What we actually use HTTP 402 for
While designing ClusterValidator's payment flow we kept coming back to a status code almost nobody uses: 402 Payment Required. It has been reserved in the HTTP spec since the nineties, waiting for digital cash systems that never arrived. The meaning is plain: I have what you asked for, and you have not paid for it yet.
The original idea was to use it for license checkout. That version never shipped. ClusterValidator went live with something more boring: you pay through Stripe or a cloud marketplace, we email a signed license file, and the software verifies it offline. Boring turned out to be right for installed software, because a person buying an annual license does not need a novel protocol. They need a file that works on a machine with no internet access.
Where 402 fits
The status code found its real use once our hosted APIs started getting called by AI agents instead of people.
An agent has no credit card, no inbox, and no patience for a checkout page. What it can do is pay per call. Call WikiMint's hosted MCP endpoint without a key and you do not get a login wall; you get HTTP 402 and a machine-readable price: 0.25 USDC on Base buys one documentation generation. GitEasy's hosted write tools work the same way at a cent a call. The agent pays, the call runs, and no account ever exists.
This is the x402 protocol, and it is exactly what 402 was reserved for thirty years ago. Our terms have a section for it now: a payment of this kind buys a single call, creates no subscription, and tells us nothing about who you are.
Two shapes, two answers
So the licensing question ended up with two answers. Software you install verifies a signed file offline and keeps working when the network does not. APIs an agent calls charge per call over 402. We tried to force the second idea onto the first product, and it took shipping both to see why they belong apart.