- Recipient
- not observed
- Chain
- not observed
- Unit type
- request
Quicknode Core Node API for 80+ blockchains and 140+ networks.
- Implementation fingerprint
- unknown no confident attribution
- Fingerprint evidence
- No implementation-specific public signal observed.
- First seen
- Aug 25, 2026, 6:43 PM UTC
- Last seen
- Oct 9, 2026, 6:17 PM UTC
- Origin
- https://mpp.quicknode.com
- Tags
- rpcjson-rpcevmsolanatemponode
Payment surface
1 MPP endpoint
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
Probe coverage
8 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://mpp.quicknode.com/openapi.json
HTTP 200611,687 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:24 PM UTCGET https://mpp.quicknode.com/.well-known/api-catalog
HTTP 40431 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:19 AM UTCGET https://mpp.quicknode.com/openapi.json
HTTP 200611,687 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:20 PM UTCGET https://mpp.quicknode.com/.well-known/api-catalog
HTTP 40431 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:18 PM UTCGET https://mpp.quicknode.com/openapi.json
HTTP 200607,154 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:22 PM UTCGET https://mpp.quicknode.com/.well-known/api-catalog
HTTP 40431 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:20 AM UTCGET https://mpp.quicknode.com/openapi.json
HTTP 200607,154 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:19 PM UTCGET https://mpp.quicknode.com/.well-known/api-catalog
HTTP 40431 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 6:18 AM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
authorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:24 PM UTCbounded_response
Tested — pass611687 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCopenapi_parse
Tested — failResponse was JSON but not a bounded supported OpenAPI 3 document
Basis: harmless discovery response · Oct 9, 2026, 12:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:24 PM UTCapi_catalog_parse
ObservedNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 9, 2026, 6:19 AM UTCHistory
Service changes
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"611687 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"611687 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"611687 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:api_catalog_parse: {"state":"observed","evidence":"API catalog source returned HTTP 404; prior advertised links were withdrawn","basis":"R… → {"state":"observed","evidence":"No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links we…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"31 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"607154 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:api_catalog_parse: {"state":"tested-fail","evidence":"API catalog source returned HTTP 404; prior advertised links were withdrawn","basis"… → {"state":"observed","evidence":"API catalog source returned HTTP 404; prior advertised links were withdrawn","basis":"R…
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-discovered
offer → {"method":"tempo","intent":"charge","currency":"0x20c000000000000000000000b9537d11c60e8b50","chainId":null,"recipient":…
Evidence: catalog payment metadata