x402 release and ecosystem changelog
A dated, source-linked record of protocol, SDK, governance, infrastructure, and production ecosystem changes without mixing incompatible version lines.
DIRECT ANSWER
This living changelog tracks dated x402 protocol, SDK, governance, infrastructure, and provider events with primary sources and an explicit version line. It does not treat every announcement as shipped software. Entries distinguish publication, release, deprecation, migration, waitlist, general availability, and observed production behavior so builders can determine what changed, when it changed, and what still requires verification.
Key takeaways
- Every entry needs an event date, evidence date, source, scope, status, and affected version or package line.
- TypeScript, Python, Go, protocol specifications, providers, and governance can move on different schedules and must not share one implied version.
- Announcements remain announcements until documentation, released artifacts, or production behavior establish a stronger status.
What this living changelog records
The x402 ecosystem changes across specifications, language SDKs, middleware, facilitators, networks, discovery systems, hosting infrastructure, and governance. A stream of separate news posts makes it difficult to reconstruct which capability existed on a particular date. This page keeps a dated ledger so a provider can connect an announcement to the actual package, documentation, migration, or production evidence relevant to its deployment.
Entries are evidence records, not endorsements. Each item identifies the event date, the date TOLL·402 checked the source, the affected component, the version or status when known, and a primary link. Corrections update the entry while preserving the distinction between the original event and the later verification. Marketing language is summarized in operational terms that a builder can test.
How statuses are separated
The changelog uses explicit statuses because announced, released, and generally available are not synonyms. An intent to launch records a proposed institutional change. An operational launch records an active organization. A waitlist records a way to request access. A package publication records an artifact in a registry. An observed production result records what a route did at a particular time.
A later status does not rewrite the earlier event. Cloudflare's July 1 Monetization Gateway announcement remains an announcement with an open waitlist until Cloudflare publishes stronger availability evidence. The Linux Foundation's April intent to launch and July operational launch remain separate milestones. This chronology lets readers see execution rather than receive a single page whose wording silently changes from future to present tense.
- Proposed: roadmap, intent, draft, or request for comment.
- Announced: publicly described but not necessarily accessible.
- Released: a versioned artifact or specification is published.
- Available: eligible users can configure the production capability under stated terms.
- Observed: TOLL·402 or another named source recorded behavior at a dated endpoint.
Why version lines must remain distinct
There is no safe single latest x402 version for every implementation. The protocol version, TypeScript packages, Python package, Go module, framework adapters, network-family packages, and provider integrations may publish at different times. A Python release number should not be attached to a TypeScript deployment merely because both live in the same repository. Likewise, an npm package version does not prove a facilitator has upgraded.
Every release entry therefore names its package or specification line. The legacy npm package x402 remains a v1 package with a different lifecycle from @x402/core and related v2 packages. Python's x402 release history is its own record. Dependency groups should be checked for compatible versions, but the changelog will not invent alignment where registries or maintainers do not provide it.
Initial dated ecosystem record
On July 1, 2026, Cloudflare announced Monetization Gateway for x402 payment enforcement at the edge and opened a waitlist. On July 14, the Linux Foundation announced the operational launch of the x402 Foundation and completion of Coinbase's protocol contribution. On July 17, PyPI published x402 2.16.0 according to its release history. Each event affects a different layer and carries a different status.
The registry also shows a rapid Python release sequence from 2.0.0 on January 22 through 2.16.0 on July 17. That cadence is evidence of publication activity, not a list of features by itself. Feature claims require package release notes, documentation, code changes, or maintainers' records. TOLL·402 will add those specifics when a primary source supports them instead of guessing from semantic version increments.
| Event date | Layer | Event | Status |
|---|---|---|---|
| 2026-07-01 | Infrastructure | Cloudflare Monetization Gateway described; waitlist opened | Announced / waitlist |
| 2026-07-14 | Governance | x402 Foundation operational launch | Operational |
| 2026-07-17 | Python SDK | x402 2.16.0 published on PyPI | Released |
| 2026-07-20 | Directory | TOLL·402 living changelog initialized | Published |
How an entry is verified before publication
For governance, TOLL·402 prefers foundation documents and canonical repositories. For packages, it checks the relevant registry and, when available, release notes or tags. For protocol behavior, it uses specifications and migration guides. For commercial services, it distinguishes a company announcement, documentation, account availability, and an observed production route. Secondary reporting can reveal an event but does not replace the primary record when one exists.
The editor records exact dates and avoids relative phrases such as today or recently. If a registry changes after publication, the entry retains its observed date. Claims that cannot be confirmed remain omitted or marked unknown. A corrected link or clarified label updates the evidence date; a substantive change, such as general availability after a waitlist, receives a new event row rather than overwriting history.
How providers should use the changelog
Use the changelog as a trigger for review, not an automated upgrade instruction. When a relevant SDK publishes, inspect release notes, dependency compatibility, security implications, and migration guidance. Re-run unpaid quote, supported-network, settlement, replay, and paid-delivery tests in a non-production environment. Pin the reviewed version and record the deployment date separately from the upstream release date.
When governance or specifications change, determine whether the change is normative, optional, or still proposed. An ecosystem announcement may create a future integration path without requiring action today. Providers should link their own status page or release notes to the exact upstream event they implemented. That makes directory evidence and customer support more precise when two deployments use different version lines.
What the changelog will not become
This page will not be a feed of every social post containing x402. It will not repeat unsourced transaction totals, token promotions, or partnership language without an operational change. It will not rank releases by excitement. The inclusion test is whether the event changes governance, specifications, implementation artifacts, supported infrastructure, provider availability, discovery, security, or observable service behavior for builders and buyers.
A dated ledger is more useful than isolated news because it can be corrected, compared, and cited. It also exposes silence: when an announcement has not progressed to documentation or availability, the unchanged status remains visible. TOLL·402 will maintain this page as a living reference and use separate guides or field reports when an event deserves deeper analysis, testing, or migration instructions.
Dated x402 releases and ecosystem changes
JSON →Entries separate protocol, SDK, governance, research and vendor changes. “Announced” does not mean generally available, and package versions apply only to the named package line.
- sdk releasereleased
The TypeScript x402 package family reached 2.19.0
The npm registry records 2.19.0 releases for @x402/core, @x402/mcp and other packages in the official TypeScript family. Package versions should be checked independently because the ecosystem does not have one universal version number.
Why it matters: Builders should pin and test the packages they actually use, then read their package metadata and repository changes before upgrading production clients or servers.
- sdk releasereleased
The official Python x402 SDK reached 2.16.0
PyPI records x402 2.16.0 as the current Python package release on July 17, 2026. The Python and TypeScript package lines use different current versions.
Why it matters: Documentation and migration notes should name the language and package, not say that x402 as a whole is on one version.
- governanceoperational
The Linux Foundation announced the operational x402 Foundation
The Linux Foundation said the protocol contribution from Coinbase was complete and the x402 Foundation was operating under formal open governance with 40 member organizations.
Why it matters: Protocol stewardship, budgets and technical priorities now have a neutral institutional home, but membership does not prove that every member has shipped interoperable production support.
- researchpreprint
A population-scale preprint challenged raw x402 settlement counts
Researchers published a Base-wide measurement of x402 settlement concentration and authenticity, arguing that transaction count alone cannot be read as independent agent adoption.
Why it matters: Market reports should separate onchain settlement volume from independent buyers, useful endpoint delivery and reviewed paid-call evidence.
- vendor integrationannounced
Cloudflare opened the Monetization Gateway waitlist
Cloudflare announced a planned gateway for applying x402 payment rules to web pages, datasets, APIs and MCP tools at its edge. The announcement describes planned capabilities and a waitlist, not general availability.
Why it matters: Providers can prepare route boundaries, pricing rules, identity policy and failure handling now, but should not describe the Gateway as deployable until Cloudflare documents availability.
Related directory entries
Sources and methodology
TOLL·402 distinguishes public claims, registry discovery, unpaid quote checks and settled paid-call verification. Sources below support the visible claims; presence in a registry is not treated as verification.
- x402 Foundation protocol repository — Canonical source for protocol specifications, code, package structure, and repository history.
- x402 Python package release history — Primary registry record for dated Python package publications, including 2.16.0 on July 17, 2026.
- @x402/core package record — Primary npm package surface for the current TypeScript core line and its v2 protocol documentation.
- Linux Foundation operational launch announcement — Primary dated governance event for the foundation's operational launch.
- Cloudflare Monetization Gateway announcement — Primary dated infrastructure announcement and current waitlist statement.