x402 security audit
GET /api/x402-auditGrade any x402 seller's payment-security posture from the outside - a read-only black-box check mapped to the 'Five Attacks on x402' failure modes. Send GET /api/x402-audit with the required field url and pay $0.01 per call over x402 or MPP (there is no free tier). It returns a JSON object with url, reachable, status, paymentRequired, x402Version and 4 more.
Probes the URL's 402 challenge (never pays) and scores TLS transport, gated-response cache hygiene (Attack III / cache leakage), error/info-leak hygiene, and payment-terms well-formedness, then returns a letter grade with per-check findings and an honest note on what only insider/active testing can confirm. ?url=https://api.example.com/paid&method=GET
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
url | string | yes | URL of the paid resource to audit Also accepted as link, uri, href, page. |
method | string | no | HTTP method to probe with (default GET) |
Example request
curl -i "https://agent402.tools/api/x402-audit?url=https%3A%2F%2Fagent402.tools%2Fapi%2Fhash&method=POST"
Without payment this returns HTTP 402 Payment Required with the exact price for x402-audit; any x402 v2 or MPP client pays it and retries.
Example response
{
"url": "https://api.example.com/paid",
"reachable": true,
"status": 402,
"paymentRequired": true,
"x402Version": 2,
"score": 92,
"grade": "A",
"checks": [
{
"id": "transport-tls",
"title": "Payment challenge served over TLS",
"attack": "credential interception",
"severity": "high",
"status": "pass",
"detail": "https"
},
{
"id": "cache-hygiene",
"title": "Gated response is not shared-cacheable",
"attack": "III - cache leakage",
"severity": "high",
"status": "pass",
"detail": "Cache-Control: no-store, private"
}
],
"summary": "A (92/100) - 6 passed, 1 warning, 0 failed. Note: replay/idempotency (II) and router Sybil (IV) can't be graded from outside."
}
| Field | Type | Always present | In the example |
|---|---|---|---|
url | string | no | https://api.example.com/paid |
reachable | boolean | no | true |
status | number | no | 402 |
paymentRequired | boolean | no | true |
x402Version | number | no | 2 |
score | number | no | 92 |
grade | string | no | A |
checks | array of objects | no | 2 items in the example |
summary | string | no | A (92/100) - 6 passed, 1 warning, 0 failed. Note: replay/idempotency (II) and... |
From an MCP client
catalog.call {
"slug": "x402-audit",
"params": {
"url": "https://agent402.tools/api/hash",
"method": "POST"
}
}
The hosted connector at https://agent402.tools/mcp needs a payment for x402-audit; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.
Errors and behavior
urlis required. An input the tool rejects returns an HTTP 4xx whose body carrieserror,tool,expected,requiredandexample, so the caller can correct it.- A paid call that ends in any status of 400 or above is not charged: settlement is cancelled when the tool fails.
- Wallet-only: this tool reaches the network or stored state, so it has no proof-of-work tier. A prepaid card-credits key (
Authorization: Bearer a402_...) also pays it. - A
POSTwith a JSON body to /api/x402-audit is served as this GET, with the body as the input. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again.
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/api/x402-audit?url=https%3A%2F%2Fagent402.tools%2Fapi%2Fhash&method=POST");
Related tools
My usage (wallet-keyed purchase history)
POST /api/my-usageYour own purchase history, keyed to the wallet that pays for the call - no wallet parameter, no signup: the x402 payment…
Certificate transparency search
POST /api/cert-transparencySearch public Certificate Transparency logs (via crt.sh) for every cert issued to a domain. Returns the cert list plus a…
Domain security & deliverability audit (graded)
POST /v1/domain-auditHand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…
Domain security audit - PRO (attack surface + stack)
POST /v1/domain-audit/proThe deeper tier: everything in the standard audit plus the attack surface from Certificate Transparency logs (subdomains…
Rate a call you paid for
POST /api/feedbackTell this server whether a call you paid for delivered what it promised. Bound to the receipt: give it the settlement tr…
Receipts (your settled calls, as accounting rows)
POST /api/receiptsYour own settled calls in the shape a finance system posts: one row per payment with what was bought, the amount settled…