Fixed scope · Fixed price · Fixed deadline

One endpoint. One report.
Every defect, ranked.

A conformance and reliability audit of a single x402 protected route. I probe your live deployed URL, read the 402 challenge the way a buyer-agent reads it, run the checks an automated validator cannot run, and hand you a prioritised list of what is broken, with the evidence each verdict came from.

Paid up front. Delivered in 48 business hours from the moment payment is confirmed and I have your URL. One free re-test after you fix things.

$399
One protected route
48 business hours, paid up front
Includes one re-test within 14 days
Buy the audit, $399 Read a full example report
What you buy

Four files, not four promises.

This is the complete list of what lands in your inbox. There is nothing else, and there is no tier above it. If an item below is not delivered, the audit was not delivered.

1 · The report, PDF

Verdict, scope, defect list by priority, and an explicit list of what passed. Every finding states what was observed, why a machine buyer cares, the fix, and how you prove the fix landed.

An anonymised copy of the exact format is published below, in full, before you pay.

2 · The validator output, JSON

The complete machine readable run from the open source validator, in strict-v2 mode: per check results, failure classes, probe methods, and probed_at_utc on every verdict.

Drop it in your CI and the same checks run on every deploy, for free, forever.

3 · The defect list, prioritised

Three bands. P1 blocks discovery or payment. P2 gives a careful buyer a documented reason to pick someone else. P3 is hygiene.

Ranked by what stops a machine buyer first, so you can stop reading after P1 and still have fixed the thing that mattered.

4 · One re-test, free

After you ship the fixes, request a re-test within 14 days of the report date. Same checks, fresh probes, and a short delta document.

It states which findings are closed, which are still open, and anything new that the fix introduced. No second invoice.

Also included, and worth saying out loud because it is unusual: the archived raw responses every verdict was derived from, headers included, timestamped. If you disagree with a finding, you can check it against the response it came from instead of taking my word.

What gets checked

Five automated layers, four manual ones.

The automated half is a public tool you can run yourself for free. The manual half is the part you are actually paying for: the checks that need a human comparing two sources and deciding whether a machine buyer would accept the difference.

Automated · open source validator, strict-v2 mode
1Reachability, per probe method GET and POST, with the method that produced the verdict recorded
2Optional /.well-known/x402 manifest, parsed and schema classified
3v2 402 conformance header canonical PAYMENT-REQUIRED, decoded, accepts[] validated
4Response time p50, p95, p99 against your declared budget
5Payment required behaviour no silent 200, no 401, no 403
Manual · this is the paid part
6Bazaar info validated against your own schematool cannot do this
7payTo compared across manifest, live challenge, and repeat probes
8Quote drift repeat probes across a spread, checking fixed terms actually stay fixed
9Amount unit check display price against atomic value, with decimals() read from the asset contract

Check 6 is the reason this exists. The validator reports bazaar_ok: true when the block has the required structure. It does not validate your advertised info against the schema shipped beside it, and that validation is the gate a facilitator applies before it catalogues your resource. A block that fails its own schema is rejected silently: your endpoint keeps serving 402 normally and the only symptom is that you never appear in the catalogue.

A green CI run does not clear that defect. That is not a criticism of the tool. It is the boundary between what a scanner can decide and what somebody has to check.

Fit

Who this is for, and who should not buy it.

Buy this if

  • You run at least one live x402 protected route that returns a 402, and it is reachable from the public internet.
  • You want it understood correctly by discovery systems and buyer-agents, and you are not sure it is.
  • You shipped a change to routing, middleware, pricing, the asset or the recipient address, and you want to know what it broke before a buyer finds out.
  • You are about to launch, and you want the pre-pay contract checked once by somebody who is not you.
  • You have a green scan and no paid calls, and you want to know which of those two facts is lying.
  • You want the finding list with evidence attached, so your engineer can act on it without a meeting.

Do not buy this if

  • You do not have a deployed endpoint yet. There is nothing to probe. Build it first.
  • You want a security assessment. This is not a penetration test, not a code review, and not a smart contract audit.
  • You want traffic or revenue. This measures your machine contract. It does not create demand, and no amount of conformance will.
  • You want somebody to implement the fixes. You get the defect list and the fix for each one. I do not ship code into your repository.
  • You want a badge or a certificate. This audit issues neither, and I would not trust one that did.
  • Your endpoint is behind auth or an allowlist and you cannot give access. If I cannot probe it as a stranger, I cannot audit what a stranger sees.
  • You want post-payment coverage. Settlement correctness, replay protection and paid error handling are out of scope. This is a pre-pay audit.

If you are in the second column, do not buy. Email me and say what you actually need. If it is not something I do, I will say so, and that answer is free.

The deliverable, before you pay

A complete report, anonymised.

Host names, addresses and figures are replaced with placeholders. The structure, the field names, the severity classes and the priority scheme are exactly what you receive. It contains no customer identity, and it is not a testimonial.

Read the full example report

Excerpt · one finding of four

P1-01 · Bazaar schema rejects the endpoint's own info (method enum)

Severity: blocking. Where: live 402 response, extensions.bazaar in the decoded PaymentRequired object.

Observed

The route accepts POST with a JSON body. The advertised info.input correctly declares it:

{"type": "http", "method": "POST", "bodyType": "json", "body": {"query": "example"}}

The schema shipped in the same block declares:

"method": {"type": "string", "enum": ["GET", "HEAD", "DELETE"]}

Validating info against schema produces one error:

$.input.method: 'POST' is not one of ['GET', 'HEAD', 'DELETE']

Why it matters

A facilitator validates info against schema before it catalogues the resource. A block that fails its own schema is rejected at that gate. The rejection is silent: nothing is returned to you, the endpoint keeps serving 402 normally, and the only visible symptom is that the resource never appears in the catalogue.

The open source validator reports bazaar_ok: true for this block, because it checks that the required keys are present and non-empty. It does not run the info against schema validation. A green CI run does not clear this defect.

Reproduce it yourself

pip install jsonschema >/dev/null
python3 - /tmp/payment-required.json <<'PY'
import json, sys
from jsonschema import Draft202012Validator
block = json.load(open(sys.argv[1]))["extensions"]["bazaar"]
Draft202012Validator.check_schema(block["schema"])
for e in Draft202012Validator(block["schema"]).iter_errors(block["info"]):
    print("$." + ".".join(str(p) for p in e.path) + ":", e.message)
PY

Fix

Replace the method enum with the body method variant and require the body fields the specification requires for body methods:

"method":   {"type": "string", "enum": ["POST", "PUT", "PATCH"]},
"bodyType": {"type": "string", "enum": ["json", "form-data", "text"]},
"body":     {"type": "object", "required": ["query"]}

and change input.required to ["type", "method", "bodyType", "body"].

How you prove it is closed

Re-run the snippet above. Zero errors printed. The re-test included in this audit does exactly that, plus a fresh live probe.

Every finding in the report is shaped like that one: observed, why it matters, the fix, and the command that proves it is closed. The report also lists what passed, explicitly, so you know what the audit covered rather than guessing from silence.

Who does this

I publish under a pseudonym. Check the work instead.

SmartFlow Observatory is an independent x402 measurement project. It operates under a pen name, and there is no founder photo, no LinkedIn, and no client logos on this page. That is a real cost to you as a buyer, so here is the substitute: a public record you can inspect without believing anything about a person.

Every link below is live right now. None of them require you to take my word for anything.

The tool is public
The validator that produces the automated half of your report is open source under MIT, and it is the same version I run against your endpoint. Read the checks before you buy the audit.
github.com/smartflowproai-lang/x402-endpoint-validator
Listed on the GitHub Actions marketplace
Other people use it
Not a claim, a merge log. Outside accounts have opened pull requests and issues against the validator, and at least one has been merged into the shipped tool. You can read the diffs, the review comments, and the disagreements.
PR #12, merged, from an outside contributor
PR #13, open, another outside operator adding their own endpoint fixture
Issue #17, opened by a third party
The method is public
The SQL behind the published measurements lives in an open repository, so the numbers can be re-run rather than believed.
github.com/smartflowproai-lang/smartflow-observatory-methodology
The mistakes are public
Nine numbered issues of a weekly measurement letter, published since April 2026. Issue #9 is titled "the facilitator number was wrong, and what that taught me" and it is a public correction of my own headline figure. That record is deliberate: an auditor who has never published a retraction has either never been wrong or never checked.
Weekly Intel #9, the correction
Full archive
The findings are reproducible
Your report ships with the raw responses each verdict came from, headers and timestamps included, and every finding carries a command you can run yourself. You are never asked to trust the verdict. You are asked to check it, and given the material to do so.
The money path is public
Payment is USDC on Base to a fixed address. The transaction is on chain and permanent, and you can look up the recipient's history before you send anything.

What this does not replace: a company you can sue, an insurance certificate, or a reference call. If your procurement requires any of those, this is not the right supplier and I would rather you knew that now.

What this does not promise

Stated up front, not buried.

Scope

You are buying a measurement and a defect list. You are not buying a business outcome. Specifically, this audit does not promise and cannot promise:

  • that a discovery catalogue will index or re-index your resource
  • that a buyer-agent will find you, choose you, or pay you
  • any change in revenue, traffic, or conversion
  • that your endpoint is secure, or that it is free of vulnerabilities
  • uptime, settlement correctness, or anything about behaviour after payment
  • that a clean report today stays true after your next deploy

A clean report proves what your endpoint returned to public probes during the stated window. That is a smaller claim than it sounds, and it is the honest one. Findings are dated because third party specifications, facilitators and catalogues change under you.

A report with zero defects is a delivered audit, not a failed one, and it is not grounds for a refund. If that outcome would make you feel cheated, do not buy: what you actually want is somebody to find problems, and nobody can promise that problems exist.

Support included with the audit is the report, the attachments, and the one re-test. It is not implementation work, not monitoring, not incident response, and there is no service level commitment of any kind.

After you pay

What happens, and when.

The clock starts when both things are true: the payment is confirmed on chain, and I have the URL of the route you want audited. Not when the transaction is broadcast, and not when you first email me.

Step 1
You
Send 399 USDC on Base to the address in the next section, then email info@smartflowproai.com with the transaction hash, the exact URL of the protected route, and the probe method if the route is POST only. If the route needs a header or a test key to be reachable, include it.
Step 2
Within 1 business day
I confirm the transaction on chain and reply with a written acknowledgement: your report ID, the exact route in scope, and the delivery deadline as a date and time. If the route is out of scope, this is where I say so and refund you in full instead of starting.
Step 3
The audit
Probes run against your live URL: the five automated layers in strict-v2 mode, repeat probes across a spread for drift, and the four manual checks. Raw responses are archived as they arrive. I do not send load, and I do not attempt a payment. Total probe volume is a few dozen requests.
Step 4
By the deadline
You receive the PDF report, the validator JSON, and the raw response archive by email, from the same address that acknowledged your order. 48 business hours means 48 hours counted on business days, Monday to Friday, Europe/Warsaw. An order confirmed Monday at 14:00 is delivered by Wednesday at 14:00. An order confirmed Friday at 14:00 is delivered by Tuesday at 14:00.
Step 5
Your side
You fix what you decide to fix. Each finding carries the fix and the command that proves it is closed, so you do not need me in order to verify your own work.
Step 6
Within 14 days
Email the report ID and ask for your free re-test. Same checks, fresh probes, and a short delta document: closed, still open, and newly introduced. The re-test is delivered on the same 48 business hour terms.
If I miss it
If the report is not delivered by the acknowledged deadline, email me and you get the full $399 back, in USDC, to the address you paid from. You keep anything already delivered. This is the only outcome based commitment on this page, because it is the only one that depends entirely on me.
Buy

$399. One route, one report.

Payment is in USDC on Base. For an x402 operator this is already the asset your endpoint quotes in, so there is no processor, no subscription, and no account to create. Half of this fee is credited toward the first month of continuous route monitoring.

Pay in USDC on Base

  1. Send 399 USDC on Base to:
    0xd779cE46567d21b9918F24f0640cA5Ad6058C893
  2. Email info@smartflowproai.com with the transaction hash and the URL of the route you want audited.
  3. You get a written acknowledgement with your report ID and a delivery deadline, normally the same business day.

The audit is priced and confirmed only in USDC on Base. Contact me before sending any other asset or using another network, because I cannot confirm what I cannot see on Base.

Do not send payment for a route you are not ready to expose to probes. If you want to check scope first, email before paying.

If you need an invoice

Invoices are available on request through Useme. Email info@smartflowproai.com before paying and say you need one. Send your company name, address, and tax number. The invoice is issued in PLN at the exchange rate on the invoice date, and the amount matches $399.

Companies that cannot pay in USDC at all should say so in the same email. The invoice route can be settled by bank transfer, and in that case the 48 business hour clock starts when the transfer lands, not when the invoice is issued.

Refunds. Full refund if the report misses the acknowledged deadline. Full refund if I decide before starting that your route is out of scope. No refund for a report that found fewer defects than you hoped, which is stated above and repeated here on purpose.

Confidentiality. Your report is yours. I do not publish your host, your findings, or the fact that you bought an audit. The published example is anonymised and contains no customer.

Why would I pay for this when the validator is free?

You should run the free validator first. It is public, it is MIT licensed, and I will not pretend otherwise: github.com/smartflowproai-lang/x402-endpoint-validator.

What you are paying for is the four manual checks the tool cannot make, the interpretation of the output, and the ranking. A validator tells you a check failed. It does not tell you which failure is the one keeping you out of the catalogue, and it cannot tell you that your Bazaar block fails its own schema.

How do I know you can do this if I do not know who you are?

You do not, and you should not take it on faith. Every claim on this page is attached to something you can open in a browser: the tool, the merged contributions from outside accounts, the methodology repository, and nine issues of a letter that includes a public correction of my own wrong number. See who does this.

The report itself is built the same way. It ships with the raw responses each verdict came from, so you can check my work instead of trusting it.

What if my endpoint has more than one protected route?

$399 covers one route. Email before paying with the list, and I will quote the set as a single fixed price with a single deadline. Routes that share a codebase usually share defects, so the second route is rarely worth full price.

Will your probes cost me money or break anything?

No payment is attempted, so nothing settles and nothing is spent. The probes are unauthenticated requests that expect a 402, plus repeat probes spread over time to check for drift. Total volume is a few dozen requests, which is less than a single buyer-agent evaluating you.

What if the report says everything is fine?

Then you have a dated, evidence backed statement that your pre-pay contract was conformant during the probe window, plus the validator wired into your CI so the next regression fails the build instead of failing silently. That is a delivered audit and it is not refundable. It is also, honestly, the outcome I cannot promise you in advance either way.

Do you sign an NDA?

Yes, if you send one. Email before paying. I will not sign anything that requires me to stop publishing aggregate measurements of the public x402 network, because that is the work that makes this audit worth buying.