X402 REPUTATION INDEX

We don't rate x402 endpoints. We buy from them and publish the receipt.

Independent reputation verdicts for 57,283 x402 payment endpoints (CDP Bazaar, Base + USDC). We probe the 402 handshake, attribute facilitator-confirmed on-chain settlements, detect wash traffic and honeypots — and then spend real USDC to find out whether an endpoint will actually sell to you, and whether what it sells is real. 894 endpoints have passed that test, backed by 924 on-chain settlements.

97.2% of the 57,283 indexed endpoints are not currently rated safe to pay.

57,283endpoints indexed
96%probe coverage
45.8%confirmed dead
1,597trustworthy
894delivery-verified by purchase
Trustworthy1,597aged, real diverse settlement history, clean 402 — top tier requires a real paid call that delivered
Caution27,049works, but thin or unattributable signals (shared payTo, low history, no schema)
Avoid55honeypots (paid then denied), non-delivery, pay-to-mint, wash traffic
Dead26,209unreachable or broken x402 handshake
Unknown2,373not yet probed (mostly templated URLs)

What we found by actually buying

Anyone can probe a 402 handshake. The two questions a handshake can't answer are will this endpoint sell to me? and is what it sold me real? We've now attempted a real purchase against 1,984 endpoints:

1,034refused the sale answered their own 402 challenge, then rejected the paid request (mostly 400/404/405/422) — 52% of everything we tried to buy
926took the money settled on-chain — $9.94 USDC actually spent
894delivered real data a response we could classify as genuine content, not a shell
30200, but empty HTTP 200 carrying an error payload, an empty result, or nothing meaningful — including one that took payment and returned a Node.js crash. 200 is not delivery.
26paid, no goods settled on-chain and then returned a non-200. Money gone, nothing back

Caveat we'd rather state than hide: some refusals are endpoints needing request parameters the catalog never declares. That is itself the finding — catalog metadata is not sufficient to complete a purchase.

Proof, not claims

Every verified delivery corresponds to USDC leaving a wallet on Base: 924 settlement transactions, $9.94 USDC spent buying from strangers' APIs so you don't have to. Check it against the chain yourself; that is the point. Wallets bought from so far: 0xb92a…1E0f.

We rotate buying wallets. A transaction hash names its payer, so the address we buy from can't be secret — rotation is what stops an endpoint from whitelisting a known auditor and serving it better responses than it serves you.

The full ledger is public and free — every settlement, its transaction hash, and what came back:

curl https://x402rep.invoitech.com/api/v1/ledger

Per-endpoint verdicts carry their own receipt too: the delivery.settlement block in every lookup names the exact transaction that bought the response we're showing you.

Query it — HTTP (10 free/day, then $0.01 USDC via x402)

curl "https://x402rep.invoitech.com/api/v1/reputation?url=<endpoint_url>"

Your first 10 lookups per day answer for free — try it right now, no wallet needed. After that the endpoint returns 402 Payment Required with an x402 challenge, and any buyer client (e.g. @x402/fetch) pays $0.01 USDC on Base and retries automatically. Meta, but that's the point: we eat the protocol we audit. Add &pay=1 to pay immediately and skip the allowance.

Query it — MCP

Give your agent the query_reputation tool:

claude mcp add --transport http x402-reputation https://x402rep.invoitech.com/mcp

Single lookups share the same free daily allowance as HTTP. batch_reputation (up to 50 endpoints per call) needs an API key — add --header "x-api-key: <key>". Works with any MCP client that speaks Streamable HTTP; a local stdio flavour is in the repo.

Three ways to pay for it

Free10/day per IPsingle lookups, HTTP or MCP — enough to evaluate, share, and try
Per lookup$0.01 USDCx402 over HTTP, no account, no signup — agents pay automatically
API keydaily quotaskips payment, works on HTTP + MCP, and unlocks bulk batch_reputation

Want a key? Get in touch — quotas are set per account.

How verdicts are made

1. Enumerate the CDP Bazaar catalog (Base + USDC). 2. Probe every endpoint's unpaid 402 handshake — reachability, challenge validity, latency, declared schemas. 3. Attribute on-chain settlements: USDC transfers count only when sent by a known facilitator (~40 tracked), so ordinary transfers and self-reported volume don't inflate reputation. 4. Break payTo collisions: a single payout address can back thousands of endpoints — our record is 14,190 — so a dead endpoint inherits its working siblings' settlement history. We refuse to grade shared-payTo endpoints as Trustworthy on on-chain signals alone; they have to pass a real paid test. Nobody else does this. 5. Detect wash: micro-transaction clusters and pay-to-mint patterns. 6. Pay-test: we spend real USDC, record whether the sale completed, classify the response body (data / error / empty / trivial), and keep a truncated redacted sample. Verdicts recompute continuously; every response carries last_probed and verdict_computed_at.

Live status

curl https://x402rep.invoitech.com/api/v1/status

Read the data

We tried to buy from 1,984 x402 endpoints. 52% wouldn't complete the sale →