AWS details pay-per-inference payments for Bedrock agents
Amazon Bedrock AgentCore payments processes HTTP 402 challenges, signs wallet authorizations and enforces session budgets for per-request services. AWS says Incarna uses the flow with BlockRun in production, but its speed, volume and pricing claims remain unverified.
AWS has explained how Amazon Bedrock AgentCore payments enables AI agents to buy model inference one request at a time, with spending limits enforced outside the model. The company says Incarna uses the managed payment capability in production so its agents can pay BlockRun for individual inference calls.
Under the flow AWS describes, an x402-compatible endpoint first returns an HTTP 402 Payment Required challenge with the price of the call. AgentCore payments checks the quote against the payment session’s limit, uses the configured wallet provider to sign an authorization and returns cryptographic proof to the merchant. BlockRun then verifies the signature, serves the inference and records the charge. The model neither holds the wallet key nor controls the session ceiling.
AgentCore payments documentation says every session has a maximum spend amount, currency and expiration time. Requests are denied when the budget is reached or the session expires. AWS also says a failed signing operation does not consume the session budget, including when the service rolls back a deduction made before the failure.
The service supports two x402 payment schemes. The exact scheme applies when the price is known in advance. With upto, the agent authorizes a maximum and the provider settles actual usage up to that ceiling. AWS says these controls run in deterministic infrastructure rather than in the agent’s prompt, preventing a prompt from raising the configured limit.
For Incarna’s deployment, AWS says every agent receives a customer-owned wallet provisioned through Coinbase CDP, with delegated spending authority. AgentCore references the wallet and signs on the agent’s behalf without exposing its key to the agent. According to AWS, Incarna uses USDC on the Base network, where each settlement can be checked on-chain. AWS separately describes the funds-flow boundary: money moves between the user’s embedded wallet and the merchant through the wallet provider’s infrastructure, and AWS says it does not enter the funds flow.
AWS says the payment service can send logs for every data-plane call to Amazon CloudWatch and traces to AWS X-Ray or AgentCore Observability. The records cover successful and rejected ProcessPayment calls, along with calls that fail at the wallet layer. Together with the on-chain settlement record, they give operators an audit trail.
The deployment figures come from AWS and have not been independently verified. AWS says Incarna completed the integration in three days—one day to build and two days to test—using about 200 lines of application code, against an internal estimate of two to three months. It also says Incarna agents processed more than 1,000 beta payments priced from $0.001 to $0.05 per call, with each payment settled separately on-chain. The supplied research identified no public transaction set linking those figures to the beta deployment.
AWS describes BlockRun as a pay-as-you-go inference router that served more than 90 models from more than 15 providers when AWS published its October 8 post. BlockRun’s own site describes a single endpoint that quotes calls before execution, accepts signed USDC authorization and settles on Base, but it does not independently substantiate Incarna’s reported deployment metrics.
For context, a separate AgentCore production workflow uses the managed runtime for recurring Shopify app updates while retaining merchant approval before publication.
AgentCore payments became generally available on August 18 after a preview launched in May, AWS said. The general-availability release added support for the Machine Payments Protocol and the x402 upto scheme alongside the per-session controls used in the BlockRun flow.
More news

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts

AWS brings managed OAuth consent to Bedrock AgentCore

AWS Outlines Three Policies for AgentCore Memory
