Service record

AgentMail

https://mpp.api.agentmail.to/
activeaisocial

Email inboxes for AI agents.

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 12:38 PM UTC
Origin
https://mpp.api.agentmail.to
Tags
emailinboxesdomainsdraftsthreadswebhooksmessaging

Payment surface

154 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.

JSON record →
POST
https://mpp.api.agentmail.to/v0/api-keys
Create API key
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
No normalized payment offer observed for this endpoint.
DELETE
https://mpp.api.agentmail.to/v0/api-keys/:api_key
Delete API key
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
No normalized payment offer observed for this endpoint.
GET
https://mpp.api.agentmail.to/v0/domains
List domains
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 06:23 PM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.api.agentmail.to/v0/domains
Create domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog10000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapi10.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
DELETE
https://mpp.api.agentmail.to/v0/domains/%7Bdomain_id%7D
Delete Domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/domains/%7Bdomain_id%7D
Get Domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
PATCH
https://mpp.api.agentmail.to/v0/domains/%7Bdomain_id%7D
Update Domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.api.agentmail.to/v0/domains/%7Bdomain_id%7D/verify
Verify Domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/domains/%7Bdomain_id%7D/zone-file
Get Zone File
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
DELETE
https://mpp.api.agentmail.to/v0/domains/:domain_id
Delete domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
No normalized payment offer observed for this endpoint.
GET
https://mpp.api.agentmail.to/v0/domains/:domain_id
Get domain
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 8, 12:21 AM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.api.agentmail.to/v0/domains/:domain_id/verify
Verify domain
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
No normalized payment offer observed for this endpoint.
GET
https://mpp.api.agentmail.to/v0/domains/:domain_id/zone-file
Get zone file
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 8, 06:22 AM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/drafts
List drafts
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 7, 06:20 AM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/drafts/%7Bdraft_id%7D
Get Draft
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/drafts/%7Bdraft_id%7D/attachments/%7Battachment_id%7D
Get Attachment
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/drafts/:draft_id
Get draft
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 8, 12:20 AM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/drafts/:draft_id/attachments/:attachment_id
Get attachment
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:21 PM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/inboxes
List inboxes
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 7, 12:31 AM UTC
tempochargechallenge0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x6e3184C204e596dED89E8A5693B602097F4Ab687
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.api.agentmail.to/v0/inboxes
Create inbox
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalog2000000 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
mppchargeopenapi2.000000 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
DELETE
https://mpp.api.agentmail.to/v0/inboxes/%7Binbox_id%7D
Delete Inbox
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/inboxes/%7Binbox_id%7D
Get Inbox
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
PATCH
https://mpp.api.agentmail.to/v0/inboxes/%7Binbox_id%7D
Update Inbox
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://mpp.api.agentmail.to/v0/inboxes/%7Binbox_id%7D/drafts
List Drafts
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://mpp.api.agentmail.to/v0/inboxes/%7Binbox_id%7D/drafts
Create Draft
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
mppchargeopenapi0.01 currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

309 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 9, 2026, 12:38 PM UTC

GET https://mpp.api.agentmail.to/v0/drafts/:draft_id/attachments/:attachment_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:21 PM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 9, 2026, 6:29 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/threads/:thread_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:19 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/drafts/:draft_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:18 AM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 9, 2026, 12:44 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:26 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/metrics

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:25 AM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 8, 2026, 6:39 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/drafts/:draft_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:25 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/threads/:thread_id/attachments/:attachment_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:25 PM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 8, 2026, 12:36 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/threads/:thread_id/attachments/:attachment_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:25 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/drafts/:draft_id/attachments/:attachment_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:25 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/drafts

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:25 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/drafts/:draft_id/attachments/:attachment_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:25 PM UTC

GET https://mpp.api.agentmail.to/v0/lists/:direction/:type/:entry

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:25 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/drafts

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:24 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages/:message_id/raw

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:23 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages/:message_id/attachments/:attachment_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:23 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/domains

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:19 PM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 8, 2026, 6:35 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/inboxes/:inbox_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:23 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/domains/:domain_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:23 AM UTC

GET https://mpp.api.agentmail.to/v0/domains/:domain_id/zone-file

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:22 AM UTC

GET https://mpp.api.agentmail.to/v0/threads/:thread_id/attachments/:attachment_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/threads

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/threads/:thread_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/lists/:direction/:type

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/lists/:direction/:type/:entry

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 8, 2026, 12:38 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/domains/:domain_id/zone-file

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:25 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/metrics

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:21 AM UTC

GET https://mpp.api.agentmail.to/v0/domains/:domain_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:21 AM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/lists/:direction/:type/:entry

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:20 AM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/inboxes

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:20 AM UTC

GET https://mpp.api.agentmail.to/v0/drafts/:draft_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:20 AM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 7, 2026, 6:37 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/api-keys

HTTP 404

92 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:23 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages/:message_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:23 PM UTC

GET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id

HTTP 403

91 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:22 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/lists/:direction/:type

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 PM UTC

GET https://mpp.api.agentmail.to/v0/pods/:pod_id/threads

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 PM UTC

GET https://mpp.api.agentmail.to/v0/threads/:thread_id

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 PM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 7, 2026, 12:35 PM UTC

GET https://mpp.api.agentmail.to/v0/lists/:direction/:type

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:20 PM UTC

GET https://mpp.api.agentmail.to/

scanner stopped: cross-host-redirect

Cross-host redirect to https://agentmail.to/ was recorded but not followed

Oct 7, 2026, 6:42 AM UTC

GET https://mpp.api.agentmail.to/v0/pods

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:24 AM UTC

GET https://mpp.api.agentmail.to/v0/webhooks

HTTP 402

192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:22 AM UTC
Showing the latest 50 of 309 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://agentmail.to/ was recorded but not followed

Basis: scanner policy decision · Oct 9, 2026, 12:38 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:19 AM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:19 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:19 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:19 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:19 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:19 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:19 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:18 AM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:18 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:18 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:18 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:18 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 AM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:26 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:26 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:26 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:26 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:25 AM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:25 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:25 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:25 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:25 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:25 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:25 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:25 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:25 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:25 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 6:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:25 PM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 6:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:24 PM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 PM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 PM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:19 PM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:19 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:19 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:19 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:19 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:19 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:19 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:23 AM UTC

bounded_response

Tested — pass

91 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:23 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:23 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 8, 2026, 6:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:23 AM UTC

bounded_response

Tested — pass

192 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:23 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:23 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 6:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC
Showing a bounded 250 of 675 security-property records.

History

Service changes

Showing the latest 50 of 847 changes. Continue in the changes API view.

— endpoint-source-withdrawn

source:catalog: 1 → 0

Evidence: https://mpp.dev/api/services

— endpoint-source-withdrawn

source:catalog: 1 → 0

Evidence: https://mpp.dev/api/services

— endpoint-updated

description: Create inbox → Create Inbox

Evidence: clock-guarded source update

— endpoint-updated

description: List threads → List Threads

Evidence: clock-guarded source update

— endpoint-updated

description: List domains → List Domains

Evidence: clock-guarded source update

— endpoint-updated

description: List pods → List Pods

Evidence: clock-guarded source update

— endpoint-updated

description: Query metrics → Query Metrics

Evidence: clock-guarded source update

— endpoint-updated

description: List inboxes → List Inboxes

Evidence: clock-guarded source update

— endpoint-updated

description: Create pod → Create Pod

Evidence: clock-guarded source update

— endpoint-updated

description: List drafts → List Drafts

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"92 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"140694 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-updated

description: Create domain → Create Domain

Evidence: clock-guarded source update

— endpoint-updated

description: Create Pod → Create pod

Evidence: clock-guarded source update

— endpoint-updated

description: List Threads → List threads

Evidence: clock-guarded source update

— endpoint-updated

description: Query Metrics → Query metrics

Evidence: clock-guarded source update

— endpoint-updated

description: Create Inbox → Create inbox

Evidence: clock-guarded source update

— endpoint-updated

description: List Pods → List pods

Evidence: clock-guarded source update

— endpoint-updated

description: List Inboxes → List inboxes

Evidence: clock-guarded source update

— endpoint-updated

description: List Drafts → List drafts

Evidence: clock-guarded source update

— endpoint-updated

description: Create Domain → Create domain

Evidence: clock-guarded source update

— endpoint-updated

description: List Domains → List domains

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"140694 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"92 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-updated

description: List inboxes → List Inboxes

Evidence: clock-guarded source update

— endpoint-updated

description: List pods → List Pods

Evidence: clock-guarded source update

— endpoint-updated

description: List threads → List Threads

Evidence: clock-guarded source update