{"uid":"cap_WjoveSRwAeC52K__hQ0JT","slug":"andromalius-audit-discovery-274b3915","name":"Andromalius Audit Discovery","description":"Preview free synthetic x402 security reports, then buy machine-readable challenge and discovery audits from $0.01 in Base USDC.","url":"https://api.andromalius.io/v1/audit/discovery","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"openapi":{"type":"object","description":"OpenAPI 3.0 or 3.1 JSON document to audit","additionalProperties":true}}},"responseSchema":{"type":"json","example":{"kind":"discovery-audit","score":100,"passed":true,"seller":{"brand":"Andromalius","contacts":{"legal":"legal@andromalius.io","privacy":"privacy@andromalius.io","support":"support@andromalius.io","security":"security@andromalius.io"},"policies":{"terms":"https://andromalius.io/terms","privacy":"https://andromalius.io/privacy","refunds":"https://andromalius.io/refunds","acceptableUse":"https://andromalius.io/acceptable-use"},"legalForm":"New York sole proprietor","legalName":"Richard Kowalczyk","eligibility":"United States business users age 18 or older","jurisdiction":"New York, United States"},"summary":"No findings","version":1,"findings":[],"observations":{},"scorePolicyVersion":"1.0.0","findingCodeRegistryVersion":"1.0.0"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_K3JuJzwNj-PZoByDVNqHw","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits an OpenAPI 3.0/3.1 document for x402 payment compliance and security best practices, returning a scored findings report","exampleAgentPrompt":"Can you audit my OpenAPI spec for x402 payment compliance and tell me if there are any security findings or policy issues?","exampleUseCases":[{"title":"Pre-launch x402 API compliance check","prompt":"Before I go live, can you run my OpenAPI 3.1 spec through the Andromalius audit and tell me my compliance score and any findings I need to fix?"},{"title":"CI pipeline security gate for payment API","prompt":"I want to make sure every version of my payment API spec scores 100 on the x402 audit before merging — can you check this OpenAPI document and flag any issues?"},{"title":"Third-party API vendor vetting","prompt":"We're considering integrating this vendor's x402-enabled API — can you audit their OpenAPI spec and tell me if it passes security and policy checks?"}],"resultDescription":"Returns a JSON object with a numeric compliance score (0-100), a boolean passed flag, a plain-text summary, a version field, an array of findings (each describing a specific issue), and an observations map. A clean audit returns score 100, passed: true, and an empty findings array.","failureModes":["Invalid or malformed OpenAPI document returns a validation error","Missing required 'openapi' field in request body results in a 400-level error","Non-x402-aware specs may return low scores with many findings rather than a hard error","Network or service unavailability returns a 5xx error","Payment failure (insufficient USDC balance) blocks the request before processing"],"whenToPreferThis":"Choose this endpoint when you need an automated, independently scored security and compliance audit of an OpenAPI specification specifically for x402 payment infrastructure. It is ideal for CI/CD pipeline integration, pre-launch API validation, or vetting third-party x402-enabled APIs. Prefer it over generic linting tools when x402 policy controls, settlement evidence, and payment security semantics are the primary concern.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T22:27:25.328Z","isFirstParty":false}