WordPress Plugin
TransX402 Paywall 1.0 — IDRX paywalls on WordPress with server settlement, no application code.
Overview
TransX402 Paywall monetizes WordPress posts and pages with IDRX micropayments — no application code. Install the plugin, enter a secret API key and merchant wallet, set prices in IDR, and enable the paywall on individual posts.
- WordPress.org: wordpress.org/plugins/transx402-paywall
- Source: github.com/campinvestment/transx402-wordpress-plugin
- Plugin slug / folder:
transx402-paywall(v1.0.0)
The plugin bundles @transx402/client and settles in PHP. It does not load the public CDN script and has no shortcodes. Gutenberg is a document setting panel, not a block.
Requirements
- WordPress 6.2+
- PHP 8.0+
- A TransX402 account (dashboard.transx402.com)
- Visitors: MetaMask (EIP-1193) with IDRX on the matching network
Installation
From WordPress.org (preferred)
- Plugins → Add New → search TransX402 Paywall
- Install and activate
From ZIP
- Download
transx402-paywall.zipfrom GitHub releases (folder inside the ZIP must betransx402-paywall/) - Plugins → Add New → Upload Plugin
- Activate TransX402 Paywall
Configuration
Main settings
Settings → TransX402:
| Setting | Description |
|---|---|
| API Key | Secret ipk_sandbox_... or ipk_live_... — stored server-side only |
| Merchant Wallet | Dashboard payout wallet (0x…). Required before the first payment |
| Facilitator URL (optional) | Local override (http://localhost:3402). Leave empty for https://api.transx402.com |
| Default Price (IDR) | Default price (e.g. 5000) |
| Preview Mode | First paragraph / first N words / custom excerpt |
| Paywall Style | Overlay / Inline / Blur |
| Paywall Message | Headline on the unlock card |
| Enable For | Public post types (enable Page if you paywall pages) |
Network and token params come from the facilitator GET /config (fetched in PHP). After a successful payment the merchant wallet may be cached in settings — that does not replace configuring it before the first charge.
Per-post / page
In the block editor: document sidebar TransX402 Paywall. Classic editor: the same fields in a side metabox.
| Setting | Description |
|---|---|
| Enable Paywall | Gate this content |
| Price (IDR) | Override default (optional) |
| Preview Content | Custom preview (optional) |
Editors with edit_post see full content plus a notice. Preview the visitor paywall with ?transx402_as_visitor=1.
How it works
Settlement: server (canonical)
- Visitor opens a paywalled singular post → PHP truncates
the_contentand mounts.transx402-paywall-root - Click Pay with IDRX → bundled client (
settlement: "server") callsGET /wp-json/transx402/v1/content/{id} - No payment header → 402 payment requirements
- Visitor signs in MetaMask (Permit2)
- Retry with
PAYMENT-SIGNATURE→ PHPPOST {facilitator}/facilitatewith the secret API key - PHP
GET /payments/{txHash}→ row in{prefix}transx402_payments→ HttpOnly cookie - Full HTML returned; reload restores access from cookie + DB
The browser never sees the API key. PHP also localizes facilitator config; paywall.js intercepts client …/transx402/v1/config fetches so there is no public REST config proxy.
Excerpts, RSS/feeds, embeds, and core REST content/excerpt are gated for enabled post types.
For visitors
- See preview + paywall card
- Pay with IDRX → connect MetaMask on CAMP (sandbox) or Base (live)
- Approve Permit2 once (needs ETH for Path 4)
- Sign the payment
- Article unlocks; return visits are free via cookie + DB
Payment history
Settings → TransX402 Payments — date, post, payer, amount IDR, tx link, status.
Each {prefix}transx402_payments row stores tx hash, payer, amount, post ID, network, resource URL, verification time.
Paywall styles
- Overlay (default) — centered card over truncated content
- Inline — card after the preview
- Blur — blurred preview with a floating pay button
WordPress REST API
Namespace: transx402/v1. Only these routes exist:
GET /wp-json/transx402/v1/content/{postId}
Full HTML after payment or an existing grant.
- Access cookie / DB grant → 200
- No
PAYMENT-SIGNATURE→ 402 - Header present → PHP facilitate, verify, insert DB, Set-Cookie → 200
Headers: PAYMENT-SIGNATURE (retry). Return visits use the HttpOnly access cookie, not a payer header.
200:
GET /wp-json/transx402/v1/access/{postId}
There is no GET /wp-json/transx402/v1/config or /config/public.
Access cookie
| Name | transx402_access_{postId} |
| Flags | HttpOnly, 1 year, SameSite=Lax, Secure on HTTPS |
Disclose this cookie in your privacy policy / CMP where required. Database grants are the source of truth.
Compatibility
| Component | Support |
|---|---|
| WordPress | 6.2+ |
| PHP | 8.0+ |
| Editor | Gutenberg (document panel), Classic metabox |
| Caching | Exclude paywalled URLs from full-page cache; preview HTML is cache-safe |
| SEO | Preview is indexable; full content is behind REST |
Testing with sandbox
- Secret sandbox key (
ipk_sandbox_...) + merchant wallet in settings - Enable paywall on a post; open logged out or
?transx402_as_visitor=1 - Pay with test IDRX on CAMP Testnet (Sandbox)
- Confirm Settings → TransX402 Payments
- Go live:
ipk_live_...+ production wallet; clear local facilitator URL
Security
- Secret API key in
wp_options— never in the browser - Full post HTML is not in the initial page for paywalled posts
PAYMENT-SIGNATUREprocessed server-side- Verify against TransX402 before DB insert
- No private keys or Permit2 signatures stored in WordPress