- Recipient
- 0xb0e55dff7ab98cdabae792ba1493e32d1caded33
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_S3_drv8C6MeSur8e3I2iI
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Product catalog search across all Affiliate.com merchants. Search and retrieve products with structured queries, and look up the merchants behind the catalog. This server is a pay-per-use, transparent proxy in front of Affiliate.com's own API: it handles identity, payment, and proxying. Agents can purchase autonomously or with their human's approval. The complete verified paid surface is listed at /openapi.json, the source of truth for available operations. Each operation here carries its live price in x-payment-info. Use the operations and details here when they meet your needs. Filtered specs contain only matching operations; if you cannot find what you need here, use search or the service catalog. The live catalog at /manifest.json is authoritative for prices and any free included units (prices[].includedUnits) - some meters include free usage per account before any charge, reserved for agents claimed by a human with a verified email.
Payment surface
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
Probe coverage
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
Response exceeds 262144 bytes
Oct 9, 2026, 12:43 PM UTCResponse exceeds 262144 bytes
Oct 9, 2026, 6:34 AM UTCResponse exceeds 262144 bytes
Oct 9, 2026, 12:48 AM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 6:43 PM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 12:41 PM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 6:40 AM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 12:42 AM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 6:40 PM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 12:39 PM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 6:45 AM UTC71 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 1:07 AM UTC4,927 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:58 AM UTC93,726 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:55 AM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 12:50 AM UTCEvidence model
Every result names its evidence state. Unknown and not tested never mean secure.
response-too-large: Response exceeds 262144 bytes
Basis: scanner policy decision · Oct 9, 2026, 12:43 PM UTCNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 7, 2026, 1:07 AM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 1:07 AM UTC71 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 1:07 AM UTCNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 7, 2026, 1:07 AM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 1:07 AM UTCNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 7, 2026, 1:07 AM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 1:07 AM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 1:07 AM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 1:07 AM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 1:07 AM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 1:07 AM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 12:58 AM UTC4927 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 12:58 AM UTC1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 12:58 AM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:58 AM UTC[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 12:58 AM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 12:58 AM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 12:58 AM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 12:58 AM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 12:58 AM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 12:58 AM UTC9 payment offer(s) accepted
Basis: harmless discovery response · Oct 7, 2026, 12:55 AM UTCHistory
security:bounded_response: {"state":"tested-pass","evidence":"93726 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"71 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
source:challenge → active
Evidence: https://zeroclick.affiliate.com/v1/merchants
implementation: unknown:0.0 → custom:0.35
Evidence: ["valid 402 Payment challenge observed without implementation-specific marker"]
challenge_format → mpp-payment-auth
Evidence: harmless unauthenticated HTTP observation
offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":"4217","recipient…
Evidence: challenge payment metadata
tls_state: not-tested → tested-pass
Evidence: harmless unauthenticated HTTP observation
content_type → application/json; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":null,"recipient":…
Evidence: openapi payment metadata
offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":null,"recipient":…
Evidence: openapi payment metadata
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
source:openapi → active
Evidence: https://zeroclick.affiliate.com/openapi.json
offer → {"method":"tempo","intent":"charge","currency":"0x20C000000000000000000000b9537d11c60E8b50","chainId":null,"recipient":…
Evidence: openapi payment metadata