A conformance and reliability audit of a single x402 protected route. I probe your live
deployed URL, read the 402 challenge the way a buyer-agent reads it, run the checks
an automated validator cannot run, and hand you a prioritised list of what is broken, with the
evidence each verdict came from.
Paid up front. Delivered in 48 business hours from the moment payment is confirmed and I have your URL. One free re-test after you fix things.
This is the complete list of what lands in your inbox. There is nothing else, and there is no tier above it. If an item below is not delivered, the audit was not delivered.
Verdict, scope, defect list by priority, and an explicit list of what passed. Every finding states what was observed, why a machine buyer cares, the fix, and how you prove the fix landed.
An anonymised copy of the exact format is published below, in full, before you pay.
The complete machine readable run from the open source validator, in strict-v2 mode:
per check results, failure classes, probe methods, and probed_at_utc on every verdict.
Drop it in your CI and the same checks run on every deploy, for free, forever.
Three bands. P1 blocks discovery or payment. P2 gives a careful buyer a documented reason to pick someone else. P3 is hygiene.
Ranked by what stops a machine buyer first, so you can stop reading after P1 and still have fixed the thing that mattered.
After you ship the fixes, request a re-test within 14 days of the report date. Same checks, fresh probes, and a short delta document.
It states which findings are closed, which are still open, and anything new that the fix introduced. No second invoice.
Also included, and worth saying out loud because it is unusual: the archived raw responses every verdict was derived from, headers included, timestamped. If you disagree with a finding, you can check it against the response it came from instead of taking my word.
The automated half is a public tool you can run yourself for free. The manual half is the part you are actually paying for: the checks that need a human comparing two sources and deciding whether a machine buyer would accept the difference.
/.well-known/x402 manifest, parsed and schema classified402 conformance header canonical PAYMENT-REQUIRED, decoded, accepts[] validated200, no 401, no 403info validated against your own schematool cannot do thispayTo compared across manifest, live challenge, and repeat probesdecimals() read from the asset contract
Check 6 is the reason this exists. The validator reports bazaar_ok: true when the
block has the required structure. It does not validate your advertised
info against the schema shipped beside it, and that validation is the
gate a facilitator applies before it catalogues your resource. A block that fails its own schema
is rejected silently: your endpoint keeps serving 402 normally and the only symptom
is that you never appear in the catalogue.
A green CI run does not clear that defect. That is not a criticism of the tool. It is the boundary between what a scanner can decide and what somebody has to check.
402, and it is reachable from the public internet.If you are in the second column, do not buy. Email me and say what you actually need. If it is not something I do, I will say so, and that answer is free.
Host names, addresses and figures are replaced with placeholders. The structure, the field names, the severity classes and the priority scheme are exactly what you receive. It contains no customer identity, and it is not a testimonial.
P1-01 · Bazaar schema rejects the endpoint's own
info (method enum)
Severity: blocking. Where: live 402 response,
extensions.bazaar in the decoded PaymentRequired object.
The route accepts POST with a JSON body. The advertised info.input
correctly declares it:
{"type": "http", "method": "POST", "bodyType": "json", "body": {"query": "example"}}
The schema shipped in the same block declares:
"method": {"type": "string", "enum": ["GET", "HEAD", "DELETE"]}
Validating info against schema produces one error:
$.input.method: 'POST' is not one of ['GET', 'HEAD', 'DELETE']
A facilitator validates info against schema before it catalogues the
resource. A block that fails its own schema is rejected at that gate. The rejection is silent:
nothing is returned to you, the endpoint keeps serving 402 normally, and the only
visible symptom is that the resource never appears in the catalogue.
The open source validator reports bazaar_ok: true for this block, because it
checks that the required keys are present and non-empty. It does not run the
info against schema validation. A green CI run does not clear
this defect.
pip install jsonschema >/dev/null
python3 - /tmp/payment-required.json <<'PY'
import json, sys
from jsonschema import Draft202012Validator
block = json.load(open(sys.argv[1]))["extensions"]["bazaar"]
Draft202012Validator.check_schema(block["schema"])
for e in Draft202012Validator(block["schema"]).iter_errors(block["info"]):
print("$." + ".".join(str(p) for p in e.path) + ":", e.message)
PY
Replace the method enum with the body method variant and require the body fields the specification requires for body methods:
"method": {"type": "string", "enum": ["POST", "PUT", "PATCH"]},
"bodyType": {"type": "string", "enum": ["json", "form-data", "text"]},
"body": {"type": "object", "required": ["query"]}
and change input.required to
["type", "method", "bodyType", "body"].
Re-run the snippet above. Zero errors printed. The re-test included in this audit does exactly that, plus a fresh live probe.
Every finding in the report is shaped like that one: observed, why it matters, the fix, and the command that proves it is closed. The report also lists what passed, explicitly, so you know what the audit covered rather than guessing from silence.
SmartFlow Observatory is an independent x402 measurement project. It operates under a pen name, and there is no founder photo, no LinkedIn, and no client logos on this page. That is a real cost to you as a buyer, so here is the substitute: a public record you can inspect without believing anything about a person.
Every link below is live right now. None of them require you to take my word for anything.
What this does not replace: a company you can sue, an insurance certificate, or a reference call. If your procurement requires any of those, this is not the right supplier and I would rather you knew that now.
You are buying a measurement and a defect list. You are not buying a business outcome. Specifically, this audit does not promise and cannot promise:
A clean report proves what your endpoint returned to public probes during the stated window. That is a smaller claim than it sounds, and it is the honest one. Findings are dated because third party specifications, facilitators and catalogues change under you.
A report with zero defects is a delivered audit, not a failed one, and it is not grounds for a refund. If that outcome would make you feel cheated, do not buy: what you actually want is somebody to find problems, and nobody can promise that problems exist.
Support included with the audit is the report, the attachments, and the one re-test. It is not implementation work, not monitoring, not incident response, and there is no service level commitment of any kind.
The clock starts when both things are true: the payment is confirmed on chain, and I have the URL of the route you want audited. Not when the transaction is broadcast, and not when you first email me.
strict-v2 mode, repeat probes across a spread for drift, and the four manual
checks. Raw responses are archived as they arrive. I do not send load, and I do not attempt a
payment. Total probe volume is a few dozen requests.Payment is in USDC on Base. For an x402 operator this is already the asset your endpoint quotes in, so there is no processor, no subscription, and no account to create. Half of this fee is credited toward the first month of continuous route monitoring.
The audit is priced and confirmed only in USDC on Base. Contact me before sending any other asset or using another network, because I cannot confirm what I cannot see on Base.
Do not send payment for a route you are not ready to expose to probes. If you want to check scope first, email before paying.
Invoices are available on request through Useme. Email info@smartflowproai.com before paying and say you need one. Send your company name, address, and tax number. The invoice is issued in PLN at the exchange rate on the invoice date, and the amount matches $399.
Companies that cannot pay in USDC at all should say so in the same email. The invoice route can be settled by bank transfer, and in that case the 48 business hour clock starts when the transfer lands, not when the invoice is issued.
Refunds. Full refund if the report misses the acknowledged deadline. Full refund if I decide before starting that your route is out of scope. No refund for a report that found fewer defects than you hoped, which is stated above and repeated here on purpose.
Confidentiality. Your report is yours. I do not publish your host, your findings, or the fact that you bought an audit. The published example is anonymised and contains no customer.
You should run the free validator first. It is public, it is MIT licensed, and I will not pretend otherwise: github.com/smartflowproai-lang/x402-endpoint-validator.
What you are paying for is the four manual checks the tool cannot make, the interpretation of the output, and the ranking. A validator tells you a check failed. It does not tell you which failure is the one keeping you out of the catalogue, and it cannot tell you that your Bazaar block fails its own schema.
You do not, and you should not take it on faith. Every claim on this page is attached to something you can open in a browser: the tool, the merged contributions from outside accounts, the methodology repository, and nine issues of a letter that includes a public correction of my own wrong number. See who does this.
The report itself is built the same way. It ships with the raw responses each verdict came from, so you can check my work instead of trusting it.
$399 covers one route. Email before paying with the list, and I will quote the set as a single fixed price with a single deadline. Routes that share a codebase usually share defects, so the second route is rarely worth full price.
No payment is attempted, so nothing settles and nothing is spent. The probes are
unauthenticated requests that expect a 402, plus repeat probes spread over time to
check for drift. Total volume is a few dozen requests, which is less than a single buyer-agent
evaluating you.
Then you have a dated, evidence backed statement that your pre-pay contract was conformant during the probe window, plus the validator wired into your CI so the next regression fails the build instead of failing silently. That is a delivered audit and it is not refundable. It is also, honestly, the outcome I cannot promise you in advance either way.
Yes, if you send one. Email before paying. I will not sign anything that requires me to stop publishing aggregate measurements of the public x402 network, because that is the work that makes this audit worth buying.