Service record

Affiliate.com

https://zeroclick.affiliate.com/
observed-mpp

Product catalog search across all Affiliate.com merchants. Search and retrieve products with structured queries, and look up the merchants behind the catalog. This server is a pay-per-use, transparent proxy in front of Affiliate.com's own API: it handles identity, payment, and proxying. Agents can purchase autonomously or with their human's approval. The complete verified paid surface is listed at /openapi.json, the source of truth for available operations. Each operation here carries its live price in x-payment-info. Use the operations and details here when they meet your needs. Filtered specs contain only matching operations; if you cannot find what you need here, use search or the service catalog. The live catalog at /manifest.json is authoritative for prices and any free included units (prices[].includedUnits) - some meters include free usage per account before any charge, reserved for agents claimed by a human with a verified email.

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Oct 7, 2026, 12:17 AM UTC
Last seen
Oct 9, 2026, 12:43 PM UTC
Origin
https://zeroclick.affiliate.com
Tags
None advertised

Payment surface

9 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://zeroclick.affiliate.com/v1/merchants
List merchants
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 7, 12:58 AM UTC
tempochargechallenge20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0xb0e55dff7ab98cdabae792ba1493e32d1caded33
Chain
4217
Unit type
not observed
Session · externalId
apay_S3_drv8C6MeSur8e3I2iI
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://zeroclick.affiliate.com/v1/merchants/%7Bid%7D
Get merchant details
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/v1/products
Create product
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/v1/tools/convert/asin-to-barcode
Convert ASIN to barcode
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/v1/tools/convert/barcode-to-asin
Convert barcode to ASIN
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/v1/tools/convert/barcode-to-sku
Convert barcode to SKU
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/v1/tools/convert/sku-to-barcode
Convert merchant-specific SKUs to product barcodes
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/v1/tools/convert/url-to-barcode
Convert retailer product page URLs to barcodes
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://zeroclick.affiliate.com/zeroclick/agent/quote
Get a free seller API quote and purchase guide
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi0 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

14 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 12:43 PM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 6:34 AM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 12:48 AM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 6:43 PM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 12:41 PM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 6:40 AM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 12:42 AM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 6:40 PM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 12:39 PM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 6:45 AM UTC

GET https://zeroclick.affiliate.com/.well-known/api-catalog

HTTP 404

71 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 1:07 AM UTC

GET https://zeroclick.affiliate.com/v1/merchants

HTTP 402

4,927 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:58 AM UTC

GET https://zeroclick.affiliate.com/openapi.json

HTTP 200

93,726 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:55 AM UTC

GET https://zeroclick.affiliate.com/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 12:50 AM UTC

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

probe_safety

Observed

response-too-large: Response exceeds 262144 bytes

Basis: scanner policy decision · Oct 9, 2026, 12:43 PM UTC

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Oct 7, 2026, 1:07 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 1:07 AM UTC

bounded_response

Tested — pass

71 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 1:07 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 7, 2026, 1:07 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 1:07 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 7, 2026, 1:07 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 1:07 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 1:07 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 1:07 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 1:07 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 12:58 AM UTC

bounded_response

Tested — pass

4927 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 12:58 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 12:58 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:58 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 12:58 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 12:58 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 12:58 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:58 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 12:58 AM UTC

openapi_parse

Tested — pass

9 payment offer(s) accepted

Basis: harmless discovery response · Oct 7, 2026, 12:55 AM UTC

History

Service changes

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"93726 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"71 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— service-updated

status: candidate → observed-mpp

Evidence: clock-guarded source update

— endpoint-source-discovered

source:challenge → active

Evidence: https://zeroclick.affiliate.com/v1/merchants

— fingerprint-changed

implementation: unknown:0.0 → custom:0.35

Evidence: ["valid 402 Payment challenge observed without implementation-specific marker"]

— probe-observation

challenge_format → mpp-payment-auth

Evidence: harmless unauthenticated HTTP observation

— payment-offer-discovered

offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":"4217","recipient…

Evidence: challenge payment metadata

— probe-observation

last_status → 402

Evidence: harmless unauthenticated HTTP observation

— probe-observation

redirect_count → 0

Evidence: harmless unauthenticated HTTP observation

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation

— probe-observation

content_type → application/json; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— payment-offer-discovered

offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":null,"recipient":…

Evidence: openapi payment metadata

— payment-offer-discovered

offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":null,"recipient":…

Evidence: openapi payment metadata

— endpoint-discovered

endpoint → created

Evidence: completed normalized source snapshot

— endpoint-discovered

endpoint → created

Evidence: completed normalized source snapshot

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— endpoint-discovered

endpoint → created

Evidence: completed normalized source snapshot

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— endpoint-discovered

endpoint → created

Evidence: completed normalized source snapshot

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— endpoint-discovered

endpoint → created

Evidence: completed normalized source snapshot

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— endpoint-source-discovered

source:openapi → active

Evidence: https://zeroclick.affiliate.com/openapi.json

— payment-offer-discovered

offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":null,"recipient":…

Evidence: openapi payment metadata