activedata

CaptainData API provides people and company enrichment, search, and discovery powered by LinkedIn Sales Navigator data. Find and enrich profiles, search for people and companies, and discover employees.

Implementation fingerprint
unknown no confident attribution
Fingerprint evidence
No implementation-specific public signal observed.
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 6:17 PM UTC
Origin
https://mpp.orthogonal.com
Tags
enrichmentpeoplecompanysearch

Payment surface

14 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://mpp.orthogonal.com/captaindata/companies/%7Bcompany_uid%7D/employees
List employees of a given company. Returns paginated results. The company_uid path parameter is the LinkedIn company ID (e.g., 1035 for Microsoft), which can be obtained from the Enrich Company or Find Company endpoints (li_company_id field). Pagination billing: call the first page normally and save billing.requestId from the Orthogonal /v1/run response. For later page, offset, or cursor calls on the same logical search, pass parentRequestId with unchanged non-pagination parameters. Valid continuation calls still get their own request IDs and quoted price, but are charged 0. Changing filters starts a new billable request.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/{company_uid}/employees
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/{company_uid}/employees
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/{company_uid}/employees
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/{company_uid}/employees
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/companies/{company_uid}/employees
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/companies/{company_uid}/employees
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/captaindata/companies/enrich
Get comprehensive company information from a LinkedIn Company URL. Returns company details, industry, size, and more.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:26 PM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/companies/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/companies/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/captaindata/companies/find
Find a company by name. Returns matching company profiles.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 28, 12:19 PM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/companies/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/companies/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/captaindata/companies/search
Search and discover companies using a LinkedIn Sales Navigator search query. Returns paginated results. Pagination billing: call the first page normally and save billing.requestId from the Orthogonal /v1/run response. For later page, offset, or cursor calls on the same logical search, pass parentRequestId with unchanged non-pagination parameters. Valid continuation calls still get their own request IDs and quoted price, but are charged 0. Changing filters starts a new billable request.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:27 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/companies/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/companies/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/companies/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/companies/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/captaindata/people/enrich
Get comprehensive profile information from a LinkedIn URL with additional enrichment data. Returns full name, headline, summary, skills, languages, education, experiences, company info, and more.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 20, 12:24 PM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/people/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/people/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/people/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/people/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/people/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/people/enrich
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/captaindata/people/find
Find people by name and optionally company name. Returns matching profiles.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 20, 12:23 PM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/people/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/people/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/people/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/people/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/people/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/people/find
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/captaindata/people/search
Search and discover people using a LinkedIn Sales Navigator search query. Returns paginated results with profile summaries. Use the X-Pagination-Next response header cursor for pagination. Pagination billing: call the first page normally and save billing.requestId from the Orthogonal /v1/run response. For later page, offset, or cursor calls on the same logical search, pass parentRequestId with unchanged non-pagination parameters. Valid continuation calls still get their own request IDs and quoted price, but are charged 0. Changing filters starts a new billable request.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:22 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/people/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/captaindata/people/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/people/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/captaindata/people/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/captaindata/people/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/captaindata/people/search
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/companies/:company_uid/employees
List employees of a given company. Returns paginated results. The company_uid path parameter is the LinkedIn company ID
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 29, 06:20 AM UTC
tempochargecatalog2290000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/companies/enrich
Get comprehensive company information from a LinkedIn Company URL. Returns company details, industry, size, and more.
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 06:22 AM UTC
tempochargecatalog90000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/companies/find
Find a company by name. Returns matching company profiles.
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:22 PM UTC
tempochargecatalog180000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/companies/search
Search and discover companies using a LinkedIn Sales Navigator search query. Returns paginated results.
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 06:22 AM UTC
tempochargecatalog2290000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/people/enrich
Get comprehensive profile information from a LinkedIn URL with additional enrichment data. Returns full name, headline
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 12:21 AM UTC
tempochargecatalog180000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/people/find
Find people by name and optionally company name. Returns matching profiles.
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 12:21 AM UTC
tempochargecatalog180000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/people/search
Search and discover people using a LinkedIn Sales Navigator search query. Returns paginated results with profile
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 7, 06:25 PM UTC
tempochargecatalog2290000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

52 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://mpp.orthogonal.com/captaindata/companies/enrich

HTTP 400

344 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:26 PM UTC

GET https://mpp.orthogonal.com/companies/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:22 PM UTC

GET https://mpp.orthogonal.com/captaindata/people/search

HTTP 400

839 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/captaindata/companies/search

HTTP 400

813 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:27 AM UTC

GET https://mpp.orthogonal.com/companies/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/companies/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/people/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:21 AM UTC

GET https://mpp.orthogonal.com/people/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:21 AM UTC

GET https://mpp.orthogonal.com/people/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:25 PM UTC

GET https://mpp.orthogonal.com/captaindata/openapi.json

HTTP 200

10,707 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:23 PM UTC

GET https://mpp.orthogonal.com/captaindata/companies/enrich

HTTP 400

344 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:21 PM UTC

GET https://mpp.orthogonal.com/companies/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:21 PM UTC

GET https://mpp.orthogonal.com/.well-known/api-catalog

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:25 AM UTC

GET https://mpp.orthogonal.com/captaindata/people/search

HTTP 400

839 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:22 AM UTC

GET https://mpp.orthogonal.com/captaindata/companies/search

HTTP 400

813 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 29, 2026, 6:22 PM UTC

GET https://mpp.orthogonal.com/companies/:company_uid/employees

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 29, 2026, 6:20 AM UTC

GET https://mpp.orthogonal.com/companies/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:26 PM UTC

GET https://mpp.orthogonal.com/companies/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:26 PM UTC

GET https://mpp.orthogonal.com/people/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:21 PM UTC

GET https://mpp.orthogonal.com/people/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:21 PM UTC

GET https://mpp.orthogonal.com/people/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:21 PM UTC

GET https://mpp.orthogonal.com/captaindata/openapi.json

HTTP 200

8,844 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:19 PM UTC

GET https://mpp.orthogonal.com/captaindata/companies/find

HTTP 400

271 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:19 PM UTC

GET https://mpp.orthogonal.com/captaindata/companies/enrich

HTTP 400

344 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:23 AM UTC

GET https://mpp.orthogonal.com/companies/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/.well-known/api-catalog

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:25 AM UTC

GET https://mpp.orthogonal.com/captaindata/people/search

HTTP 400

839 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 20, 2026, 6:24 PM UTC

GET https://mpp.orthogonal.com/captaindata/people/enrich

HTTP 400

308 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 20, 2026, 12:24 PM UTC

GET https://mpp.orthogonal.com/captaindata/companies/search

HTTP 400

813 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 20, 2026, 12:23 PM UTC

GET https://mpp.orthogonal.com/captaindata/people/find

HTTP 400

373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 20, 2026, 12:23 PM UTC

GET https://mpp.orthogonal.com/companies/:company_uid/employees

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 20, 2026, 12:20 AM UTC

GET https://mpp.orthogonal.com/companies/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 12:24 PM UTC

GET https://mpp.orthogonal.com/companies/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 12:22 PM UTC

GET https://mpp.orthogonal.com/captaindata/companies/find

HTTP 400

271 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 12:18 PM UTC

GET https://mpp.orthogonal.com/people/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/people/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/people/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 6:21 AM UTC

GET https://mpp.orthogonal.com/captaindata/openapi.json

HTTP 200

8,844 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 19, 2026, 6:19 AM UTC

GET https://mpp.orthogonal.com/captaindata/companies/enrich

HTTP 400

344 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:21 AM UTC

GET https://mpp.orthogonal.com/companies/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:20 AM UTC

GET https://mpp.orthogonal.com/.well-known/api-catalog

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:25 AM UTC

GET https://mpp.orthogonal.com/captaindata/people/search

HTTP 400

839 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 11, 2026, 6:25 PM UTC

GET https://mpp.orthogonal.com/captaindata/people/enrich

HTTP 400

308 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 11, 2026, 12:24 PM UTC

GET https://mpp.orthogonal.com/captaindata/companies/search

HTTP 400

813 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 11, 2026, 12:23 PM UTC

GET https://mpp.orthogonal.com/captaindata/people/find

HTTP 400

373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 11, 2026, 12:22 PM UTC

GET https://mpp.orthogonal.com/companies/:company_uid/employees

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 11, 2026, 12:24 AM UTC

GET https://mpp.orthogonal.com/companies/search

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 10, 2026, 12:24 PM UTC

GET https://mpp.orthogonal.com/companies/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 10, 2026, 6:25 AM UTC

GET https://mpp.orthogonal.com/people/find

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 10, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/people/enrich

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 10, 2026, 6:22 AM UTC
Showing the latest 50 of 52 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTC

bounded_response

Tested — pass

344 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 AM UTC

bounded_response

Tested — pass

839 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:22 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:27 AM UTC

bounded_response

Tested — pass

813 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:27 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:27 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:27 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:27 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:27 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:27 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:27 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:27 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:27 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:27 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:27 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:27 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:27 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:22 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 6:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:22 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 6:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:21 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:21 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:21 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:21 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:21 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:21 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:25 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:25 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:25 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 6:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:23 PM UTC

bounded_response

Tested — pass

10707 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 6:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:23 PM UTC

openapi_parse

Tested — pass

42 payment offer(s) accepted

Basis: harmless discovery response · Oct 7, 2026, 6:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:23 PM UTC

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Sep 30, 2026, 6:25 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 29, 2026, 6:20 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Sep 29, 2026, 6:20 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 29, 2026, 6:20 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 29, 2026, 6:20 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 29, 2026, 6:20 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 29, 2026, 6:20 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 29, 2026, 6:20 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 29, 2026, 6:20 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 29, 2026, 6:20 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 29, 2026, 6:20 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 29, 2026, 6:20 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 29, 2026, 6:20 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 29, 2026, 6:20 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 29, 2026, 6:20 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 28, 2026, 12:19 PM UTC

bounded_response

Tested — pass

271 bytes within scanner limit

Basis: harmless scanner · Sep 28, 2026, 12:19 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 28, 2026, 12:19 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 28, 2026, 12:19 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 28, 2026, 12:19 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 28, 2026, 12:19 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 28, 2026, 12:19 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 28, 2026, 12:19 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 28, 2026, 12:19 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 28, 2026, 12:19 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 28, 2026, 12:19 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 28, 2026, 12:19 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 28, 2026, 12:19 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 28, 2026, 12:19 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 20, 2026, 12:24 PM UTC

bounded_response

Tested — pass

308 bytes within scanner limit

Basis: harmless scanner · Sep 20, 2026, 12:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 20, 2026, 12:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 20, 2026, 12:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 20, 2026, 12:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 20, 2026, 12:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 20, 2026, 12:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 20, 2026, 12:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 20, 2026, 12:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 20, 2026, 12:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 20, 2026, 12:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 20, 2026, 12:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 20, 2026, 12:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 20, 2026, 12:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 20, 2026, 12:23 PM UTC

bounded_response

Tested — pass

373 bytes within scanner limit

Basis: harmless scanner · Sep 20, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 20, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 20, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 20, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 20, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 20, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 20, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 20, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 20, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 20, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 20, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 20, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 20, 2026, 12:23 PM UTC

History

Service changes

Showing the latest 50 of 192 changes. Continue in the changes API view.

— payment-offer-updated

method: x402 → mpp

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","url":"https://x402.orthogonal.com/captaindata/companies/{company_uid}/employees"} → {"rail":"tempo","url":"https://mpp.orthogonal.com/captaindata/companies/{company_uid}/employees"}

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-updated

method: x402 → mpp

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","url":"https://x402.orthogonal.com/captaindata/people/find"} → {"rail":"tempo","url":"https://mpp.orthogonal.com/captaindata/people/find"}

Evidence: openapi payment metadata

— payment-offer-updated

method: np → x402

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/captaindata/companies/{company_uid}/employees"} → {"rail":"base","url":"https://x402.orthogonal.com/captaindata/companies/{company_uid}/employees"}

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/captaindata/companies/enrich"} → {"rail":"base","url":"https://x402.orthogonal.com/captaindata/companies/enrich"}

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/captaindata/companies/find"} → {"rail":"base","url":"https://x402.orthogonal.com/captaindata/companies/find"}

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","settlement":"circle-gateway","version":"x402-v2","url":"https://np.orthogonal.com/captaindata/people/se… → {"rail":"base","url":"https://x402.orthogonal.com/captaindata/people/search"}

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","url":"https://x402.orthogonal.com/captaindata/companies/find"} → {"rail":"tempo","url":"https://mpp.orthogonal.com/captaindata/companies/find"}

Evidence: openapi payment metadata

— payment-offer-updated

method: x402 → mpp

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","url":"https://x402.orthogonal.com/captaindata/people/search"} → {"rail":"tempo","url":"https://mpp.orthogonal.com/captaindata/people/search"}

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"np","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"unitT…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","settlement":"circle-gateway","version":"x402-v2","url":"https://np.orthogonal.com/captaindata/people/fi… → {"rail":"base","url":"https://x402.orthogonal.com/captaindata/people/find"}

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/captaindata/people/find"} → {"rail":"base","url":"https://x402.orthogonal.com/captaindata/people/find"}

Evidence: openapi payment metadata