Service record

VALORIA

https://valoria.net/
candidate

Search engine for agents. 100K+ x402, MCP, and MPP services indexed with real on-chain revenue data. Free discovery layer for the agentic web. Search, discover, and interact with any service — pay via x402 or MPP/Tempo. Powered by Valoria.

Implementation fingerprint
unknown no confident attribution
Fingerprint evidence
No implementation-specific public signal observed.
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 12:53 PM UTC
Origin
https://valoria.net
Tags
None advertised

Payment surface

12 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://valoria.net/api/categories
Browse all categories in the agent economy
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 6, 12:25 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://valoria.net/api/domain/%7Bdomain%7D
Full details for any indexed service
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://valoria.net/api/feeds
Curated feeds — the front page of the agent economy
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 6, 12:23 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://valoria.net/api/leaderboard
Ranked leaderboard of top agent services
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 6, 12:20 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://valoria.net/api/protocols
All supported payment and discovery protocols
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 7, 12:21 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://valoria.net/api/stats
Economy-wide statistics
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 6, 12:22 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://valoria.net/intelligence/analyze
Deep competitive analysis of any x402 service
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi5.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://valoria.net/intelligence/market
Full market report: trends, concentration, builder playbook
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi50.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://valoria.net/intelligence/opportunities
Ranked profitable gaps in the agent economy
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi25.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://valoria.net/intelligence/pricing
Data-driven pricing recommendation for your x402 service
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi10.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://valoria.net/intelligence/pulse
Market pulse — real-time agent economy snapshot
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi1.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://valoria.net/search
Search the agent economy
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Sep 7, 06:23 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
open
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

301 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 9, 2026, 12:53 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 9, 2026, 12:33 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 9, 2026, 6:48 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 9, 2026, 6:27 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 9, 2026, 12:57 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 9, 2026, 12:37 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 8, 2026, 6:56 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 8, 2026, 6:36 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 8, 2026, 12:53 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 8, 2026, 12:33 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 8, 2026, 6:52 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 8, 2026, 6:31 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 8, 2026, 12:53 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 8, 2026, 12:32 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 7, 2026, 6:52 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 7, 2026, 6:32 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 7, 2026, 12:52 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 7, 2026, 12:31 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 7, 2026, 6:57 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 7, 2026, 6:36 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 7, 2026, 1:01 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 7, 2026, 12:40 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 6, 2026, 6:57 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 6, 2026, 6:36 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 6, 2026, 12:57 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 6, 2026, 12:37 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 6, 2026, 6:46 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 6, 2026, 6:26 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 6, 2026, 12:52 AM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 6, 2026, 12:40 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 6, 2026, 12:32 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 5, 2026, 6:52 PM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 5, 2026, 6:39 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 5, 2026, 6:32 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 5, 2026, 12:50 PM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 5, 2026, 12:38 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 5, 2026, 12:31 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 5, 2026, 6:50 AM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 5, 2026, 6:37 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 5, 2026, 6:30 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 5, 2026, 12:51 AM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 5, 2026, 12:39 AM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 5, 2026, 12:31 AM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 4, 2026, 6:48 PM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 4, 2026, 6:35 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 4, 2026, 6:28 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 4, 2026, 12:53 PM UTC

GET https://valoria.net/

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/ was recorded but not followed

Oct 4, 2026, 12:40 PM UTC

GET https://valoria.net/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/openapi.json was recorded but not followed

Oct 4, 2026, 12:33 PM UTC

GET https://valoria.net/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Oct 4, 2026, 6:51 AM UTC
Showing the latest 50 of 301 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-catalog was recorded but not followed

Basis: scanner policy decision · Oct 9, 2026, 12:53 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/api/protocols was recorded but not followed

Basis: scanner policy decision · Sep 16, 2026, 12:24 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/search was recorded but not followed

Basis: scanner policy decision · Sep 16, 2026, 6:24 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/api/stats was recorded but not followed

Basis: scanner policy decision · Sep 15, 2026, 12:24 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/api/leaderboard was recorded but not followed

Basis: scanner policy decision · Sep 15, 2026, 12:21 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/api/categories was recorded but not followed

Basis: scanner policy decision · Sep 15, 2026, 12:28 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://www.valoria.net/api/feeds was recorded but not followed

Basis: scanner policy decision · Sep 15, 2026, 12:26 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 7, 2026, 12:21 PM UTC

bounded_response

Tested — pass

1293 bytes within scanner limit

Basis: harmless scanner · Sep 7, 2026, 12:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 7, 2026, 12:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 7, 2026, 12:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 7, 2026, 12:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 7, 2026, 12:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 7, 2026, 12:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 7, 2026, 12:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 7, 2026, 12:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 7, 2026, 12:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 7, 2026, 12:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 7, 2026, 12:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 7, 2026, 12:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 7, 2026, 12:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 7, 2026, 6:23 AM UTC

bounded_response

Tested — pass

6509 bytes within scanner limit

Basis: harmless scanner · Sep 7, 2026, 6:23 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 7, 2026, 6:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 7, 2026, 6:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 7, 2026, 6:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 7, 2026, 6:23 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 7, 2026, 6:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 7, 2026, 6:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 7, 2026, 6:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 7, 2026, 6:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 7, 2026, 6:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 7, 2026, 6:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 7, 2026, 6:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 7, 2026, 6:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 6, 2026, 12:22 PM UTC

bounded_response

Tested — pass

138 bytes within scanner limit

Basis: harmless scanner · Sep 6, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 6, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 6, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 6, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 6, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 6, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 6, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 6, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 6, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 6, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 6, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 6, 2026, 12:20 PM UTC

bounded_response

Tested — pass

5612 bytes within scanner limit

Basis: harmless scanner · Sep 6, 2026, 12:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 6, 2026, 12:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 6, 2026, 12:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 6, 2026, 12:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 6, 2026, 12:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 6, 2026, 12:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 6, 2026, 12:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 6, 2026, 12:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 6, 2026, 12:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 6, 2026, 12:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 6, 2026, 12:20 PM UTC

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Sep 6, 2026, 6:18 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 6, 2026, 6:18 AM UTC

bounded_response

Tested — pass

162 bytes within scanner limit

Basis: harmless scanner · Sep 6, 2026, 6:18 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 6, 2026, 6:18 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 6, 2026, 6:18 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 6, 2026, 6:18 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 6:18 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 6, 2026, 6:18 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 6, 2026, 6:18 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 6, 2026, 6:18 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 6, 2026, 6:18 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 6, 2026, 6:18 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 6, 2026, 6:18 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 6:18 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 6, 2026, 6:18 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 6, 2026, 12:25 AM UTC

bounded_response

Tested — pass

438 bytes within scanner limit

Basis: harmless scanner · Sep 6, 2026, 12:25 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 6, 2026, 12:25 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 6, 2026, 12:25 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 6, 2026, 12:25 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:25 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 6, 2026, 12:25 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 6, 2026, 12:25 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 6, 2026, 12:25 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 6, 2026, 12:25 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 6, 2026, 12:25 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 6, 2026, 12:25 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:25 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 6, 2026, 12:25 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 6, 2026, 12:23 AM UTC

bounded_response

Tested — pass

8347 bytes within scanner limit

Basis: harmless scanner · Sep 6, 2026, 12:23 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 6, 2026, 12:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 6, 2026, 12:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 6, 2026, 12:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:23 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 6, 2026, 12:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 6, 2026, 12:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 6, 2026, 12:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 6, 2026, 12:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 6, 2026, 12:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 6, 2026, 12:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 6, 2026, 12:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 6, 2026, 12:23 AM UTC

openapi_parse

Tested — pass

12 payment offer(s) accepted

Basis: harmless discovery response · Sep 4, 2026, 12:21 PM UTC

History

Service changes

Showing the latest 50 of 369 changes. Continue in the changes API view.

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/openapi.json was re… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://www.valoria.net/.well-known/api-cat…

Evidence: Repeated harmless observation changed the modeled property