the task. Use plugins or MCPs first, resort to visual control (Computer Use) only for GUI-dependent tasks, employ the Chrome extension for identity-reliant browser work, and prefer the In-App Browser for isolated development. **Appshots** are clarified as a fourth, complementary tool for *inputting* context—capturing a screenshot of a window to point Codex to something—rather than a method for Codex to *act*. Together, this layered approach highlights a key to AI agent productization: not granting unlimited permissions, but constraining them within clear boundaries for specific tasks while preserving user oversight.

marsbit4 saat önce

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

marsbit4 saat önce

İşlemler

Spot
Futures
活动图片