NanoTrans Agent Paywall
NanoTrans Agent Paywall is an agent-native paywall plugin that enables AI agents to automatically discover and purchase WordPress content using the x402 payment protocol with USDC stablecoin on the Base Network (Ethereum L2). Key Features: Dual Access – Humans pay via browser wallet (MetaMask); AI agents pay automatically via x402 protocol Gasless Payments – Buyers unlock content with a signature only and sellers receive payouts automatically — neither side needs ETH for gas (with the Facilitator Proxy connection enabled on Base mainnet; see “When is payment really gasless?” in the FAQ) x402 Protocol – Industry-standard HTTP 402 payment flow with EIP-712 signatures USDC Payments – Stablecoin payments on Base Network (low gas fees, fast settlement) Agent Discovery – /.well-known/x402 endpoint for automatic content discovery Gutenberg Block – Visual paywall block editor with price configuration Batch Payments – Purchase up to 20 articles in a single transaction Admin Dashboard – Revenue tracking, anomaly detection, emergency controls Real-time Notifications – SSE-based payment alerts Permanent Access – One-time payment grants permanent access via signed wallet cookie How It Works: Publisher sets content prices using the Gutenberg paywall block AI agent requests content and receives HTTP 402 with payment requirements Agent signs USDC payment via EIP-712 x402 Facilitator verifies payment on-chain Content is delivered as structured JSON For Content Publishers: Set per-article prices in USDC Dynamic pricing (agent vs human, time-based) Revenue dashboard with real-time analytics Automatic fund distribution via Splitter contracts For AI Agent Developers: Standard x402 (HTTP 402) payment flow — works with any x402-capable agent or SDK Machine-readable site discovery at /.well-known/x402 Structured JSON API responses (articles, categories, search) External services This plugin relies on the following third-party services to process x402 micropayments. Payments cannot be verified or settled without them. All connections are opt-in: no outbound network call is made until the site administrator explicitly enables the Facilitator Proxy connection in Settings > NanoTrans and saves the settings. 1. NanoTrans Facilitator Proxy (Cloudflare Worker) What it is: A Cloudflare Worker operated by NanoTrans that brokers authenticated requests to the Coinbase CDP x402 Facilitator. It signs requests with CDP credentials on your behalf so site owners do not need to manage CDP API keys. What data is sent, and when: Only after the site administrator opts in (checks “Enable Facilitator Proxy connection” in Settings > NanoTrans and saves the settings). On the first save after opt-in, the plugin sends the site URL to register the site and receive an API key. During each payment attempt (agent or human gasless), it forwards x402 payment data (EIP-712 signed USDC transfer authorization, payer wallet address, transaction hash, amount, recipient address) to verify and settle the payment. When Automatic Payout Distribution is enabled, the plugin also sends the seller wallet address after payments so the Worker can trigger the on-chain payout split. Default endpoint: https://nanotrans-facilitator-proxy.celee.workers.dev/ (configurable via the NANOTRANS_FACILITATOR_URL constant in wp-config.php). Terms of service: https://www.cloudflare.com/website-terms/ Privacy policy: https://www.cloudflare.com/privacypolicy/ 2. Coinbase Developer Platform (CDP) x402 Facilitator What it is: Coinbase’s official x402 Facilitator service that verifies EIP-712 USDC transfer authorizations and submits settled transfers on the Base Network. What data is sent, and when: Only during a payment attempt after Facilitator Proxy opt-in. The Cloudflare Worker forwards the signed USDC transfer authorization and payment requirements (payer address, receiver address, USDC amount, network ID, nonce, signature) so CDP can validate and broadcast the on-chain settlement. Endpoint: https://api.cdp.coinbase.com/platform/v2/x402 Terms of service: https://www.coinbase.com/legal/cloud/terms-of-service Privacy policy: https://www.coinbase.com/legal/privacy 3. Base Network JSON-RPC (public endpoint) What it is: A public JSON-RPC endpoint for Base Mainnet and Base Sepolia used to read on-chain transaction receipts and verify that a USDC transfer has been confirmed. What data is sent, and when: Only after a payment attempt. The plugin issues read-only RPC calls (eth_getTransactionReceipt, eth_call) with the submitted transaction hash and USDC contract address. Endpoint: https://mainnet.base.org (Base Mainnet) and https://sepolia.base.org (Base Sepolia). Terms of service: https://www.base.org/terms-of-service Privacy policy: https://www.coinbase.com/legal/privacy 4. Bundled ethers.js provider URLs (not called by this plugin) The ethers.js library bundled at assets/js/ethers.umd.min.js is the official upstream UMD build from https://github.com/ethers-io/ethers.js (version 6.16.0, MIT licensed). That bundle contains hard-coded provider URLs for common block explorers (listed below) as part of its default provider list. This plugin does NOT call any of these URLs. It only uses ethers.js for EIP-712 signing and USDC contract read/write through the user’s browser wallet (MetaMask or compatible) and the configured Base Network RPC endpoint listed above. No Etherscan/Arbiscan/Basescan API keys are configured, requested, or stored by this plugin. Domains present in the ethers.js bundle for reference (NOT contacted by this plugin): https://api.etherscan.io https://api-goerli.etherscan.io https://api-sepolia.etherscan.io https://api-holesky.etherscan.io https://api.arbiscan.io https://api-goerli.arbiscan.io https://api.basescan.org If a user integrates a custom ethers.js provider pointing to one of these endpoints, the operator of that endpoint is responsible for its own terms and privacy policy. For the default ethers.js usage in this plugin, no connection is made to any of them. ethers.js upstream license: https://github.com/ethers-io/ethers.js/blob/main/LICENSE.md No personal data (email, real name, IP logs) is sent to any of these services. Wallet addresses are pseudonymous blockchain identifiers required for USDC transfer settlement. Privacy Policy NanoTrans Agent Paywall processes the following data: Wallet addresses: Stored in the transactions table for payment verification and receipt lookup. Wallet addresses are pseudonymous blockchain identifiers, not directly linked to personal identity. User-Agent strings: Stored for request routing (human vs agent detection). Retained with transaction records. IP addresses: Used for rate limiting only (via WordPress transients). Not permanently stored. Wallet cookies: After a successful payment, an HMAC-signed cookie is set to grant permanent access to purchased content. The cookie contains a wallet address hash and a timestamp; no personal data is stored. This plugin does not use third-party tracking services and does not collect email addresses or personal information. For GDPR compliance, transaction records containing wallet addresses can be exported or deleted via the WordPress admin dashboard.
Top keywords
- https19×1.80%
- payment17×1.61%
- base13×1.23%
- x40213×1.23%
- usdc12×1.14%
- js11×1.04%
- wallet11×1.04%
- agent10×0.95%
- ethers10×0.95%
- facilitator10×0.95%
- ethers js9×0.85%
- api8×0.76%
AI Chatbot & Support Agent
You already know the old kind. A visitor asks a real question, the bot replies with a link to your FAQ page, and the visitor leaves. This is the other kind. Ultimo Bots puts a real AI support agent on your WordPress site. It answers from your own content, and then it does the actual work: books the meeting, looks up the order, saves the lead, and pulls you into the conversation when it matters. You describe it. It builds itself. There is no canvas to drag boxes around on. You open the builder and type what should happen, in your own words: “When someone asks about pricing, explain the plans and offer a demo call. If they want one, book it in my Cal.com and send the lead to HubSpot.” That is the entire build step. The agent is configured from that sentence. No code, no flowcharts, no developer, no agency. Changed your mind? Tell it. That is the edit step too. It doesn’t just answer. It acts. Connect the tools you already run, and the agent uses them mid-conversation: Books appointments in Cal.com, including reschedule and cancel, or hands over your Calendly link Takes payments and manages subscriptions through Stripe links. It can list, change, or cancel a subscription. Card details never enter the chat Saves and finds contacts in HubSpot, and subscribes visitors to Mailchimp with proper double opt-in Answers from your product catalog, with prices and stock, so “do you have this in blue” gets a real answer Calls your own API with your own credentials when you need something nobody else offers Captures leads inside the conversation and emails them to you the second they land Before the agent touches anything private, it emails the visitor a six-digit code and waits for it. Verified first, every time. One agent. Every channel. The same agent runs on your WordPress site, on a shareable chat link, in Facebook Messenger, Instagram DMs, Telegram, and Slack. You train it once and it shows up everywhere. Nothing to duplicate, nothing to keep in sync. It knows your business, and it will not invent Point it at your WordPress site and it reads it. Add PDFs, Word files, spreadsheets, Google Drive, OneDrive, Notion. Every answer is built from your material, and one click re-scans your site whenever it changes. When it does not know something, it says so and offers you instead. That one habit is why people trust it on a live site. It detects the language your visitor is writing in and answers in it. You configure nothing. You stay in control Write your rules in plain words and the agent holds them, even when a visitor pushes back. Watch conversations as they happen and jump in yourself with one click. The agent goes quiet the moment you start typing and picks up again when you leave. Get pinged in Slack, Telegram, Teams, or email whenever someone wants a human. Everything is included Every capability above is on every plan. Plans differ in volume, not in what your agent can do. No per-seat pricing, no per-resolution fees, no “contact sales”. Start with a free trial, then from $19 a month. Live in about two minutes Activate the plugin, answer a few questions, and your agent is on your site. That is the whole setup. External services This plugin connects to external services operated by Ultimo Bots to function. The integration is required to register your site securely and render your AI assistant. Below are the services, what they are used for, and what data is transmitted. Policies for all of them: Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy 1) Ultimo Bots Portal API – site registration What: https://portal.ultimo-bots.com/api/auth/wordpress/save_secret When: On plugin activation (and retried if the first attempt failed). Purpose: Register your WordPress site and exchange a site-specific identifier used for secure operations. Data sent: site_id (random UUID generated in your WordPress site), site_url (your WordPress home URL), site_secret (random secret generated in your WordPress site), and the admin user’s email, first_name, last_name (used only to prefill the onboarding form; transferred server-side, never placed in a URL). Data received: wordpress_secret_id (an internal identifier) and a one-time connect code (valid 15 minutes, single use). 2) Ultimo Bots Portal API – connect code What: https://portal.ultimo-bots.com/api/auth/wordpress/connect_code When: When you click “Connect to Ultimo Bots” in the plugin settings, and right before the one-time onboarding redirect. Purpose: Mint a fresh one-time connect code so the onboarding can be opened without any personal data in the URL. Data sent: site_id, site_secret, and the admin user’s email, first_name, last_name (prefill, server-side only). Data received: a one-time connect code. 3) Ultimo Bots Portal API – assistant lookup What: https://portal.ultimo-bots.com/api/wordpress/my_bot When: On WP-Admin page loads (throttled to once per 5 minutes), on the plugin settings page, and once daily via WP-Cron. Purpose: Fetch the ID of the assistant connected to this site, so the assistant activates automatically after onboarding. Data sent: site_id, site_secret. Data received: bot_id and its creation status. 4) Ultimo Bots Widget Configuration API What: https://portal.ultimo-bots.com/api/widget_configuration/{bot_id} When: On public page views where the assistant is displayed, and on activation to check whether an existing Bot ID is active. Purpose: Retrieve the widget configuration for your Bot ID (colors, sizes, welcome messages). Data sent: bot_id (path parameter); optionally host_url when provided by the widget for basic operational analytics. Data received: widget configuration JSON. 5) Ultimo Bots Widget Script Host – static asset What: https://robert-kloepsch.github.io/ultimo-bots-widget/dist/bundle.js When: On public page views where the assistant is displayed. Purpose: Load the widget client code. Data sent: standard CDN/HTTP request metadata (IP, user agent) as with any static asset request. Important: This plugin does not accept or store arbitrary HTML/JS/CSS from users. It only stores a Bot ID and generates safe markup internally. The widget script is properly enqueued via WordPress functions. Privacy This plugin communicates with Ultimo Bots services as described in External services. Please review: – Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy