TransX402 Docs
Integrations

WordPress Plugin

TransX402 Paywall 1.0 — IDRX paywalls on WordPress with server settlement, no application code.

Overview

TransX402 Paywall monetizes WordPress posts and pages with IDRX micropayments — no application code. Install the plugin, enter a secret API key and merchant wallet, set prices in IDR, and enable the paywall on individual posts.

The plugin bundles @transx402/client and settles in PHP. It does not load the public CDN script and has no shortcodes. Gutenberg is a document setting panel, not a block.

Requirements

  • WordPress 6.2+
  • PHP 8.0+
  • A TransX402 account (dashboard.transx402.com)
  • Visitors: MetaMask (EIP-1193) with IDRX on the matching network

Installation

From WordPress.org (preferred)

  1. Plugins → Add New → search TransX402 Paywall
  2. Install and activate

From ZIP

  1. Download transx402-paywall.zip from GitHub releases (folder inside the ZIP must be transx402-paywall/)
  2. Plugins → Add New → Upload Plugin
  3. Activate TransX402 Paywall

Configuration

Main settings

Settings → TransX402:

SettingDescription
API KeySecret ipk_sandbox_... or ipk_live_... — stored server-side only
Merchant WalletDashboard payout wallet (0x…). Required before the first payment
Facilitator URL (optional)Local override (http://localhost:3402). Leave empty for https://api.transx402.com
Default Price (IDR)Default price (e.g. 5000)
Preview ModeFirst paragraph / first N words / custom excerpt
Paywall StyleOverlay / Inline / Blur
Paywall MessageHeadline on the unlock card
Enable ForPublic post types (enable Page if you paywall pages)

Network and token params come from the facilitator GET /config (fetched in PHP). After a successful payment the merchant wallet may be cached in settings — that does not replace configuring it before the first charge.

Per-post / page

In the block editor: document sidebar TransX402 Paywall. Classic editor: the same fields in a side metabox.

SettingDescription
Enable PaywallGate this content
Price (IDR)Override default (optional)
Preview ContentCustom preview (optional)

Editors with edit_post see full content plus a notice. Preview the visitor paywall with ?transx402_as_visitor=1.

How it works

Settlement: server (canonical)

  1. Visitor opens a paywalled singular post → PHP truncates the_content and mounts .transx402-paywall-root
  2. Click Pay with IDRX → bundled client (settlement: "server") calls GET /wp-json/transx402/v1/content/{id}
  3. No payment header → 402 payment requirements
  4. Visitor signs in MetaMask (Permit2)
  5. Retry with PAYMENT-SIGNATURE → PHP POST {facilitator}/facilitate with the secret API key
  6. PHP GET /payments/{txHash} → row in {prefix}transx402_payments → HttpOnly cookie
  7. Full HTML returned; reload restores access from cookie + DB

The browser never sees the API key. PHP also localizes facilitator config; paywall.js intercepts client …/transx402/v1/config fetches so there is no public REST config proxy.

Excerpts, RSS/feeds, embeds, and core REST content/excerpt are gated for enabled post types.

For visitors

  1. See preview + paywall card
  2. Pay with IDRX → connect MetaMask on CAMP (sandbox) or Base (live)
  3. Approve Permit2 once (needs ETH for Path 4)
  4. Sign the payment
  5. Article unlocks; return visits are free via cookie + DB

Payment history

Settings → TransX402 Payments — date, post, payer, amount IDR, tx link, status.

Each {prefix}transx402_payments row stores tx hash, payer, amount, post ID, network, resource URL, verification time.

Paywall styles

  • Overlay (default) — centered card over truncated content
  • Inline — card after the preview
  • Blur — blurred preview with a floating pay button

WordPress REST API

Namespace: transx402/v1. Only these routes exist:

GET /wp-json/transx402/v1/content/{postId}

Full HTML after payment or an existing grant.

  1. Access cookie / DB grant → 200
  2. No PAYMENT-SIGNATURE → 402
  3. Header present → PHP facilitate, verify, insert DB, Set-Cookie → 200

Headers: PAYMENT-SIGNATURE (retry). Return visits use the HttpOnly access cookie, not a payer header.

200:

{
  "content": "<p>Full article HTML...</p>",
  "paid": true,
  "txHash": "0x...",
  "payer": "0x..."
}

GET /wp-json/transx402/v1/access/{postId}

{
  "granted": true,
  "payer": "0x..."
}

There is no GET /wp-json/transx402/v1/config or /config/public.

Nametransx402_access_{postId}
FlagsHttpOnly, 1 year, SameSite=Lax, Secure on HTTPS

Disclose this cookie in your privacy policy / CMP where required. Database grants are the source of truth.

Compatibility

ComponentSupport
WordPress6.2+
PHP8.0+
EditorGutenberg (document panel), Classic metabox
CachingExclude paywalled URLs from full-page cache; preview HTML is cache-safe
SEOPreview is indexable; full content is behind REST

Testing with sandbox

  1. Secret sandbox key (ipk_sandbox_...) + merchant wallet in settings
  2. Enable paywall on a post; open logged out or ?transx402_as_visitor=1
  3. Pay with test IDRX on CAMP Testnet (Sandbox)
  4. Confirm Settings → TransX402 Payments
  5. Go live: ipk_live_... + production wallet; clear local facilitator URL

Security

  • Secret API key in wp_options — never in the browser
  • Full post HTML is not in the initial page for paywalled posts
  • PAYMENT-SIGNATURE processed server-side
  • Verify against TransX402 before DB insert
  • No private keys or Permit2 signatures stored in WordPress