GET https://x402.agentindex.world/openapi.json
HTTP 200297,599 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:53 PM UTCPublic discovery candidate; runtime MPP not yet established
Payment surface
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
Probe coverage
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
297,599 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:53 PM UTC164,214 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:43 PM UTC22 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:29 PM UTCEvidence model
Every result names its evidence state. Unknown and not tested never mean secure.
Requires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:53 PM UTC297599 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:53 PM UTCNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:53 PM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:53 PM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:53 PM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:53 PM UTCNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:53 PM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:53 PM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:53 PM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:53 PM UTCCredential-shaped discovery URL was excluded from indexing and fan-out by scanner policy
Basis: harmless discovery response · Oct 9, 2026, 12:53 PM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:53 PM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:53 PM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:53 PM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:53 PM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:43 PM UTC164214 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:43 PM UTCNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:43 PM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:43 PM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:43 PM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:43 PM UTCNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:43 PM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:43 PM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:43 PM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:43 PM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:43 PM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:43 PM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:43 PM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:43 PM UTCNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 9, 2026, 12:29 PM UTCHistory
security:bounded_response: {"state":"tested-pass","evidence":"22 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"297599 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
content_type → application/json
Evidence: harmless unauthenticated HTTP observation
tls_state: not-tested → tested-pass
Evidence: harmless unauthenticated HTTP observation