SDK
Burnbound has a TypeScript client with payFetch and wrapFetchWithPayment, but it is not published on npm yet. There is no package to install today. To give an agent paid access to x402 APIs now, use the MCP server @burnbound/mcp, which runs this same client inside.
Is there a JavaScript or TypeScript SDK I can install?
Not yet. The client that pays x402 APIs under a Burnbound policy is used internally by @burnbound/mcp, but it has not been released as a public npm package, so there is no package name to install. This page will give install instructions when it is published.
Until then:
- For agents in Claude Code, Cursor or another MCP client, install the MCP server. See the Quickstart.
- For agent frameworks that support MCP tools, connect
npx -y @burnbound/mcpas a stdio MCP server, withBURNBOUND_KEYin its environment.
What will the SDK do?
The SDK makes a fetch that pays x402 under your Burnbound policy. It is the same flow fetch_paid follows: on HTTP 402 it asks Burnbound to authorize the payment, gets it signed by your wallet, retries the request once with the payment, and reports the receipt. The interface below is the current one and may change before it is published.
wrapFetchWithPayment(options)returns a drop-in replacement forfetch. A denied payment or one waiting for approval throws an error that carries Burnbound's decision.payFetch(options, input, init)makes one purchase attempt and returns what happened:free(no payment was needed),paid(withintentId,idempotencyKey,mode,replayedand the receipt),denied(with the reason codes) orstep_up(with theapprovalIdto poll).
Both take the Burnbound API base URL, the agent key, the agent id and, for client-side signing, a signer. Like the MCP server, they send the key only to the Burnbound API, never to the seller, and they never follow a redirect after paying.
Should I wait for the SDK or use the MCP server?
Use the MCP server unless you need to pay from your own code outside an MCP client. It is published, it adds client-side guards that a plain fetch wrapper does not have (allowed hosts checked before any request, private addresses blocked, seller responses marked as untrusted, the key kept out of tool results), and it works with every MCP client.