# How do I control what an AI agent pays with x402 or a crypto wallet?

> Decide each payment before the wallet signs. Immiscible's SDK reads the HTTP 402, asks with the payment requirements, and calls your x402 signer only on allow; for wallets it decides first and your wallet signs after. It never holds keys.

Source: https://immiscible.fly.dev/docs/answers/x402-and-wallet-payments

Decide each payment before the wallet signs, against a rule with limits in your own currency. Immiscible's SDK reads an HTTP `402`, asks with the payment requirements, and calls your x402 signer only on `allow`; for any wallet, `decideThenSign` asks first and calls your signing function only after an allow whose signed receipt covers the exact transfer.

## How do I set it up for x402?

```bash
npm install @immiscible/sdk
npx immiscible init --purpose buys_software
```

```ts
import { Immiscible, x402Fetch } from '@immiscible/sdk';

const pay = x402Fetch(new Immiscible(), {
  pay: ({ requirements, paymentRequired }) => myX402Client.createPaymentHeader(requirements, paymentRequired), // called only on allow
  provenance: [{ source: 'user', detail: 'the analyst asked for this report' }],
});
const res = await pay('https://api.data-vendor.example/v1/quotes');
```

x402 versions 1 and 2 are handled. See [x402 payments](https://immiscible.fly.dev/docs/guides/x402.md).

## How do I set it up for a wallet?

```ts
import { Immiscible, decideThenSign } from '@immiscible/sdk';

await decideThenSign(new Immiscible(), { asset: 'USDC', network: 'base', amount: '12.50', recipient: '0x...' },
  async () => ({ txHash: await wallet.send() }));
```

Amounts are decimal strings, priced at the rate of the moment against limits kept in pounds; lookalike addresses are stopped. Guides exist for [Fireblocks](https://immiscible.fly.dev/docs/guides/fireblocks.md) (the Co-Signer callback), [Turnkey](https://immiscible.fly.dev/docs/guides/turnkey.md), [Privy](https://immiscible.fly.dev/docs/guides/privy.md), [Circle](https://immiscible.fly.dev/docs/guides/circle.md) and [Coinbase CDP](https://immiscible.fly.dev/docs/guides/coinbase-cdp.md). See [crypto payments](https://immiscible.fly.dev/docs/guides/crypto-payments.md).

## How does this relate to agent payment schemes from card networks and payment companies?

Those schemes move the money and carry their own controls. Immiscible is the decision before them, held by you: the same rule, approval and record whether the agent pays by x402, a wallet or a card. For cards, the [card rail](https://immiscible.fly.dev/docs/guides/card-rail.md) has the issuer ask before money moves. No card network or payment company endorses or partners with Immiscible; these are integrations built against public interfaces.

## What does it not do?

- It never holds keys or signs; your signer or wallet does, after an allow.
- A wallet policy engine at the custodian is still worth keeping for transfers people make by hand; see [compare](https://immiscible.fly.dev/docs/compare.md#wallet-policy-engines).
- An agent holding a wallet key directly can sign without asking. Keep the key in a wallet service that asks first.
