x402 security audit

$0.01 per call · USDC via x402 · GET /api/x402-audit

Grade any x402 seller's payment-security posture from the outside - a read-only black-box check mapped to the 'Five Attacks on x402' failure modes. Send GET /api/x402-audit with the required field url and pay $0.01 per call over x402 or MPP (there is no free tier). It returns a JSON object with url, reachable, status, paymentRequired, x402Version and 4 more.

Probes the URL's 402 challenge (never pays) and scores TLS transport, gated-response cache hygiene (Attack III / cache leakage), error/info-leak hygiene, and payment-terms well-formedness, then returns a letter grade with per-check findings and an honest note on what only insider/active testing can confirm. ?url=https://api.example.com/paid&method=GET

Category: Payments & x402 · Tags: x402 audit security posture cache tls grade five-attacks

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
urlstringyesURL of the paid resource to audit Also accepted as link, uri, href, page.
methodstringnoHTTP method to probe with (default GET)

Example request

curl -i "https://agent402.tools/api/x402-audit?url=https%3A%2F%2Fagent402.tools%2Fapi%2Fhash&method=POST"

Without payment this returns HTTP 402 Payment Required with the exact price for x402-audit; any x402 v2 or MPP client pays it and retries.

Example response

{
  "url": "https://api.example.com/paid",
  "reachable": true,
  "status": 402,
  "paymentRequired": true,
  "x402Version": 2,
  "score": 92,
  "grade": "A",
  "checks": [
    {
      "id": "transport-tls",
      "title": "Payment challenge served over TLS",
      "attack": "credential interception",
      "severity": "high",
      "status": "pass",
      "detail": "https"
    },
    {
      "id": "cache-hygiene",
      "title": "Gated response is not shared-cacheable",
      "attack": "III - cache leakage",
      "severity": "high",
      "status": "pass",
      "detail": "Cache-Control: no-store, private"
    }
  ],
  "summary": "A (92/100) - 6 passed, 1 warning, 0 failed. Note: replay/idempotency (II) and router Sybil (IV) can't be graded from outside."
}
FieldTypeAlways presentIn the example
urlstringnohttps://api.example.com/paid
reachablebooleannotrue
statusnumberno402
paymentRequiredbooleannotrue
x402Versionnumberno2
scorenumberno92
gradestringnoA
checksarray of objectsno2 items in the example
summarystringnoA (92/100) - 6 passed, 1 warning, 0 failed. Note: replay/idempotency (II) and...

From an MCP client

catalog.call {
  "slug": "x402-audit",
  "params": {
    "url": "https://agent402.tools/api/hash",
    "method": "POST"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for x402-audit; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/x402-audit?url=https%3A%2F%2Fagent402.tools%2Fapi%2Fhash&method=POST");

Related tools

My usage (wallet-keyed purchase history)

$0.005 · POST /api/my-usage

Your own purchase history, keyed to the wallet that pays for the call - no wallet parameter, no signup: the x402 payment…

Certificate transparency search

$0.005 · POST /api/cert-transparency

Search public Certificate Transparency logs (via crt.sh) for every cert issued to a domain. Returns the cert list plus a…

Domain security & deliverability audit (graded)

$0.60 · POST /v1/domain-audit

Hand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…

Domain security audit - PRO (attack surface + stack)

$0.85 · POST /v1/domain-audit/pro

The deeper tier: everything in the standard audit plus the attack surface from Certificate Transparency logs (subdomains…

Rate a call you paid for

$0.001 · POST /api/feedback

Tell this server whether a call you paid for delivered what it promised. Bound to the receipt: give it the settlement tr…

Receipts (your settled calls, as accounting rows)

$0.005 · POST /api/receipts

Your own settled calls in the shape a finance system posts: one row per payment with what was bought, the amount settled…