{"uid":"cap_DuP2Tmkh-TPqb7Jx25agu","slug":"taskmaster-url-readiness-audit-3c0d35d8","name":"TaskMaster URL Readiness Audit","description":"Deterministic HTML QA and bounded x402 API security, Bazaar discovery, and OpenAPI readiness audits that never settle the inspected endpoint's payment challenge.","url":"https://taskmaster-x402.vercel.app/api/url-readiness","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"Public HTTPS x402 resource URL. Private and reserved network targets are rejected."},"method":{"enum":["GET","POST"],"type":"string","description":"Unpaid probe method. POST sends an empty JSON object and never settles a 402 challenge."}}},"responseSchema":{"type":"json","example":{"safety":"The audit observes public metadata and never signs or settles payment.","target":{"method":"POST","status":402},"summary":{"score":100,"x402Ready":true,"challengeObserved":true},"security":{"hsts":true,"contentTypeOptions":true},"discovery":{"openApi":{"present":true,"paidOperationsInvocable":true},"x402Manifest":{"present":true},"agentManifest":{"present":true}},"schemaVersion":"1.0","recommendations":[]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_TSOUEwcnumbrfyQVf3RPc","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a public HTTPS endpoint for x402 payment-protocol readiness, API security headers, Bazaar/manifest discovery signals, and OpenAPI compliance without ever settling a payment challenge.","exampleAgentPrompt":"Can you run an x402 readiness audit on https://myapi.example.com/resource using a GET probe — I want to know if it returns a proper 402 challenge, has the right security headers, and shows up in Bazaar discovery?","exampleUseCases":[{"title":"Pre-launch x402 compliance check","prompt":"Before I list my new payments API on x402scan, can you audit https://payments.myservice.com/checkout with a GET probe and tell me if it's fully x402 ready — proper 402 challenge, HSTS, and OpenAPI manifest all present?"},{"title":"Debugging a missing Bazaar listing","prompt":"My API isn't showing up in Bazaar discovery — can you probe https://api.myproject.io/data with POST and check whether the x402 manifest and agent manifest are actually detectable?"},{"title":"Security header validation for an agent API","prompt":"Can you check whether https://agentapi.example.com/invoke has HSTS and content-type-options headers set correctly, and also confirm it's responding with a 402 challenge when probed with GET?"}],"resultDescription":"A JSON object containing: an overall readiness score (0–100), a boolean x402Ready flag, whether a 402 challenge was observed, HSTS and content-type-options security header booleans, OpenAPI/x402 manifest/agent manifest presence flags, schema version, and an array of actionable recommendations — all without ever settling the payment challenge on the inspected endpoint.","failureModes":["Private or reserved network URLs are rejected with an error","Non-HTTPS URLs are rejected","Target endpoint is unreachable or times out, resulting in incomplete audit data","Endpoint returns unexpected non-402 status codes, lowering readiness score","Missing manifests or security headers result in score below 100 with recommendations populated"],"whenToPreferThis":"Choose this endpoint when you need a safe, non-destructive audit of an x402-compliant API — especially before listing on x402scan or Bazaar, or when debugging why an endpoint isn't discoverable. It is preferable to manual inspection because it checks x402 challenge correctness, security headers, OpenAPI and agent manifest presence, and Bazaar discoverability in a single bounded call that never triggers a real payment.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:37:29.577Z","isFirstParty":false}