Service record

ForgeMesh Crypto Signals API

https://crypto.forgemesh.io/
observed-mpp

Paid crypto market-intelligence API for autonomous agents: crypto signals, whale/CEX/bridge flow alerts, calibrated price ranges, risk state, preflight checks, decision journals, and outcome audits via x402.

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 26, 2026, 12:17 PM UTC
Last seen
Oct 9, 2026, 6:22 PM UTC
Origin
https://crypto.forgemesh.io
Tags
None advertised

Payment surface

14 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
POST
https://crypto.forgemesh.io/api/feedback
Send paid feedback or suggestions
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
evmchargeopenapi5000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/audit
Audit market-intelligence outcome against real prices
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 06:18 AM UTC
evmchargechallenge70000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns a verdict, realized pnl_pct, and direction_correct flag for any prior decision_id — the accountability check that closes the loop on
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi70000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/decision
Market-intelligence decision journal with anomaly, calibration, verification, disclaimers, and decision_id
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 1, 12:24 AM UTC
evmchargechallenge150000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns a full decision journal entry — directional_bias, calibrated_confidence, anomaly_score, and agreement_score — plus a decision_id, co
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi150000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/forecast
Conformally-calibrated price forecast with an honest 80% range
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 06:20 PM UTC
evmchargechallenge50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns a conformally-calibrated range_80 price interval (~80% empirical coverage) plus current_price and upside_probability for BTC, ETH, S
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/futures/decision
Perpetual-futures decision package: direction, stop/target on the calibrated range, leverage cap, liquidation, sizing, funding
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:24 PM UTC
evmchargechallenge150000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns a perpetual-futures decision package for BTC, ETH, SOL, XRP, or ADA: direction LONG / SHORT / FLAT from the Kronos signal, stop-loss
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi150000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/futures/funding
Live perp funding, mark/index, open interest, and crowding across Kraken Futures and Hyperliquid
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:23 PM UTC
evmchargechallenge20000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns live perpetual-futures funding rates, mark and index price, open interest, and 24h volume for BTC, ETH, SOL, XRP, and ADA from Krake
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi20000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/futures/risk
Will this leveraged perp position survive the calibrated range?
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:23 PM UTC
evmchargechallenge50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Answers 'will this leveraged perp position survive the calibrated range?' for a side, entry, and leverage you specify: liquidation price and
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/history
Recent Kronos context history
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 06:21 PM UTC
evmchargechallenge50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns up to 168 hours of historical signal snapshots with timestamps and per-symbol scores — use it to backtest, chart signal drift, or bu
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/preflight
Market-state preflight check
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 06:21 PM UTC
evmchargechallenge50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns a go/no-go allowed flag with market_state, cooldown status, and warnings for one symbol — call it before /kronos/decision to skip a
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/risk
Current market risk state
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 06:20 PM UTC
evmchargechallenge20000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns current market risk state, per-symbol signal streaks, and active cooldown timers — use it as a pre-trade risk gate before acting on
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi20000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/kronos/signals
Latest Kronos market context
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 06:20 PM UTC
evmchargechallenge50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns latest per-symbol signal scores and a ranked top_k list across crypto and supported stock symbols — pair with /kronos/risk and /kron
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/signals
Current crypto market-intelligence signals
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:26 PM UTC
evmchargechallenge50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns current signal scores for BTC, ETH, SOL, XRP, and ADA plus a ranked top_k list, regime, and data freshness — use it as a lightweight
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/api/whale
Whale, CEX, bridge, and stablecoin flow alerts
Status: 402TLS: tested-passRedirects: 0Challenge: mpp-payment-authLast probe: Oct 9, 12:23 PM UTC
evmchargechallenge20000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
Chain
8453
Unit type
not observed
Session · description
Returns whale, CEX, bridge, and stablecoin flow alerts for a chosen chain and lookback window, each with direction, venue, and USD value — u
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
evmchargeopenapi20000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://crypto.forgemesh.io/signal/%7Bsymbol%7D
Single-symbol crypto signal lookup
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
evmchargeopenapi50000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

53 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://crypto.forgemesh.io/.well-known/api-catalog

HTTP 404

162 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:22 PM UTC

GET https://crypto.forgemesh.io/api/kronos/preflight

HTTP 402

1,178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/history

HTTP 402

1,256 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/

HTTP 200

35,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/kronos/forecast

HTTP 402

1,355 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/kronos/risk

HTTP 402

1,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/kronos/signals

HTTP 402

1,261 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/signals

HTTP 402

1,543 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:26 PM UTC

GET https://crypto.forgemesh.io/api/kronos/futures/decision

HTTP 402

1,806 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:24 PM UTC

GET https://crypto.forgemesh.io/api/whale

HTTP 402

1,330 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/futures/funding

HTTP 402

1,549 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/futures/risk

HTTP 402

1,525 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/openapi.json

HTTP 200

34,187 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:18 AM UTC

GET https://crypto.forgemesh.io/api/kronos/audit

HTTP 402

1,373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:18 AM UTC

GET https://crypto.forgemesh.io/api/kronos/decision

HTTP 402

1,630 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:24 AM UTC

GET https://crypto.forgemesh.io/.well-known/api-catalog

HTTP 404

162 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:22 PM UTC

GET https://crypto.forgemesh.io/api/kronos/preflight

HTTP 402

1,178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/history

HTTP 402

1,256 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/forecast

HTTP 402

1,355 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/

HTTP 200

35,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/risk

HTTP 402

1,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/signals

HTTP 402

1,261 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/whale

HTTP 402

1,330 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/signals

HTTP 402

1,544 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:20 PM UTC

GET https://crypto.forgemesh.io/api/kronos/futures/decision

HTTP 402

1,806 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:24 PM UTC

GET https://crypto.forgemesh.io/api/kronos/futures/funding

HTTP 402

1,549 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/futures/risk

HTTP 402

1,525 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:22 PM UTC

GET https://crypto.forgemesh.io/openapi.json

HTTP 200

34,187 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:18 PM UTC

GET https://crypto.forgemesh.io/api/kronos/audit

HTTP 402

1,373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:18 PM UTC

GET https://crypto.forgemesh.io/api/kronos/decision

HTTP 402

1,626 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/preflight

HTTP 402

1,178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:24 PM UTC

GET https://crypto.forgemesh.io/.well-known/api-catalog

HTTP 404

162 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:24 PM UTC

GET https://crypto.forgemesh.io/api/kronos/history

HTTP 402

1,256 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/forecast

HTTP 402

1,355 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/risk

HTTP 402

1,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/

HTTP 200

34,069 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/api/kronos/signals

HTTP 402

1,259 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:22 PM UTC

GET https://crypto.forgemesh.io/api/whale

HTTP 402

1,330 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:22 PM UTC

GET https://crypto.forgemesh.io/api/signals

HTTP 402

1,542 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 12:22 PM UTC

GET https://crypto.forgemesh.io/openapi.json

HTTP 200

25,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:22 AM UTC

GET https://crypto.forgemesh.io/api/kronos/audit

HTTP 402

1,373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:20 AM UTC

GET https://crypto.forgemesh.io/api/kronos/decision

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:25 PM UTC

GET https://crypto.forgemesh.io/api/kronos/preflight

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:23 PM UTC

GET https://crypto.forgemesh.io/.well-known/api-catalog

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:22 PM UTC

GET https://crypto.forgemesh.io/api/kronos/history

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:22 PM UTC

GET https://crypto.forgemesh.io/api/kronos/forecast

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/risk

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:21 PM UTC

GET https://crypto.forgemesh.io/

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:21 PM UTC

GET https://crypto.forgemesh.io/api/kronos/signals

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:21 PM UTC

GET https://crypto.forgemesh.io/api/whale

HTTP 530

17 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 12:20 PM UTC
Showing the latest 50 of 53 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Oct 9, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTC

bounded_response

Tested — pass

162 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

1178 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

1256 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTC

bounded_response

Tested — pass

35038 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTC

bounded_response

Tested — pass

1355 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTC

bounded_response

Tested — pass

1413 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTC

bounded_response

Tested — pass

1261 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTC

bounded_response

Tested — pass

1543 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:24 PM UTC

bounded_response

Tested — pass

1806 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

1330 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

1549 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

1525 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

openapi_parse

Tested — pass

14 payment offer(s) accepted

Basis: harmless discovery response · Oct 9, 2026, 6:18 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:18 AM UTC

bounded_response

Tested — pass

1373 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:18 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 9, 2026, 6:18 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:18 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:18 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:24 AM UTC

bounded_response

Tested — pass

1630 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 12:24 AM UTC

challenge_parse

Tested — pass

1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated

Basis: unauthenticated HTTP response · Oct 1, 2026, 12:24 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:24 AM UTC

economic_exposure_metadata

Unknown

[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]

Basis: observable challenge values only · Oct 1, 2026, 12:24 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 12:24 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 12:24 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:24 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:24 AM UTC

History

Service changes

Showing the latest 50 of 315 changes. Continue in the changes API view.

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"34187 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"162 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1544 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1543 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"162 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"34187 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1626 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1630 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"34187 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"162 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"34069 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"35038 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1259 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1261 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"1542 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1544 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-discovered

offer → {"method":"evm","intent":"charge","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chainId":"8453","recipient":…

Evidence: challenge payment metadata

— probe-observation

content_type → application/json; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation

— endpoint-source-discovered

source:challenge → active

Evidence: https://crypto.forgemesh.io/api/kronos/futures/decision

— probe-observation

challenge_format → mpp-payment-auth

Evidence: harmless unauthenticated HTTP observation

— probe-observation

last_status → 402

Evidence: harmless unauthenticated HTTP observation

— probe-observation

redirect_count → 0

Evidence: harmless unauthenticated HTTP observation

— probe-observation

redirect_count → 0

Evidence: harmless unauthenticated HTTP observation

— probe-observation

content_type → application/json; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— payment-offer-discovered

offer → {"method":"evm","intent":"charge","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chainId":"8453","recipient":…

Evidence: challenge payment metadata

— probe-observation

last_status → 402

Evidence: harmless unauthenticated HTTP observation

— endpoint-source-discovered

source:challenge → active

Evidence: https://crypto.forgemesh.io/api/kronos/futures/funding

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation

— probe-observation

challenge_format → mpp-payment-auth

Evidence: harmless unauthenticated HTTP observation

— probe-observation

tls_state: not-tested → tested-pass

Evidence: harmless unauthenticated HTTP observation

— probe-observation

redirect_count → 0

Evidence: harmless unauthenticated HTTP observation

— payment-offer-discovered

offer → {"method":"evm","intent":"charge","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chainId":"8453","recipient":…

Evidence: challenge payment metadata