- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Market and economic data for AI agents — US stocks, ETFs and options, forex, crypto and on-chain perps, energy commodities (crude, natural gas, gasoline), US and global macro (Fed funds, CPI/PCE, jobs, GDP, Treasury debt & yields, World Bank indicators), SEC filings, congressional trades, and market sentiment. No API keys, no accounts. Pay per request in USDC via x402 or MPP. This server is a pay-per-use, transparent proxy in front of x402stock's own API: it handles identity, payment, and proxying. Agents can purchase autonomously or with their human's approval. This document is the source of truth for agents: it lists the complete verified paid surface with each operation's live price in its x-payment-info. Endpoints not listed here are not part of the supported catalog. The live catalog at /manifest.json is authoritative for prices and any free included units (prices[].includedUnits) - some meters include free usage per account before any charge, reserved for agents claimed by a human with a verified email.
- Implementation fingerprint
- custom 35% confidence
- Fingerprint evidence
- valid 402 Payment challenge observed without implementation-specific marker
- First seen
- Aug 25, 2026, 6:43 PM UTC
- Last seen
- Oct 9, 2026, 12:43 PM UTC
- Origin
- https://agents.x402stock.xyz
- Tags
- None advertised
Payment surface
140 MPP endpoints
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_nxS8FmiliWUE0gTaoYp3U
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_Qxm3T_LSMyhJjzcurD-jP
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_mbjWhnh4n7-uAweL922LC
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_vFfNlDjilSQIvn9wUczlV
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay__8BWS5is5ZUR-qz4jrJja
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_TfRPDKUbsVesBzthRFLCP
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_hbiHDoNfunkWgsMvjG84T
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_KfAsnDuXKCR4OeI82Tjp_
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay__EV9WoSTr0FI1Gop_qwyF
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_OsxqFpS3r5zrTkGamsTiY
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x47b2ec06cad49c0722312be93d46147ddb8c568e
- Chain
- 4217
- Unit type
- not observed
- Session · externalId
- apay_lpWLd5J2WBi22HXb7IPXZ
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Probe coverage
435 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 9, 2026, 12:43 PM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 9, 2026, 12:33 PM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 9, 2026, 6:35 AM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 9, 2026, 6:26 AM UTCGET https://agents.x402stock.xyz/api/v1/ipos
HTTP 4024,912 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 9, 2026, 12:48 AM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 9, 2026, 12:38 AM UTCGET https://agents.x402stock.xyz/api/v1/frames
HTTP 4024,668 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:36 AM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 8, 2026, 6:45 PM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 8, 2026, 6:34 PM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 8, 2026, 12:42 PM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 8, 2026, 12:32 PM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 8, 2026, 6:40 AM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 8, 2026, 6:31 AM UTCGET https://agents.x402stock.xyz/api/v1/calendar
HTTP 4024,836 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:22 AM UTCGET https://agents.x402stock.xyz/api/v1/ticker-types
HTTP 4024,576 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/api/v1/spot
HTTP 4024,671 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 8, 2026, 12:42 AM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 8, 2026, 12:33 AM UTCGET https://agents.x402stock.xyz/api/v1/market-pulse
HTTP 4024,770 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:23 AM UTCGET https://agents.x402stock.xyz/api/v1/fear-greed/crypto
HTTP 4024,772 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:20 AM UTCGET https://agents.x402stock.xyz/api/v1/fed-funds
HTTP 4024,681 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:19 AM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 7, 2026, 6:42 PM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 7, 2026, 6:32 PM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 7, 2026, 12:40 PM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 7, 2026, 12:30 PM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 7, 2026, 6:46 AM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 7, 2026, 6:37 AM UTCGET https://agents.x402stock.xyz/api/v1/conditions
HTTP 4024,656 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:27 AM UTCGET https://agents.x402stock.xyz/api/v1/portfolio/xray
HTTP 4024,729 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:24 AM UTCGET https://agents.x402stock.xyz/api/v1/exchanges
HTTP 4024,555 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:24 AM UTCGET https://agents.x402stock.xyz/api/v1/splits-calendar
HTTP 4025,039 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:24 AM UTCGET https://agents.x402stock.xyz/api/v1/pce
HTTP 4024,683 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:23 AM UTCGET https://agents.x402stock.xyz/api/v1/treasury-yields
HTTP 4024,820 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:23 AM UTCGET https://agents.x402stock.xyz/api/v1/money-supply
HTTP 4024,715 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:22 AM UTCGET https://agents.x402stock.xyz/api/v1/inflation
HTTP 4024,679 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:22 AM UTCGET https://agents.x402stock.xyz/api/v1/trending/4chan
HTTP 4024,765 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/api/v1/macro
HTTP 4024,686 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/api/v1/private-stocks
HTTP 4024,712 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/api/v1/prediction-markets
HTTP 4024,745 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:21 AM UTCGET https://agents.x402stock.xyz/api/v1/calendar/fomc
HTTP 4024,682 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:20 AM UTCGET https://agents.x402stock.xyz/api/v1/xstocks
HTTP 4024,702 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:20 AM UTCGET https://agents.x402stock.xyz/openapi.json
scanner stopped: response-too-largeResponse exceeds 1048576 bytes
Oct 7, 2026, 12:51 AM UTCGET https://agents.x402stock.xyz/
scanner stopped: response-too-largeResponse exceeds 262144 bytes
Oct 7, 2026, 12:41 AM UTCGET https://agents.x402stock.xyz/api/v1/national-debt
HTTP 4024,792 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:30 AM UTCGET https://agents.x402stock.xyz/api/v1/regulatory
HTTP 4024,985 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:28 AM UTCGET https://agents.x402stock.xyz/api/v1/perps/predicted-funding
HTTP 4024,727 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:27 AM UTCGET https://agents.x402stock.xyz/api/v1/hip3/dexs
HTTP 4024,704 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:26 AM UTCGET https://agents.x402stock.xyz/api/v1/gdp
HTTP 4024,654 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:24 AM UTCGET https://agents.x402stock.xyz/api/v1/fear-greed
HTTP 4024,710 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:24 AM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
probe_safety
Observedresponse-too-large: Response exceeds 1048576 bytes
Basis: scanner policy decision · Oct 9, 2026, 12:43 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 AM UTCbounded_response
Tested — pass4912 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:36 AM UTCbounded_response
Tested — pass4668 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:36 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:36 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:36 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:36 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:36 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:36 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:36 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:36 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:36 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:22 AM UTCbounded_response
Tested — pass4836 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:22 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 6:22 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:22 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:22 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 6:22 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:22 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:22 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:21 AM UTCbounded_response
Tested — pass4576 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 6:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:21 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:21 AM UTCbounded_response
Tested — pass4671 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 6:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:21 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 6:21 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:21 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:21 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 AM UTCbounded_response
Tested — pass4770 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:23 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:23 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:23 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:23 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:23 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:20 AM UTCbounded_response
Tested — pass4772 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:20 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:20 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:20 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:20 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:20 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:20 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:20 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:20 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:20 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:19 AM UTCbounded_response
Tested — pass4681 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:19 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:19 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:19 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:19 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:19 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:19 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:19 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:27 AM UTCbounded_response
Tested — pass4656 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:27 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:27 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:27 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:27 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:27 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:27 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:27 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:27 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:27 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 AM UTCbounded_response
Tested — pass4729 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:24 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:24 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 AM UTCbounded_response
Tested — pass4555 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:24 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:24 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:24 AM UTCbounded_response
Tested — pass5039 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:24 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:24 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:24 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:24 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:24 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:24 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:24 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:23 AM UTCbounded_response
Tested — pass4683 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:23 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:23 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:23 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:23 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:23 AM UTCbounded_response
Tested — pass4820 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:23 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:23 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:23 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:23 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:23 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:23 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:23 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:22 AM UTCbounded_response
Tested — pass4715 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:22 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:22 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:22 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:22 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:22 AM UTCbounded_response
Tested — pass4679 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:22 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:22 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:22 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:22 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:22 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:22 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:22 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:21 AM UTCbounded_response
Tested — pass4765 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:21 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:21 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:21 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:21 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:21 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:21 AM UTCbounded_response
Tested — pass4686 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:21 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:21 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 7, 2026, 6:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:21 AM UTC— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-updated
session_json: {"externalId":"apay_pmWXjhpNq9PgFhcUhfQrw"} → {"externalId":"apay_gaBGtCiJJQEClQaquzzUY"}
Evidence: challenge payment metadata
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-updated
session_json: {"externalId":"apay_cxt01ixfwUtib3KkRVJK2"} → {"externalId":"apay_k8AaT67lLXQIeEc2aEOD3"}
Evidence: challenge payment metadata
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-updated
session_json: {"externalId":"apay_wOCjsenfTAzNXifh1Usop"} → {"externalId":"apay_vFfNlDjilSQIvn9wUczlV"}
Evidence: challenge payment metadata
— payment-offer-updated
session_json: {"externalId":"apay_dyNykdSJoyDWfZLD_i4BV"} → {"externalId":"apay_ki053F9LZB6wp87A9URPy"}
Evidence: challenge payment metadata
— payment-offer-updated
session_json: {"externalId":"apay_H_Er_tHVF3gPjKX8JUuWg"} → {"externalId":"apay_-5NG0lJZDImjSIhrL2y6-"}
Evidence: challenge payment metadata
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-updated
session_json: {"externalId":"apay_2ok2Fwc9JIpIGPx4YMpDq"} → {"externalId":"apay_qZs3s59UsnSSY8feovP-9"}
Evidence: challenge payment metadata
— payment-offer-updated
session_json: {"externalId":"apay_zl2NpaHKIgeeb_1qMsI8K"} → {"externalId":"apay_hx1-hT5AGMz9Vz5IBESjj"}
Evidence: challenge payment metadata
— payment-offer-updated
session_json: {"externalId":"apay_V2kUCPZDmnE6j0DqX9a6A"} → {"externalId":"apay_q8kre-hWSLpCIJYtLNRMh"}
Evidence: challenge payment metadata
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"response-too-large: Response exceeds 262144 bytes","basis":"scanner policy decision"} → {"state":"observed","evidence":"response-too-large: Response exceeds 1048576 bytes","basis":"scanner policy decision"}
Evidence: Repeated harmless observation changed the modeled property