Service record

x402stock

https://agents.x402stock.xyz/
observed-mpp

Market and economic data for AI agents — US stocks, ETFs and options, forex, crypto and on-chain perps, energy commodities (crude, natural gas, gasoline), US and global macro (Fed funds, CPI/PCE, jobs, GDP, Treasury debt & yields, World Bank indicators), SEC filings, congressional trades, and market sentiment. No API keys, no accounts. Pay per request in USDC via x402 or MPP. This server is a pay-per-use, transparent proxy in front of x402stock's own API: it handles identity, payment, and proxying. Agents can purchase autonomously or with their human's approval. This document is the source of truth for agents: it lists the complete verified paid surface with each operation's live price in its x-payment-info. Endpoints not listed here are not part of the supported catalog. The live catalog at /manifest.json is authoritative for prices and any free included units (prices[].includedUnits) - some meters include free usage per account before any charge, reserved for agents claimed by a human with a verified email.

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 12:43 PM UTC
Origin
https://agents.x402stock.xyz
Tags
None advertised

Payment surface

140 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.

JSON record →
GET
https://agents.x402stock.xyz/api/v1/aggregates/%7Bticker%7D
The stock price history endpoint. Returns historical OHLCV bars at the requested multiplier and timespan (minute, hour, day, week, month) between `from` and `to`. Use for price history, charting, backtesting, and trend analysis over any date range. From x402stock, a pay-per-call market & economic data API for AI agents. No API key or account; pay in USDC via x402.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/archive
Use to discover the point-in-time archive: immutable daily snapshots of ephemeral market state (Hyperliquid perps/spot, JLP pool, pre-IPO marks, market regime, squeeze scores), captured once per UTC day and never overwritten or backfilled. Lists every feed and entity with date coverage; read days via /archive/{feed} and series via /archive/{feed}/range. From x402stock
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 12:24 AM UTC
tempochargechallenge20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_nxS8FmiliWUE0gTaoYp3U
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/archive/%7Bfeed%7D
Use to read one immutable archived day of a feed (sol.jlp, hl.perps, prestocks.markets, scores.squeeze, …): the exact payload the live endpoint returned that day, plus provenance (observed/captured/ingested timestamps + a content hash proving contemporaneous capture). Defaults to latest; ?date=YYYY-MM-DD for a past day, ?entity= on multi-entity feeds. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/archive/%7Bfeed%7D/range
Use for time-series questions over the archive: how JLP AUM, Hyperliquid funding, a pre-IPO token premium, or a ticker's squeeze score evolved day by day. Per-day summaries (oldest first, ?from ?to ?limit, max 366) with capture provenance; payloads omitted — buy a full day via /archive/{feed}?date=. History accumulates daily and cannot be reconstructed retroactively. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi30000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/avg-interest-rates
The average interest rate the US Treasury currently pays on its outstanding debt, broken out by security (Treasury Bills, Notes, Bonds, TIPS, FRNs, savings, and the marketable/total aggregates) for the latest reported month, in percent. No ticker needed. A read on the government's cost of borrowing that complements the /treasury-yields curve. Sourced from the US Treasury (FiscalData).
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 06:22 PM UTC
tempochargechallenge10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_Qxm3T_LSMyhJjzcurD-jP
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/backtest/%7Bticker%7D
Backtests a simple rule on a US stock and returns a finished report PNG. Runs an SMA crossover (?strategy=sma_cross&fast=50&slow=200) or RSI mean-reversion (?strategy=rsi_reversion&period=14&lower=30&upper=70) over daily history (?years=, max 5), no lookahead, rendered as an equity curve vs buy & hold. Returns full stats plus a hosted `artifact.png_url`. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi500000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/basis
Scans every US stock that also trades as a 24/7 synthetic perp and returns the gap: official (delayed) price, prev close, perp mark and oracle, funding APR, open interest, and computed `basis_percent` + `basis_vs_prev_close_percent` — the implied overnight move while the US market is shut. Widest dislocation first, plus a plain-English `reading`. `?limit=`, `?min_basis=`. From x402stock
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 12:22 PM UTC
tempochargechallenge50000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_mbjWhnh4n7-uAweL922LC
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi50000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/basis/%7Bticker%7D
One stock priced on every rail at once: its official US listing (delayed, closed overnight) against the 24/7 Hyperliquid HIP-3 synthetic perp. Returns both prices, funding APR, open interest, and the gap as `basis_percent` + `basis_vs_prev_close_percent` — while the US market is shut, the live view of where the name reopens. From x402stock, a market & economic data API (x402, USDC).
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi30000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/beneficial-ownership/%7Bticker%7D
Schedule 13D/13G filings — triggered when a holder crosses 5% of a class — disclosing beneficial-ownership and activist stakes in a US-listed company, from SEC EDGAR. Per filing: the reporting person, filer-reported percent of class (can be <5% if held via derivatives), shares, voting/dispositive power, and (for 13D) the activist intent. `?type=13D|13G|all`, `?limit=` max 25. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/calendar
Upcoming US economic data releases — WHEN the market-moving prints land, not just their latest values. Returns curated high-importance releases (CPI, PPI, PCE, jobs, JOLTS, GDP, retail sales, housing starts, industrial production) within `?days=` (default 30, max 90), each with date and category, plus the next FOMC meeting. `?past=true` includes the last week. Release dates from FRED.
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 8, 06:22 AM UTC
tempochargechallenge20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_vFfNlDjilSQIvn9wUczlV
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/calendar/fomc
The full FOMC meeting schedule (2025–2027) with the last and next meeting and days-until. Each entry carries the two-day meeting's start and decision date, year, and past/upcoming status. No ticker needed — the rate-decision calendar every macro-aware agent plans around. Source: U.S. Federal Reserve. From x402stock, a market & economic data API (x402, USDC).
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 7, 06:20 AM UTC
tempochargechallenge10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay__8BWS5is5ZUR-qz4jrJja
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/clinical-trials
Clinical trials run by a company, from ClinicalTrials.gov, newest first. Pass `?sponsor=Vertex Pharmaceuticals` (required) plus `?limit=` (max 100). Each trial carries NCT id, title, status, phase(s), study type, conditions, enrollment, lead sponsor, and start/completion/update dates with a link. A primary biotech catalyst. From x402stock, a market & economic data API (x402, USDC).
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 06:20 AM UTC
tempochargechallenge20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_TfRPDKUbsVesBzthRFLCP
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/company-facts/%7Bticker%7D
Every XBRL financial fact a company has reported to the SEC, each collapsed to its latest value: tag, taxonomy, label, unit, the figure, and the period/form/filing it came from. Filter with `?taxonomy=us-gaap|dei`, `?search=revenue`, and `?limit=`. Discover which metrics exist for a ticker before drilling into the full series via /concept. Sourced from SEC EDGAR. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/compare
Compare 2 to 3 US-listed stocks side by side (peer or watchlist comparisons). Pass a comma-separated list via `?tickers=AAPL,MSFT,NVDA` (1 to 3 symbols). Returns price and day change, market cap, P/E, EPS, revenue, gross and net margins, and dividend yield per ticker. Built for multiple stocks — for a single stock, `/api/v1/quote/{ticker}` is cheaper. From x402stock
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 12:22 PM UTC
tempochargechallenge50000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_hbiHDoNfunkWgsMvjG84T
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi50000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/concept/%7Bticker%7D
The reported time series of one XBRL financial concept (e.g. Revenues, Assets, NetIncomeLoss) for a company, taken directly from its SEC filings. Pass the tag via `?tag=` and optionally `?taxonomy=` (default us-gaap) and `?limit=`. Each point carries the value, period, fiscal year/quarter, source form, and accession. Use for precise, filing-grade fundamentals and quant time series. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/conditions
Reference catalog of trade/quote condition codes (the numeric `conditions` seen on trades) with names, types, data types, and SIP mappings. From x402stock, a pay-per-call market & economic data API for AI agents. No API key or account; pay in USDC via x402.
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 7, 06:27 AM UTC
tempochargechallenge10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_KfAsnDuXKCR4OeI82Tjp_
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/congress-trades
Recent stock trades disclosed by US members of Congress under the STOCK Act, parsed live from official House and Senate Periodic Transaction Reports: per trade the member, chamber, ticker, asset, buy/sell type, date, and disclosed dollar range. ?chamber=house|senate|both, ?ticker=AAPL, ?limit= recent filings per chamber (max 20). From US House & Senate. From x402stock
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 06:21 AM UTC
tempochargechallenge30000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay__EV9WoSTr0FI1Gop_qwyF
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi30000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/cot
The weekly CFTC Commitments of Traders positioning across major futures markets in one call: for each market the open interest, non-commercial (large speculator) net position and weekly change, and commercial (hedger) net position. Covers equity indices, gold/silver, crude/natural gas, major FX, the 10-year note, and bitcoin. No ticker needed. Sourced from the US CFTC. From x402stock
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 5, 06:21 PM UTC
tempochargechallenge20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_OsxqFpS3r5zrTkGamsTiY
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/cot/%7Bmarket%7D
CFTC Commitments of Traders for one futures market by slug: sp500, nasdaq, gold, silver, crude-oil, natural-gas, euro, british-pound, japanese-yen, swiss-franc, us-dollar-index, 10y-note, bitcoin. Returns open interest and non-commercial, commercial, and non-reportable long/short/net with weekly changes plus net history. `?weeks=` 12 (max 52). From the US CFTC. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/crypto/%7Bpair%7D/aggregates
Historical OHLCV bars for a major-coin crypto spot pair at the requested multiplier and timespan (minute, hour, day, week, month) between `from` and `to`. Pass the pair in the path as BASE-QUOTE, e.g. BTC-USD or ETH-USD. Aggregated centralized-market spot — for Hyperliquid-listed token spot use /api/v1/spot, for perps use /api/v1/perps. From x402stock, a market & economic data API (x402, USDC).
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/crypto/%7Bpair%7D/open-close
The official UTC open and close price for a crypto spot pair on a given date. Pass the pair in the path as BASE-QUOTE, e.g. BTC-USD, and the date via `?date=YYYY-MM-DD` (required). Crypto trades 24/7, so this is the UTC-day open/close. From x402stock, a pay-per-call market & economic data API for AI agents. No API key or account; pay in USDC via x402.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/crypto/%7Bpair%7D/prev-close
Crypto trades 24/7, so there is no session close: this returns the previous UTC calendar day's full OHLCV candle (00:00–24:00 UTC) for a spot pair — open, high, low, close, volume, and VWAP. Pass the pair in the path as BASE-QUOTE, e.g. BTC-USD. One call returns yesterday's daily bar. From x402stock, a pay-per-call market & economic data API. Pay per request in USDC via x402, no API key.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/dividend-calendar
Market-wide dividend calendar (no ticker needed). Per row: ticker, ex-dividend / record / pay / declaration dates, cash amount per share, currency, type, payments-per-year `frequency` + `frequency_label` (quarterly, monthly, weekly, one-time), and computed `annualized_amount`. Upcoming payments first. Filter `?from=`/`?to=` on ex-date, `?ticker=`, `?frequency=`, `?order=`, `?limit=`.
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 6, 06:20 PM UTC
tempochargechallenge20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0x47b2ec06cad49c0722312be93d46147ddb8c568e
Chain
4217
Unit type
not observed
Session · externalId
apay_lpWLd5J2WBi22HXb7IPXZ
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi20000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/dividends/%7Bticker%7D
Historical cash dividends for a ticker: amount, currency, type, frequency, and the declaration / ex-dividend / record / pay dates. Most recent first. From x402stock, a pay-per-call market & economic data API for AI agents. No API key or account; pay in USDC via x402.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi10000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://agents.x402stock.xyz/api/v1/dossier/%7Bticker%7D
A company's recent SEC disclosure picture in one call: the filings index, insider transactions from Form 4 with a net buy/sell signal, material 8-K events by item code, and initial holdings from Form 3. The CIK is resolved once and shared across sections (faster than four separate calls), at a lower combined price. From SEC EDGAR; sections degrade independently. From x402stock
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargeopenapi50000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

435 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 9, 2026, 12:43 PM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 12:33 PM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 9, 2026, 6:35 AM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 6:26 AM UTC

GET https://agents.x402stock.xyz/api/v1/ipos

HTTP 402

4,912 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 9, 2026, 12:48 AM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 9, 2026, 12:38 AM UTC

GET https://agents.x402stock.xyz/api/v1/frames

HTTP 402

4,668 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:36 AM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 8, 2026, 6:45 PM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 6:34 PM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 8, 2026, 12:42 PM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 12:32 PM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 8, 2026, 6:40 AM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 6:31 AM UTC

GET https://agents.x402stock.xyz/api/v1/calendar

HTTP 402

4,836 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:22 AM UTC

GET https://agents.x402stock.xyz/api/v1/ticker-types

HTTP 402

4,576 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/api/v1/spot

HTTP 402

4,671 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 8, 2026, 12:42 AM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 8, 2026, 12:33 AM UTC

GET https://agents.x402stock.xyz/api/v1/market-pulse

HTTP 402

4,770 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:23 AM UTC

GET https://agents.x402stock.xyz/api/v1/fear-greed/crypto

HTTP 402

4,772 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:20 AM UTC

GET https://agents.x402stock.xyz/api/v1/fed-funds

HTTP 402

4,681 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 12:19 AM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 7, 2026, 6:42 PM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 6:32 PM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 7, 2026, 12:40 PM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 12:30 PM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 7, 2026, 6:46 AM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 6:37 AM UTC

GET https://agents.x402stock.xyz/api/v1/conditions

HTTP 402

4,656 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:27 AM UTC

GET https://agents.x402stock.xyz/api/v1/portfolio/xray

HTTP 402

4,729 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:24 AM UTC

GET https://agents.x402stock.xyz/api/v1/exchanges

HTTP 402

4,555 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:24 AM UTC

GET https://agents.x402stock.xyz/api/v1/splits-calendar

HTTP 402

5,039 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:24 AM UTC

GET https://agents.x402stock.xyz/api/v1/pce

HTTP 402

4,683 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:23 AM UTC

GET https://agents.x402stock.xyz/api/v1/treasury-yields

HTTP 402

4,820 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:23 AM UTC

GET https://agents.x402stock.xyz/api/v1/money-supply

HTTP 402

4,715 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:22 AM UTC

GET https://agents.x402stock.xyz/api/v1/inflation

HTTP 402

4,679 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:22 AM UTC

GET https://agents.x402stock.xyz/api/v1/trending/4chan

HTTP 402

4,765 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/api/v1/macro

HTTP 402

4,686 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/api/v1/private-stocks

HTTP 402

4,712 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/api/v1/prediction-markets

HTTP 402

4,745 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:21 AM UTC

GET https://agents.x402stock.xyz/api/v1/calendar/fomc

HTTP 402

4,682 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 AM UTC

GET https://agents.x402stock.xyz/api/v1/xstocks

HTTP 402

4,702 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 6:20 AM UTC

GET https://agents.x402stock.xyz/openapi.json

scanner stopped: response-too-large

Response exceeds 1048576 bytes

Oct 7, 2026, 12:51 AM UTC

GET https://agents.x402stock.xyz/

scanner stopped: response-too-large

Response exceeds 262144 bytes

Oct 7, 2026, 12:41 AM UTC

GET https://agents.x402stock.xyz/api/v1/national-debt

HTTP 402

4,792 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:30 AM UTC

GET https://agents.x402stock.xyz/api/v1/regulatory

HTTP 402

4,985 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:28 AM UTC

GET https://agents.x402stock.xyz/api/v1/perps/predicted-funding

HTTP 402

4,727 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:27 AM UTC

GET https://agents.x402stock.xyz/api/v1/hip3/dexs

HTTP 402

4,704 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:26 AM UTC

GET https://agents.x402stock.xyz/api/v1/gdp

HTTP 402

4,654 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:24 AM UTC

GET https://agents.x402stock.xyz/api/v1/fear-greed

HTTP 402

4,710 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 7, 2026, 12:24 AM UTC
Showing the latest 50 of 435 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

probe_safety

Observed

response-too-large: Response exceeds 1048576 bytes

Basis: scanner policy decision · Oct 9, 2026, 12:43 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 AM UTC

bounded_response

Tested — pass

4912 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:36 AM UTC

bounded_response

Tested — pass

4668 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:36 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:36 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:36 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:36 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:36 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:36 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:36 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:36 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:22 AM UTC

bounded_response

Tested — pass

4836 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 6:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:21 AM UTC

bounded_response

Tested — pass

4576 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 6:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:21 AM UTC

bounded_response

Tested — pass

4671 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 6:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 6:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 6:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 AM UTC

bounded_response

Tested — pass

4770 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:23 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:20 AM UTC

bounded_response

Tested — pass

4772 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:20 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:20 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:20 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:20 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:20 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:20 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:20 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:20 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:19 AM UTC

bounded_response

Tested — pass

4681 bytes within scanner limit

Basis: harmless scanner · Oct 8, 2026, 12:19 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 8, 2026, 12:19 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 8, 2026, 12:19 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 8, 2026, 12:19 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 8, 2026, 12:19 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:19 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:27 AM UTC

bounded_response

Tested — pass

4656 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:27 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:27 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:27 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:27 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:27 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:27 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:27 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:27 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 AM UTC

bounded_response

Tested — pass

4729 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:24 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:24 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 AM UTC

bounded_response

Tested — pass

4555 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:24 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:24 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 AM UTC

bounded_response

Tested — pass

5039 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:24 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:24 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:23 AM UTC

bounded_response

Tested — pass

4683 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:23 AM UTC

bounded_response

Tested — pass

4820 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:22 AM UTC

bounded_response

Tested — pass

4715 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:22 AM UTC

bounded_response

Tested — pass

4679 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:21 AM UTC

bounded_response

Tested — pass

4765 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:21 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:21 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 7, 2026, 6:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:21 AM UTC

bounded_response

Tested — pass

4686 bytes within scanner limit

Basis: harmless scanner · Oct 7, 2026, 6:21 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 7, 2026, 6:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:21 AM UTC

economic_exposure_metadata

Unknown

[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 7, 2026, 6:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 7, 2026, 6:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC
Showing a bounded 250 of 899 security-property records.

History

Service changes

Showing the latest 50 of 1,515 changes. Continue in the changes API view.

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-updated

session_json: {"externalId":"apay_pmWXjhpNq9PgFhcUhfQrw"} → {"externalId":"apay_gaBGtCiJJQEClQaquzzUY"}

Evidence: challenge payment metadata

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-updated

session_json: {"externalId":"apay_cxt01ixfwUtib3KkRVJK2"} → {"externalId":"apay_k8AaT67lLXQIeEc2aEOD3"}

Evidence: challenge payment metadata

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-updated

session_json: {"externalId":"apay_wOCjsenfTAzNXifh1Usop"} → {"externalId":"apay_vFfNlDjilSQIvn9wUczlV"}

Evidence: challenge payment metadata

— payment-offer-updated

session_json: {"externalId":"apay_dyNykdSJoyDWfZLD_i4BV"} → {"externalId":"apay_ki053F9LZB6wp87A9URPy"}

Evidence: challenge payment metadata

— payment-offer-updated

session_json: {"externalId":"apay_H_Er_tHVF3gPjKX8JUuWg"} → {"externalId":"apay_-5NG0lJZDImjSIhrL2y6-"}

Evidence: challenge payment metadata

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-updated

session_json: {"externalId":"apay_2ok2Fwc9JIpIGPx4YMpDq"} → {"externalId":"apay_qZs3s59UsnSSY8feovP-9"}

Evidence: challenge payment metadata

— payment-offer-updated

session_json: {"externalId":"apay_zl2NpaHKIgeeb_1qMsI8K"} → {"externalId":"apay_hx1-hT5AGMz9Vz5IBESjj"}

Evidence: challenge payment metadata

— payment-offer-updated

session_json: {"externalId":"apay_V2kUCPZDmnE6j0DqX9a6A"} → {"externalId":"apay_q8kre-hWSLpCIJYtLNRMh"}

Evidence: challenge payment metadata

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}

Evidence: Repeated harmless observation changed the modeled property