Service record

ip402.xyz

https://ip402.xyz/
observed-mpp

Paid IP geolocation and ASN lookup for agents. One IP in, normalized geolocation + network data out. Payment is the access control — no accounts, no API keys. Optional bundle: pay n x $0.01 once (?bundle=<n>, 2<=n<=100) and spend n lookups within 1 hour via SIWX (CAIP-122) signatures.

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 6:17 PM UTC
Origin
https://ip402.xyz
Tags
None advertised

Payment surface

1 MPP endpoint

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://ip402.xyz/v1/geo
Paid single IP geolocation lookup
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 1, 12:22 PM UTC
tempochargechallenge10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x15A6a5B190de7C3bf33abe7a81e0C0eE77dDf581
Chain
4217
Unit type
not observed
Session · description
ip402 single GeoIP lookup
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

13 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://ip402.xyz/openapi.json

HTTP 200

5,654 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:22 PM UTC

GET https://ip402.xyz/.well-known/api-catalog

HTTP 200

2,931 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 2, 2026, 12:24 PM UTC

GET https://ip402.xyz/

HTTP 200

2,931 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:24 PM UTC

GET https://ip402.xyz/v1/geo

HTTP 402

1,700 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:22 PM UTC

GET https://ip402.xyz/openapi.json

HTTP 200

5,654 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:19 PM UTC

GET https://ip402.xyz/.well-known/api-catalog

HTTP 200

2,931 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 23, 2026, 6:21 AM UTC

GET https://ip402.xyz/

HTTP 200

2,931 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 12:19 PM UTC

GET https://ip402.xyz/v1/geo

HTTP 402

1,700 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 6:22 AM UTC

GET https://ip402.xyz/openapi.json

HTTP 200

5,654 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:20 PM UTC

GET https://ip402.xyz/.well-known/api-catalog

HTTP 200

2,931 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 14, 2026, 6:21 AM UTC

GET https://ip402.xyz/

HTTP 200

2,931 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 13, 2026, 12:17 PM UTC

GET https://ip402.xyz/v1/geo

HTTP 402

1,339 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 13, 2026, 6:21 AM UTC

GET https://ip402.xyz/openapi.json

HTTP 200

5,623 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:18 PM UTC

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTC

bounded_response

Tested — pass

5654 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

openapi_parse

Tested — pass

1 payment offer(s) accepted

Basis: harmless discovery response · Oct 9, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTC

api_catalog_parse

Observed

RFC 9727 well-known path returned 200 text/html; charset=utf-8; no API catalog was established

Basis: RFC 9727 discovery response · Oct 2, 2026, 12:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:24 PM UTC

bounded_response

Tested — pass

2931 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 12:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 1, 2026, 12:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 12:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 12:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 1, 2026, 12:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 12:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 12:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 12:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 12:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 12:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:22 PM UTC

bounded_response

Tested — pass

1700 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 12:22 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 1, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 1, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:22 PM UTC

History

Service changes

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"5654 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"5654 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"5654 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"5654 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1339 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1700 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"5654 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:api_catalog_parse: {"state":"tested-fail","evidence":"API catalog response was not valid JSON","basis":"RFC 9727 discovery response"} → {"state":"observed","evidence":"RFC 9727 well-known path returned 200 text/html; charset=utf-8; no API catalog was esta…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402","basis":"unauthenticated HTTP response"} → {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"5623 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"2931 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation

— endpoint-discovered

endpoint → created

Evidence: normalized discovery source

— probe-observation

last_status → 200

Evidence: harmless unauthenticated HTTP observation

— probe-observation

content_type → text/html; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— probe-observation

redirect_count → 0

Evidence: harmless unauthenticated HTTP observation

— service-updated

status: candidate → observed-mpp

Evidence: clock-guarded source update

— endpoint-source-discovered

source:challenge → active

Evidence: https://ip402.xyz/v1/geo

— fingerprint-changed

implementation: unknown:0.0 → custom:0.35

Evidence: ["valid 402 Payment challenge observed without implementation-specific marker"]

— probe-observation

redirect_count → 0

Evidence: harmless unauthenticated HTTP observation

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation