Estate-grown Napa Valley wine. AI agents can browse and purchase wine with identity verification (KYC, age 21+, US only) via AgentScore.
- Implementation fingerprint
- unknown no confident attribution
- Fingerprint evidence
- No implementation-specific public signal observed.
- First seen
- Aug 25, 2026, 6:43 PM UTC
- Last seen
- Oct 9, 2026, 6:22 PM UTC
- Origin
- https://agents.martinestate.com
- Tags
- winecommercealcoholage-restrictedphysical-goodsnapa-valley
Payment surface
5 MPP endpoints
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · dynamic
- true
- Session · amountHint
- Variable
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Probe coverage
22 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://agents.martinestate.com/catalog/:slug
HTTP 40460 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:22 PM UTCGET https://agents.martinestate.com/.well-known/api-catalog
HTTP 40413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 PM UTCGET https://agents.martinestate.com/openapi.json
HTTP 20012,053 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 PM UTCGET https://agents.martinestate.com/orders/:id
HTTP 4013,102 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:22 PM UTCGET https://agents.martinestate.com/orders/:id/status
HTTP 4013,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 6:23 PM UTCGET https://agents.martinestate.com/catalog
HTTP 2002,609 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 6:21 AM UTCGET https://agents.martinestate.com/catalog/:slug
HTTP 40460 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:21 AM UTCGET https://agents.martinestate.com/.well-known/api-catalog
HTTP 40413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:20 AM UTCGET https://agents.martinestate.com/openapi.json
HTTP 20011,756 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:19 AM UTCGET https://agents.martinestate.com/orders/:id
HTTP 4013,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:19 PM UTCGET https://agents.martinestate.com/orders/:id/status
HTTP 4013,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 22, 2026, 12:24 PM UTCGET https://agents.martinestate.com/catalog
HTTP 2002,609 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 22, 2026, 12:24 AM UTCGET https://agents.martinestate.com/catalog/:slug
HTTP 40460 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:23 PM UTCGET https://agents.martinestate.com/.well-known/api-catalog
HTTP 40413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:23 PM UTCGET https://agents.martinestate.com/openapi.json
HTTP 20011,219 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:20 PM UTCGET https://agents.martinestate.com/orders/:id
HTTP 4013,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:20 PM UTCGET https://agents.martinestate.com/orders/:id/status
HTTP 4013,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 13, 2026, 6:24 AM UTCGET https://agents.martinestate.com/catalog
HTTP 2002,609 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 13, 2026, 12:23 AM UTCGET https://agents.martinestate.com/catalog/:slug
HTTP 40460 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 6:21 PM UTCGET https://agents.martinestate.com/.well-known/api-catalog
HTTP 40413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 6:20 PM UTCGET https://agents.martinestate.com/openapi.json
HTTP 20011,219 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 6:19 PM UTCGET https://agents.martinestate.com/orders/:id
HTTP 4013,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 6:18 PM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
authorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTCbounded_response
Tested — pass60 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTCapi_catalog_parse
ObservedNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass13 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCopenapi_parse
Tested — pass3 payment offer(s) accepted
Basis: harmless discovery response · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTCbounded_response
Tested — pass3102 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 6:23 PM UTCbounded_response
Tested — pass3120 bytes within scanner limit
Basis: harmless scanner · Oct 1, 2026, 6:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 1, 2026, 6:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 1, 2026, 6:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 1, 2026, 6:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 1, 2026, 6:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 6:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 6:21 AM UTCbounded_response
Tested — pass2609 bytes within scanner limit
Basis: harmless scanner · Oct 1, 2026, 6:21 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 1, 2026, 6:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:21 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 1, 2026, 6:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 1, 2026, 6:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 1, 2026, 6:21 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:21 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 6:21 AM UTC— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"12053 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-withdrawn
offer-active: 1 → 0
Evidence: openapi source https://agents.martinestate.com/openapi.json
— endpoint-updated
description: Purchase wine with identity verification via AgentScore and MPP payment → Purchase wine. Requires identity verification via AgentScore and MPP payment.
Evidence: clock-guarded source update
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"12053 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:openapi_parse: {"state":"tested-pass","evidence":"4 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-pass","evidence":"3 payment offer(s) accepted","basis":"harmless discovery response"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-updated
currency: USD → EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
Evidence: openapi payment metadata
— payment-offer-updated
session_json: {"mode":"dynamic","min":"50.00","max":"5000.00","x402":{"scheme":"exact","network":"base","asset":"USDC","client":"agen…
Evidence: openapi payment metadata
— payment-offer-updated
currency: USD → 0x20c000000000000000000000b9537d11c60e8b50
Evidence: openapi payment metadata
— payment-offer-updated
session_json: {"mode":"dynamic","min":"50.00","max":"5000.00","mpp":{"method":"solana","intent":"charge","currency":"EPjFWdd5AufqSSqe…
Evidence: openapi payment metadata
— payment-offer-updated
session_json: {"mode":"dynamic","min":"50.00","max":"5000.00","mpp":{"method":"tempo","intent":"charge","currency":"0x20c000000000000…
Evidence: openapi payment metadata
— endpoint-updated
description: Purchase wine. Requires identity verification via AgentScore and MPP payment. → Purchase wine with identity verification via AgentScore and MPP payment
Evidence: clock-guarded source update
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"3120 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"3102 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"11756 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— endpoint-updated
description: Purchase wine with identity verification via AgentScore and MPP payment → Purchase wine. Requires identity verification via AgentScore and MPP payment.
Evidence: clock-guarded source update
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"11756 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— endpoint-updated
description: Purchase wine. Requires identity verification via AgentScore and MPP payment. → Purchase wine with identity verification via AgentScore and MPP payment
Evidence: clock-guarded source update
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"11219 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— endpoint-updated
description: Purchase wine with identity verification via AgentScore and MPP payment → Purchase wine. Requires identity verification via AgentScore and MPP payment.
Evidence: clock-guarded source update
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"11219 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— endpoint-updated
description: Purchase wine. Requires identity verification via AgentScore and MPP payment. → Purchase wine with identity verification via AgentScore and MPP payment
Evidence: clock-guarded source update
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"11219 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property