Discovery and normalization
The index combines public service catalogs, MPPScan/Merit listings, advertised OpenAPI or MPP discovery metadata, and manually submitted public URLs. Each normalized record retains its source URL and first/last-seen timestamps. A runtime 402 challenge is treated as time-specific evidence; catalog and OpenAPI declarations remain advertised configuration.
Safe probe boundary
Probes are limited to harmless, unauthenticated HTTP: advertised discovery documents, GET/HEAD, legitimate 402 Payment Required responses, bounded redirects, and TLS/HTTP metadata. The scanner does not pay, sign credentials, replay authorizations, fuzz inputs, exploit suspected bugs, or intentionally change remote state.
- Targets are deduplicated and processed with per-origin rate limits, jitter, timeouts, redirect limits, bounded response sizes, and retry backoff.
- SSRF defenses reject localhost, private and reserved IPv4, link-local and private IPv6, cloud metadata addresses, DNS rebinding, and every target or redirect outside the normalized service hostname.
- Authorization, cookies, payment credentials, secrets, and sensitive headers are redacted before observations are persisted or returned.
- Redacted R2 observations expire after 30 days; D1 retains normalized summaries and body digests while bounded cleanup preserves current authority and the change timeline.
Evidence states
Observed: Directly present in public metadata, an unauthenticated response, or a recorded scanner-policy decision.
Inferred: An evidence-supported hypothesis; not directly established by the scanner.
Tested — pass: The named harmless check passed. This is not a general security guarantee.
Tested — fail: The named harmless validation ran and failed; optional absence and scanner stops use observed instead.
Unknown: The available public evidence cannot determine this property.
Not tested: Outside this observatory’s safe, unauthenticated test scope.
Implementation fingerprints
Fingerprint categories — mppx, mpp-rs, Cloudflare mpp-proxy, custom, and unknown — require explicit public signals. Each record carries a confidence score and evidence list. Fingerprints do not establish an exact version or prove that a public advisory applies.
Economic security
The model tracks authorization/delivery/settlement mismatch, per-request price/debit mismatch, concurrency and single-winner behavior, replay and idempotency scope, channel lifecycle binding, fee-payer/cosigner behavior, and payment-method fallback as separate research classes. Public advisories and prior research inform what evidence to preserve; applicability remains unknown unless direct public evidence establishes it.
For session or streaming offers, ratios and authorization-exposure metrics are shown only when the required numeric inputs appear in public metadata or a challenge. Otherwise the value is explicitly unknown. A ratio is descriptive evidence, not a vulnerability verdict.
What this observatory cannot establish
Passive public probing cannot verify settlement correctness, delivery accounting, credential replay resistance, concurrency safety, database transaction boundaries, private code versions, internal topology, or controls that require a valid payment session. Those properties remain unknown or not tested, not passed.