activewebdata

API for retrieving context data from any website. Web scraping, brand retrieval, AI data extraction, screenshots, and more.

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 6:22 PM UTC
Origin
https://mpp.orthogonal.com
Tags
scrapingbrandcontextextraction

Payment surface

48 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.

JSON record →
POST
https://mpp.orthogonal.com/brand/ai/product
Beta feature: Given a single URL, determines if it is a product detail page, classifies the platform/product type, and
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/brand/ai/products
Beta feature: Extract product information from a brand's website. We will analyze the website and return a list of
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/brand/ai/query
Use AI to extract specific data points from a brand's website. The AI will crawl the website and extract the requested
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/brand/prefetch
Signal that you may fetch brand data for a particular domain soon to improve latency. This endpoint does not charge
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/brand/prefetch-by-email
Signal that you may fetch brand data for a particular domain soon to improve latency. This endpoint accepts an email
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/retrieve
Retrieve logos, backdrops, colors, industry, description, and more from any domain
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 30, 06:24 AM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/retrieve-by-email
Retrieve brand information using an email address while detecting disposable and free email addresses. This endpoint
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 7, 06:24 PM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/retrieve-by-isin
Retrieve brand information using an ISIN (International Securities Identification Number). This endpoint looks up the
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 12:23 AM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/retrieve-by-name
Retrieve brand information using a company name. This endpoint searches for the company by name and returns its brand
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 7, 06:20 PM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/retrieve-by-ticker
Retrieve brand information using a stock ticker symbol. This endpoint looks up the company associated with the ticker
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 7, 06:22 PM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/retrieve-simplified
Returns a simplified version of brand data containing only essential information: domain, title, colors, logos, and
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 12:21 AM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/brand/transaction_identifier
Endpoint specially designed for platforms that want to identify transaction data by the transaction title.
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 30, 06:21 AM UTC
tempochargecatalog30000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
request
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/context-dev/brand/ai/product
Beta feature: Given a single URL, determines if it is a product detail page, classifies the platform/product type, and extracts the product information. Supports Amazon, TikTok Shop, Etsy, and generic ecommerce sites.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/ai/product
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/ai/product
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/product
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/product
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/product
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/ai/product
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/context-dev/brand/ai/products
Beta feature: Extract product information from a brand's website. We will analyze the website and return a list of products with details such as name, description, image, pricing, features, and more.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/ai/products
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/ai/products
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/products
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/products
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/products
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/ai/products
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/context-dev/brand/ai/query
Use AI to extract specific data points from a brand's website. The AI will crawl the website and extract the requested information based on the provided data points.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/ai/query
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/ai/query
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/query
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/query
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/ai/query
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/ai/query
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/context-dev/brand/prefetch
Signal that you may fetch brand data for a particular domain soon to improve latency. This endpoint does not charge credits and is available for paid customers to optimize future requests. [You must be on a paid plan to use this endpoint]
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/prefetch
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/prefetch
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/prefetch
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/prefetch
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/prefetch
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/prefetch
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/context-dev/brand/prefetch-by-email
Signal that you may fetch brand data for a particular domain soon to improve latency. This endpoint accepts an email address, extracts the domain from it, validates that it's not a disposable or free email provider, and queues the domain for prefetching. This endpoint does not charge credits and is available for paid customers to optimize future requests. [You must be on a paid plan to use this endpoint]
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/prefetch-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/prefetch-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/prefetch-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/prefetch-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/prefetch-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/prefetch-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/retrieve
Retrieve logos, backdrops, colors, industry, description, and more from any domain
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 12:23 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-email
Retrieve brand information using an email address while detecting disposable and free email addresses. This endpoint extracts the domain from the email address and returns brand data for that domain. Disposable and free email addresses (like gmail.com, yahoo.com) will throw a 422 error.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:22 PM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/retrieve-by-email
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-isin
Retrieve brand information using an ISIN (International Securities Identification Number). This endpoint looks up the company associated with the ISIN and returns its brand data.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 12:24 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-isin
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-isin
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-isin
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-isin
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-isin
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/retrieve-by-isin
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-name
Retrieve brand information using a company name. This endpoint searches for the company by name and returns its brand data.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 06:22 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-name
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-name
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-name
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-name
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-name
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/retrieve-by-name
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-ticker
Retrieve brand information using a stock ticker symbol. This endpoint looks up the company associated with the ticker and returns its brand data.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 12:24 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-ticker
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-by-ticker
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-ticker
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-ticker
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-by-ticker
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/retrieve-by-ticker
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/retrieve-simplified
Returns a simplified version of brand data containing only essential information: domain, title, colors, logos, and backdrops. This endpoint is optimized for faster responses and reduced data transfer.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:21 PM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-simplified
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/retrieve-simplified
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-simplified
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-simplified
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/retrieve-simplified
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/retrieve-simplified
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.orthogonal.com/context-dev/brand/transaction_identifier
Endpoint specially designed for platforms that want to identify transaction data by the transaction title.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 12:25 AM UTC
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/transaction_identifier
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/brand/transaction_identifier
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/transaction_identifier
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/brand/transaction_identifier
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/brand/transaction_identifier
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/brand/transaction_identifier
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.orthogonal.com/context-dev/people/retrieve
Retrieve and normalize a person profile from identifiers such as LinkedIn URL.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapiamount unknown USDC.e
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/people/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
tempo
Session · url
https://mpp.orthogonal.com/context-dev/people/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/people/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown OUSD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · url
https://x402.orthogonal.com/context-dev/people/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
monad
Session · url
https://x402.orthogonal.com/context-dev/people/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
npchargeopenapiamount unknown USDC
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · rail
base
Session · settlement
circle-gateway
Session · version
x402-v2
Session · url
https://np.orthogonal.com/context-dev/people/retrieve
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

122 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-by-email

HTTP 400

934 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:22 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/images

HTTP 400

291 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/competitors

HTTP 400

401 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-simplified

HTTP 400

524 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/sitemap

HTTP 400

516 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:22 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/fonts

HTTP 400

604 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:22 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/html

HTTP 400

279 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:20 PM UTC

GET https://mpp.orthogonal.com/.well-known/api-catalog

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:24 AM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-isin

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:23 AM UTC

GET https://mpp.orthogonal.com/brand/retrieve-simplified

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:21 AM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-email

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:24 PM UTC

GET https://mpp.orthogonal.com/context-dev/openapi.json

HTTP 200

33,905 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:22 PM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-ticker

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:22 PM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-name

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 PM UTC

GET https://mpp.orthogonal.com/web/scrape/html

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 PM UTC

GET https://mpp.orthogonal.com/web/scrape/markdown

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:24 PM UTC

GET https://mpp.orthogonal.com/web/scrape/sitemap

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:28 AM UTC

GET https://mpp.orthogonal.com/web/fonts

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 2, 2026, 12:46 AM UTC

GET https://mpp.orthogonal.com/web/screenshot

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 2, 2026, 12:45 AM UTC

GET https://mpp.orthogonal.com/web/naics

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 2, 2026, 12:44 AM UTC

GET https://mpp.orthogonal.com/web/styleguide

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 2, 2026, 12:44 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/markdown

HTTP 400

821 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:23 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-by-name

HTTP 400

1,014 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/transaction_identifier

HTTP 400

1,624 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:25 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-by-isin

HTTP 400

941 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:24 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-by-ticker

HTTP 400

1,001 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:24 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve

HTTP 400

882 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:23 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/sic

HTTP 400

683 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:23 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/screenshot

HTTP 402

303 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:23 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/naics

HTTP 400

953 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:22 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-by-email

HTTP 400

934 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:21 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/images

HTTP 400

291 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:20 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/competitors

HTTP 400

401 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:19 AM UTC

GET https://mpp.orthogonal.com/context-dev/brand/retrieve-simplified

HTTP 400

524 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:19 AM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/sitemap

HTTP 400

516 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:19 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/fonts

HTTP 400

604 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:19 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/styleguide

HTTP 402

314 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:19 PM UTC

GET https://mpp.orthogonal.com/context-dev/web/scrape/html

HTTP 400

279 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:18 PM UTC

GET https://mpp.orthogonal.com/brand/retrieve

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:24 AM UTC

GET https://mpp.orthogonal.com/brand/transaction_identifier

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 AM UTC

GET https://mpp.orthogonal.com/web/scrape/images

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:24 PM UTC

GET https://mpp.orthogonal.com/.well-known/api-catalog

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:23 PM UTC

GET https://mpp.orthogonal.com/brand/screenshot

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:23 PM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-isin

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:22 PM UTC

GET https://mpp.orthogonal.com/brand/retrieve-simplified

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 12:21 PM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-email

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/brand/fonts

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:22 AM UTC

GET https://mpp.orthogonal.com/context-dev/openapi.json

HTTP 200

26,999 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:21 AM UTC

GET https://mpp.orthogonal.com/brand/retrieve-by-ticker

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:21 AM UTC

GET https://mpp.orthogonal.com/brand/naics

HTTP 404

79 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 28, 2026, 6:20 AM UTC
Showing the latest 50 of 122 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTC

bounded_response

Tested — pass

934 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

291 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

401 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

524 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTC

bounded_response

Tested — pass

516 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTC

bounded_response

Tested — pass

604 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:20 PM UTC

bounded_response

Tested — pass

279 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:20 PM UTC

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Oct 8, 2026, 12:24 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:24 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:24 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:24 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:24 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:24 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:24 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:24 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:24 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:24 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:24 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:24 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:24 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:24 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:24 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:23 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:21 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:21 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:21 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 6:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 PM UTC

openapi_parse

Tested — pass

156 payment offer(s) accepted

Basis: harmless discovery response · Oct 7, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:22 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:20 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:20 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 12:24 PM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 12:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 12:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 12:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 12:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 12:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 12:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 12:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 12:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 12:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 12:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 12:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 12:28 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 12:28 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 12:28 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 12:28 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 12:28 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:28 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 12:28 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 12:28 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 12:28 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 12:28 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 12:28 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 12:28 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:28 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 12:28 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 2, 2026, 12:46 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 2, 2026, 12:46 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 2, 2026, 12:46 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 2, 2026, 12:46 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 2, 2026, 12:46 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 12:46 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 2, 2026, 12:46 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 2, 2026, 12:46 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 2, 2026, 12:46 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 2, 2026, 12:46 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 2, 2026, 12:46 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 2, 2026, 12:46 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 12:46 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 2, 2026, 12:46 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 2, 2026, 12:45 AM UTC

bounded_response

Tested — pass

79 bytes within scanner limit

Basis: harmless scanner · Oct 2, 2026, 12:45 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 2, 2026, 12:45 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 2, 2026, 12:45 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 2, 2026, 12:45 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 12:45 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 2, 2026, 12:45 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 2, 2026, 12:45 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 2, 2026, 12:45 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 2, 2026, 12:45 AM UTC
Showing a bounded 250 of 520 security-property records.

History

Service changes

Showing the latest 50 of 643 changes. Continue in the changes API view.

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"33905 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"79 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","url":"https://x402.orthogonal.com/context-dev/brand/retrieve-by-isin"} → {"rail":"tempo","url":"https://mpp.orthogonal.com/context-dev/brand/retrieve-by-isin"}

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/context-dev/web/sic"} → {"rail":"base","url":"https://x402.orthogonal.com/context-dev/web/sic"}

Evidence: openapi payment metadata

— payment-offer-updated

method: np → x402

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/context-dev/brand/prefetch"} → {"rail":"base","url":"https://x402.orthogonal.com/context-dev/brand/prefetch"}

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

method: x402 → mpp

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"np","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"unitT…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","settlement":"circle-gateway","version":"x402-v2","url":"https://np.orthogonal.com/context-dev/brand/ret… → {"rail":"base","url":"https://x402.orthogonal.com/context-dev/brand/retrieve-simplified"}

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"np","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"unitT…

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"np","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"unitT…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","url":"https://x402.orthogonal.com/context-dev/web/scrape/html"} → {"rail":"tempo","url":"https://mpp.orthogonal.com/context-dev/web/scrape/html"}

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"np","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"unitT…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"monad","url":"https://x402.orthogonal.com/context-dev/web/extract"} → {"rail":"base","url":"https://x402.orthogonal.com/context-dev/web/extract"}

Evidence: openapi payment metadata

— payment-offer-updated

method: np → x402

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"rail":"base","settlement":"circle-gateway","version":"x402-v2","url":"https://np.orthogonal.com/context-dev/web/crawl… → {"rail":"base","url":"https://x402.orthogonal.com/context-dev/web/crawl"}

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"x402","intent":"charge","currency":"USDC","chainId":null,"recipient":null,"amount":null,"decimals":null,"uni…

Evidence: openapi payment metadata

— payment-offer-updated

currency: USDC → OUSD

Evidence: openapi payment metadata