OFAC screening for payment APIs

Payment APIs move money, but the API provider may not screen for OFAC. The developer building on them bears ultimate liability.

TL;DR

TL;DR: Payment APIs such as x402 move money but do not necessarily screen. The developer who builds on them must add OFAC screening before authorizing a payment.

The liability gap

Protocols like x402, AP2, ACP, and Coinbase AgentKit move money but do not screen counterparties. That means screening is your job as the developer. OFAC applies strict liability, so a missed check can be a violation even without intent. Delegating the payment does not delegate the compliance.

Screen at your layer

Insert a check between "payment requested" and "payment authorized." Verify the recipient wallet against listed crypto wallets and the counterparty name against SDN names before releasing funds. Apply the 50 Percent Rule to majority owned entities.

Fit into the flow

A screening API that returns in under 100 ms keeps the payment path fast. Use the same check for every provider, so your compliance posture is consistent whether you build on x402, MCP, or a hosted gateway. Log each screen as evidence, because the record belongs to you, not to the API provider.

Who keeps the record

Even when an upstream provider screens, the developer should keep a record of its own check. Your compliance posture is yours to defend, and the provider's log may not be available to you. Running a screen at your layer and storing the result gives you evidence that is independent of the provider's claims.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →