1. Connect
Any browser wallet, or a wallet app on your phone. We ask for your address and for Arc to be the active network, nothing else.
2. Choose what to buy
Pick any, a fraction of a cent each: live facts about the Arc network, what a wallet or a transaction holds, the text of a web page, the state of a software package or a domain, exchange rates, Wikipedia. Not sure? Leave it as it is: the price of Bitcoin on Arc, from real trades.
3. Pay and fetch
You sign a permission to move one exact amount to one address, once, within two minutes. There is no transaction to send and no gas to pay.
What your wallet will show, so it does not surprise you. Some wallets, Rabby for one, label this a “token approval” and flag our address as new to you. That label is right to make you look twice, so look at the amount: it says 0.0030, not “unlimited”. This is not the kind of approval that lets someone empty a wallet. It can move three tenths of a cent, to 0x33b3…Ea74, one time. Check those two values in the wallet before you sign. If either is different, cancel.
What just happened
The API answered 402 Payment Required with a price. Your wallet signed an EIP-3009 authorization: a permission to move that exact amount to that exact address before it expires. Our facilitator checked it, ran the request, and only then submitted the transfer and paid its gas. If the request had failed, the authorization would never have been used. Try the route that fails on purpose to see it.
An agent does the same thing without a person in the loop, under a spending policy it cannot change: install the agent.