Service record

Xquik API

https://xquik.com/
observed-mpp

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Read and automate X. Paid reads accept credits. Some lookups accept MPP. Writes require API key or OAuth 2.1. Shared-account reads return public posts only. ## Client Libraries [SDK, CLI, Terraform](https://docs.xquik.com/sdks), [TweetClaw](https://docs.xquik.com/guides/tweetclaw), and [version deprecation](https://xquik.com/deprecation-policy.md).

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 12:29 PM UTC
Origin
https://xquik.com
Tags
None advertised

Payment surface

7 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://xquik.com/api/v1/trends
Returns current regional trends through the compatibility route.
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 1, 06:20 PM UTC
tempochargechallenge450 0x20c000000000000000000000b9537d11c60e8b50
Recipient
0xbe6c07f6fce303483458a7ddc929eb50a8ae6574
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi450 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://xquik.com/api/v1/x/articles/%7BtweetId%7D
Retrieve the full content of an X Article (long-form post) by numeric tweet ID. Returns article_not_found when the tweet is valid but is not an X Article.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi750 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://xquik.com/api/v1/x/communities/%7Bid%7D/info
Returns public identity and membership counts for one community.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi150 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://xquik.com/api/v1/x/followers/check
Returns whether one public account follows another.
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:19 AM UTC
tempochargechallenge150 0x20c000000000000000000000b9537d11c60e8b50
Recipient
0xbe6c07f6fce303483458a7ddc929eb50a8ae6574
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi750 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://xquik.com/api/v1/x/trends
Returns current X trends for the requested region.
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 2, 06:21 PM UTC
tempochargechallenge450 0x20c000000000000000000000b9537d11c60e8b50
Recipient
0xbe6c07f6fce303483458a7ddc929eb50a8ae6574
Chain
4217
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi450 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://xquik.com/api/v1/x/tweets/%7Bid%7D
Returns one public tweet with author, metrics, and media.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi150 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://xquik.com/api/v1/x/users/%7Bid%7D
Returns one public profile with counts and verification details.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi150 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

104 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 12:29 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 6:25 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 12:32 AM UTC

GET https://xquik.com/api/v1/x/followers/check

HTTP 402

1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:19 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 6:32 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 12:29 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 6:28 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 12:29 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 6:29 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 12:28 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 6:32 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 12:37 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 6, 2026, 6:31 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 6, 2026, 12:34 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 6, 2026, 6:24 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 6, 2026, 12:30 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 5, 2026, 6:29 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 5, 2026, 12:28 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 5, 2026, 6:27 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 5, 2026, 12:27 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 5, 2026, 12:19 AM UTC

GET https://xquik.com/api/v1/x/trends

HTTP 402

1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 2, 2026, 6:21 PM UTC

GET https://xquik.com/api/v1/trends

HTTP 402

1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:20 PM UTC

GET https://xquik.com/mcp/server-card

HTTP 200

845 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:19 PM UTC

GET https://xquik.com/.well-known/api-catalog

HTTP 200

1,434 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:20 AM UTC

GET https://xquik.com/openapi.json

HTTP 200

420,650 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:20 AM UTC

GET https://xquik.com/api/v1/x/followers/check

HTTP 402

1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 29, 2026, 6:19 PM UTC

GET https://xquik.com/

HTTP 200

258,743 response bytes · 1 redirect · HTTPS fetch completed with platform certificate validation

Sep 25, 2026, 12:24 PM UTC · Final URL: https://xquik.com/en

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 25, 2026, 6:26 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 25, 2026, 12:35 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 24, 2026, 6:29 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 24, 2026, 12:27 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 24, 2026, 6:28 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 24, 2026, 12:26 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 23, 2026, 6:28 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 23, 2026, 12:32 PM UTC

GET https://xquik.com/api/v1/x/trends

HTTP 402

1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 23, 2026, 12:21 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 23, 2026, 6:30 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 23, 2026, 12:34 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 22, 2026, 6:37 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 22, 2026, 12:24 PM UTC

GET https://xquik.com/api/v1/trends

HTTP 402

1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 12:21 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 22, 2026, 6:30 AM UTC

GET https://xquik.com/mcp/server-card

HTTP 200

845 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 6:20 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 22, 2026, 12:31 AM UTC

GET https://xquik.com/openapi.json

HTTP 200

389,177 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 12:26 AM UTC

GET https://xquik.com/.well-known/api-catalog

HTTP 200

1,434 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 12:26 AM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 21, 2026, 6:30 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 21, 2026, 12:28 PM UTC

GET https://xquik.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Sep 21, 2026, 6:30 AM UTC
Showing the latest 50 of 104 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

probe_safety

Observed

response-too-large: Response exceeds 262144 bytes

Basis: scanner policy decision · Oct 9, 2026, 12:29 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:19 AM UTC

bounded_response

Tested — pass

1038 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:19 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:19 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:19 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:19 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:19 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:19 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:19 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:19 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 2, 2026, 6:21 PM UTC

bounded_response

Tested — pass

1038 bytes within scanner limit

Basis: harmless scanner · Oct 2, 2026, 6:21 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 2, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 2, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 2, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 2, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 2, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 6:20 PM UTC

bounded_response

Tested — pass

1038 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 6:20 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 1, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 1, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:19 PM UTC

bounded_response

Tested — pass

845 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 12:19 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 1, 2026, 12:19 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:19 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 1, 2026, 12:19 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 12:19 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTC

openapi_parse

Tested — fail

Response was JSON but not a bounded supported OpenAPI 3 document

Basis: harmless discovery response · Oct 1, 2026, 12:19 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 12:19 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:19 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:19 PM UTC

api_catalog_parse

Tested — pass

3 OpenAPI link(s) accepted

Basis: RFC 9727 discovery response · Oct 1, 2026, 6:20 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 25, 2026, 12:24 PM UTC

bounded_response

Tested — pass

258743 bytes within scanner limit

Basis: harmless scanner · Sep 25, 2026, 12:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Sep 25, 2026, 12:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 25, 2026, 12:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Sep 25, 2026, 12:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Sep 25, 2026, 12:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTC

redirect_policy

Tested — pass

1 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Sep 25, 2026, 12:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 25, 2026, 12:24 PM UTC

ssrf_target_validation

Tested — pass

2 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Sep 25, 2026, 12:24 PM UTC

History

Service changes

Showing the latest 50 of 88 changes. Continue in the changes API view.

— payment-offer-updated

amount: 750 → 150

Evidence: challenge payment metadata

— security-property-changed

security:openapi_parse: {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless …

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"420650 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— service-updated

description: Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re… → Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re…

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"420650 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:openapi_parse: {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless … → {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"}

Evidence: Repeated harmless observation changed the modeled property

— probe-observation

content_type → text/html; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation

— endpoint-discovered

endpoint → created

Evidence: normalized discovery source

— probe-observation

last_status → 200

Evidence: harmless unauthenticated HTTP observation

— probe-observation

redirect_count → 1

Evidence: harmless unauthenticated HTTP observation

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"389177 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:openapi_parse: {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless …

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"389177 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— service-updated

description: Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re… → Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re…

Evidence: clock-guarded source update

— security-property-changed

security:openapi_parse: {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless … → {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"387972 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:openapi_parse: {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless …

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"387972 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:openapi_parse: {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless … → {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402","basis":"unauthenticated HTTP response"} → {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402","basis":"unauthenticated HTTP response"} → {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat…

Evidence: Repeated harmless observation changed the modeled property