X402 REPUTATION INDEX
We don't rate x402 endpoints. We buy from them and publish the receipt.
Independent reputation verdicts for 57,283 x402 payment endpoints (CDP Bazaar, Base + USDC). We probe the 402 handshake, attribute facilitator-confirmed on-chain settlements, detect wash traffic and honeypots — and then spend real USDC to find out whether an endpoint will actually sell to you, and whether what it sells is real. 894 endpoints have passed that test, backed by 924 on-chain settlements.
97.2% of the 57,283 indexed endpoints are not currently rated safe to pay.
| Trustworthy | 1,597 | aged, real diverse settlement history, clean 402 — top tier requires a real paid call that delivered |
| Caution | 27,049 | works, but thin or unattributable signals (shared payTo, low history, no schema) |
| Avoid | 55 | honeypots (paid then denied), non-delivery, pay-to-mint, wash traffic |
| Dead | 26,209 | unreachable or broken x402 handshake |
| Unknown | 2,373 | not yet probed (mostly templated URLs) |
What we found by actually buying
Anyone can probe a 402 handshake. The two questions a handshake can't answer are will this endpoint sell to me? and is what it sold me real? We've now attempted a real purchase against 1,984 endpoints:
| 1,034 | refused the sale | answered their own 402 challenge, then rejected the paid request (mostly 400/404/405/422) — 52% of everything we tried to buy |
| 926 | took the money | settled on-chain — $9.94 USDC actually spent |
| 894 | delivered real data | a response we could classify as genuine content, not a shell |
| 30 | 200, but empty | HTTP 200 carrying an error payload, an empty result, or nothing meaningful — including one that took payment and returned a Node.js crash. 200 is not delivery. |
| 26 | paid, no goods | settled on-chain and then returned a non-200. Money gone, nothing back |
Caveat we'd rather state than hide: some refusals are endpoints needing request parameters the catalog never declares. That is itself the finding — catalog metadata is not sufficient to complete a purchase.
Proof, not claims
Every verified delivery corresponds to USDC leaving a wallet on Base:
924 settlement transactions, $9.94 USDC
spent buying from strangers' APIs so you don't have to. Check it against the chain yourself; that is
the point. Wallets bought from so far: 0xb92a…1E0f.
We rotate buying wallets. A transaction hash names its payer, so the address we buy from can't be secret — rotation is what stops an endpoint from whitelisting a known auditor and serving it better responses than it serves you.
The full ledger is public and free — every settlement, its transaction hash, and what came back:
curl https://x402rep.invoitech.com/api/v1/ledger
Per-endpoint verdicts carry their own receipt too: the delivery.settlement block in
every lookup names the exact transaction that bought the response we're showing you.
Query it — HTTP (10 free/day, then $0.01 USDC via x402)
curl "https://x402rep.invoitech.com/api/v1/reputation?url=<endpoint_url>"
Your first 10 lookups per day answer for free — try it right now, no wallet needed. After that the endpoint returns 402 Payment Required with an x402 challenge, and any buyer client (e.g. @x402/fetch) pays $0.01 USDC on Base and retries automatically. Meta, but that's the point: we eat the protocol we audit. Add &pay=1 to pay immediately and skip the allowance.
Query it — MCP
Give your agent the query_reputation tool:
claude mcp add --transport http x402-reputation https://x402rep.invoitech.com/mcp
Single lookups share the same free daily allowance as HTTP. batch_reputation
(up to 50 endpoints per call) needs an API key — add --header "x-api-key: <key>".
Works with any MCP client that speaks Streamable HTTP; a local stdio flavour is in the repo.
Three ways to pay for it
| Free | 10/day per IP | single lookups, HTTP or MCP — enough to evaluate, share, and try |
| Per lookup | $0.01 USDC | x402 over HTTP, no account, no signup — agents pay automatically |
| API key | daily quota | skips payment, works on HTTP + MCP, and unlocks bulk batch_reputation |
Want a key? Get in touch — quotas are set per account.
How verdicts are made
1. Enumerate the CDP Bazaar catalog (Base + USDC). 2. Probe every endpoint's unpaid 402
handshake — reachability, challenge validity, latency, declared schemas. 3. Attribute on-chain
settlements: USDC transfers count only when sent by a known facilitator (~40 tracked), so ordinary
transfers and self-reported volume don't inflate reputation. 4. Break payTo collisions: a single
payout address can back thousands of endpoints — our record is
14,190 — so a dead endpoint inherits its working siblings' settlement history.
We refuse to grade shared-payTo endpoints as Trustworthy on on-chain signals alone; they have to pass a
real paid test. Nobody else does this. 5. Detect wash: micro-transaction clusters and pay-to-mint
patterns. 6. Pay-test: we spend real USDC, record whether the sale completed, classify the
response body (data / error / empty / trivial), and keep a truncated redacted sample.
Verdicts recompute continuously; every response carries last_probed and
verdict_computed_at.
Live status
curl https://x402rep.invoitech.com/api/v1/status
Read the data
We tried to buy from 1,984 x402 endpoints. 52% wouldn't complete the sale →