01Discovery: the public mpp.dev services registry, plus anyone who self-registers at POST /api/mpp-index/register.
02Every listed origin gets a real, unpaid request to one of its actual advertised endpoints - a registry claim alone never counts.
03A listing counts as verified only when that request genuinely comes back with a WWW-Authenticate: Payment challenge.
04A crawl cycle re-probes every known origin every 5 minutes; a seller that stops answering drops out of the verified count on its own.
Two known scope limits, disclosed rather than hidden: sellers hosted as per-tenant paths on one shared gateway domain aren't discoverable yet, and self-serve registration for a seller not already in the mpp.dev registry can only verify at the bare origin root (MPP has no standard discovery path the way x402's /.well-known/x402 is).