Skip to main content
Authorize Circle Gateway to transfer USDC from your Gateway balance by signing an EIP-3009 TransferWithAuthorization message directly. Sign manually when integrating a custom payment workflow, building a non-JavaScript client, or debugging what the SDK handles automatically.

Prerequisites

Before you begin, ensure that you’ve:
  • Generated an EVM wallet private key for signing.
  • Deposited USDC into a Gateway Wallet contract (see the buyer quickstart).
  • Familiarized yourself with EIP-712 typed data signing.
  • Installed the viem library (npm install viem).

Steps

1

Construct the EIP-712 domain

Gateway uses a custom EIP-712 domain named GatewayWalletBatched. This is specific to Gateway’s batching feature and is not the standard USDC domain.
sign.ts
The verifyingContract is the GatewayWallet contract address for the blockchain you are transacting on. Find the address for your target blockchain in the EVM contract addresses reference. You can also retrieve it programmatically using getVerifyingContract() from the SDK or from the 402 response’s accepts array (in the extra.verifyingContract field).
The chainId must be the standard EVM chain ID for your target network (for example, 5042002 for Arc Testnet), not the Gateway domain identifier. Using the wrong chain ID causes the signature to fail silently.
2

Define the typed data

The TransferWithAuthorization type follows the EIP-3009 specification:
sign.ts
Populate the message fields.USDC uses 6 decimal places: $1.00 = 1000000, $0.01 = 10000, $0.001 = 1000. Always convert dollar amounts to base units before signing.
sign.ts
The validBefore timestamp must be at least 3 days in the future. Gateway rejects signatures with shorter validity periods to ensure there is enough time to include them in a settlement batch.
3

Sign the typed data

Use the viem library’s signTypedData to produce the EIP-712 signature:
sign.ts
4

Assemble and send the payment payload

Encode the payment payload as base64 JSON and attach it to your HTTP request in the Payment-Signature header. The server-side facilitator settles this payment through the Settle x402 Payment API endpoint:
sign.ts

Alternative: sign through the x402 client scheme

If you are integrating with an existing x402 client (such as @x402/core), use BatchEvmScheme instead of constructing the payload manually. It handles domain construction, nonce generation, and payload encoding:
sign-x402.ts

Troubleshoot rejected signatures

Gateway returns invalid_signature for any EIP-712 domain or field mismatch without specifying which field is wrong. If your signature is rejected, check every item in this list:
  • Domain name must be exactly "GatewayWalletBatched". Common mistakes include "GatewayWallet", "Gateway", and "USDC".
  • verifyingContract must be the GatewayWallet contract address, not the USDC token address or GatewayMinter. See EVM contract addresses for the correct address on each blockchain.
  • chainId must be the standard EVM chain ID (for example, 5042002 for Arc Testnet). Do not use the Gateway domain identifier.
  • nonce must be a unique random 32-byte value for every payment. Reusing a nonce causes the same invalid_signature error.
  • validBefore must be at least 3 days in the future. Shorter validity periods are rejected with authorization_validity_too_short.
  • value must be in USDC base units (6 decimals). Passing a dollar amount instead of base units causes an amount mismatch.
  • from must match the address derived from the private key that signed the message.
For the full list of error codes, see the error reference.
The EIP-712 domain for payment authorizations (GatewayWalletBatched) is different from the domain used for Gateway withdrawal and crosschain transfer operations (GatewayWallet). If you are building manual signing for both payments and withdrawals, use the correct domain for each operation. The SDK’s client.withdraw() and client.pay() methods handle this automatically.