okx-agent-payments-protocol
Handle OKX Agent Payment Flows
Paid agent endpoints often require careful signing, confirmation, and replay steps. This skill guides Claude, Codex, and Claude Code through OKX Agent Payments Protocol flows.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "okx-agent-payments-protocol" from https://skillstore.io/skills/internet-court-okx-agent-payments-protocol.md and its manifest at https://skillstore.io/api/skills/internet-court-okx-agent-payments-protocol/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "okx-agent-payments-protocol". I need to access a paid weather endpoint that returned HTTP 402.
Expected outcome:
- Shows the required network, token, amount, recipient, and request parameters.
- Asks for explicit confirmation before checking wallet status or signing.
- After payment, reports the settlement result and suggests a balance check.
Using "okx-agent-payments-protocol". Create a payment link for 0.01 USDT to my seller wallet.
Expected outcome:
- Confirms the payment link was created.
- Displays the payment identifier, amount, recipient, and shareable link when available.
- Suggests checking status after the buyer pays.
Using "okx-agent-payments-protocol". Close my active payment channel after the final request.
Expected outcome:
- Uses the saved channel state to close the channel.
- Shows the charged amount, prepaid balance, refund amount, and on-chain transaction reference.
Security Audit
High RiskMost static matches are false positives caused by Markdown code formatting, relative documentation links, protocol literals, and security-oriented guidance. Four findings are confirmed because the local-key fallback reads EVM_PRIVATE_KEY from the environment or ~/.onchainos/.env to authorize payment signing. No prompt-injection, credential-exfiltration, or covert network-intent evidence was found in the reviewed material.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Filesystem access (12)
๐ Env variables (2)
โก Contains scripts (1)
โ๏ธ External commands (50)
๐ Network access (2)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/internet-court-okx-agent-payments-protocol/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/internet-court-okx-agent-payments-protocol?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/internet-court-okx-agent-payments-protocol?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/internet-court-okx-agent-payments-protocol/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/internet-court-okx-agent-payments-protocol.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
internet-court. (2026). okx-agent-payments-protocol security audit report (audit version 2) [Author version 4.2.1]. Skillstore. https://skillstore.io/skills/internet-court-okx-agent-payments-protocol/audits/2BibTeX citation
@techreport{internet-court-internet-court-okx-agent-payments-protocol-2026,
author = {internet-court},
title = {okx-agent-payments-protocol security audit report (audit version 2)},
institution = {Skillstore},
year = {2026},
number = {2},
url = {https://skillstore.io/skills/internet-court-okx-agent-payments-protocol/audits/2},
note = {Author version 4.2.1}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "okx-agent-payments-protocol security audit report (audit version 2)"
version: "4.2.1"
type: report
authors:
- name: "internet-court"
date-released: "2026-07-21"
url: "https://skillstore.io/skills/internet-court-okx-agent-payments-protocol/audits/2"
identifiers:
- type: other
value: "skillstore:internet-court-okx-agent-payments-protocol:audit:2"
description: "Skillstore immutable audit report identifier"
Compare variants
2 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
internet-court-okx-agent-payments-protocol
2026-09-09
okx-okx-agent-payments-protocol
2026-09-09
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Access paid agent endpoints
Handle HTTP 402 responses, show payment details, collect confirmation, sign, and replay the protected request.
Manage payment channels
Open a prepaid session, issue vouchers, top up balance, and close the channel with clear state tracking.
Operate a2a payment links
Create seller links, pay buyer links, poll status, and present terminal payment states in plain language.
Try These Prompts
Call <endpoint URL>. If it returns a payment requirement, show the charge details and wait for my confirmation before payment.
Create an a2a payment link for <amount> <symbol> to <recipient address> with description <description>.
Use channel <channel_id> to make another request to <business URL>. Track the cumulative amount and show the channel state.
For this HTTP 402 response, compare the available OKX Agent Payments Protocol options, recommend one, and wait for confirmation.
Best Practices
- Confirm each payment with amount, token, network, recipient, and request parameters before signing.
- Prefer TEE wallet signing over local private key fallback when possible.
- Keep channel identifiers, escrow address, chain ID, deposit, cumulative amount, and signature in conversation state.
Avoid
- Do not sign a payment before showing the required confirmation card.
- Do not reuse stale signatures or expired payment challenges.
- Do not expose internal protocol routing when a plain payment result is enough.
Frequently Asked Questions
What payment flows does this skill cover?
Does this skill move funds by itself?
Does it require an OKX wallet session?
Can it use a private key?
How are recurring payments handled?
What should I verify for a2a links?
Developer Details
Author
internet-courtLicense
MIT
Author version
v4.2.1
Skillstore revision
r1
Ref
3f6e026a3363e0954ede7bef0cfe88d4475de137
Maintenance freshness
7/21/2026
Usage
1 downloads ยท 0 views
File structure
๐ _shared/
๐ amount-display.md
๐ preflight.md
๐ references/
๐ a2a_charge.md
๐ accepts-schemes.md
๐ charge.md
๐ multi-scheme.md
๐ session.md
๐ subscription.md
๐ SKILL.md