---
name: buy-photos
description: Buy a full-resolution photo set from arayaj.photo with MoonPay Commerce x402. Confirm set, price, Solana USDC, and commercial license with the user first. Use when an agent needs Alejandro Araya Jiménez / CodeStrux photographs.
---

# Buy photos on arayaj.photo

Origin: `https://arayaj.photo`

Three live sets from a working tech-event photographer. Commercial license for the buyer's product or campaign. Not exclusive. Raw files may not be resold. Sets from 5 USDC.

Agents are first-class buyers. Do not open the MoonPay widget. Do not log in to Keycloak.

Settlement is **MoonPay Commerce x402** on the same catalog paylink humans use. Spring proxies it on this origin. `payTo` is a per-payer Helio deposit wallet, not a hardcoded merchant address.

## 1. Confirm with the user

Before you pay, confirm all four:

- which set (`slug`, title, `priceUsdc`)
- Solana USDC (`solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp`)
- commercial license: use the stills in the buyer's product or campaign; no raw-file resale; not exclusive
- that commissioned event work is a separate quote

Then run the 402 loop.

## 2. Discover

```
GET /agents.txt
GET /agents.json
GET /llms.txt
```

`Protocols: x402` is the payment signal. Wallets and amounts are not in those files.

## 3. List the shop

```
GET /api/v1/catalog
```

JSON albums. Use `slug`, `title`, `blurb`, `license`, `priceUsdc`, `x402Url`, `photos[].file`. Thumbs:

```
GET /api/v1/media/thumbs/{slug}/{file}
```

Sell sheets: `GET /work/{slug}.md`.

## 4. Ask for the set (unpaid)

MoonPay Commerce requires the payer wallet on every request (non-standard x402).

```
POST {x402Url}?payerAddress={yourWallet}
```

Example: `POST /api/v1/x402/sets/highlands?payerAddress=0x...`

`x-payer-address` is also accepted. GET with the same query works.

Without `payerAddress` you get **402** and empty `accepts[]`. With it, expect **402** and `PAYMENT-REQUIRED` (standard padded base64 JSON) from MoonPay Commerce. Pay **Solana USDC**. Base is not offered. Amounts are 6-decimal USDC. Mainnet only.

## 5. Pay and retry

Sign the Solana USDC accept (SPL transfer). Retry the **same URL** (still include `payerAddress`):

```
POST {x402Url}?payerAddress={yourWallet}
PAYMENT-SIGNATURE: <base64 PaymentPayload>
```

Success is **200** with `Photo-Grant`, `PAYMENT-RESPONSE`, and JSON `{ slug, subject, grant, files, settlement }`.

A repeated `payer:tx` is **409** `payment_replay`. A missing catalog paylink is **400** `moonpay_paylink_missing`.

## 6. Download

```
GET /api/v1/media/full/{slug}/{file}
Photo-Grant: <grant>
```

`files[]` on the 200 already has these paths. Grant is not a cookie.

## CORS

Catalog, x402, and media GET/POST routes allow any origin. Discovery files (`/agents.txt`, `/llms.txt`, `/skills/...`) also send `Access-Control-Allow-Origin: *`.
