Keep the controller cold. Sign a side PDA once that names a hot payment key the gateway and x402 middleware will trust. Rotate the hot key any time without touching the bond. On-chain dual-signer on record_action is parked until the audit prices it in.
Connect a Solana wallet to submit this transaction.