{"uid":"cap_c9_OdWJOZqnAMY02C2r6S","slug":"sitesignal-vendor-due-diligence-5d5cdeac","name":"SiteSignal Vendor Due Diligence","description":"Create a bounded public-website, HTTP, TLS, and response-header evidence pack for human vendor due diligence.","url":"https://trinity-throw-thursday-gravity.trycloudflare.com/x402/vendor-due-diligence","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url","decisionContext"],"properties":{"url":{"type":"string","format":"uri"},"riskFocus":{"type":"string"},"decisionContext":{"type":"string"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.08","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.08/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.08","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.08","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_3Q_7U_YyOSFOxpiBN9WpX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.08","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Collects a bounded evidence pack of public-website, HTTP, TLS, and response-header signals for a vendor URL to support human due diligence decisions.","exampleAgentPrompt":"Can you pull a public due diligence evidence pack for https://acme-vendor.com? We're evaluating them as a payments processor, so focus on TLS certificate quality and security headers.","exampleUseCases":[{"title":"Procurement vendor security check","prompt":"We're about to onboard Stripe as a payment vendor — can you collect a public evidence pack for https://stripe.com focusing on TLS and response header security so we have something for the procurement file?"},{"title":"SaaS tool compliance review","prompt":"Before I approve this new SaaS tool for our team, can you pull the public HTTP, TLS, and header evidence for https://notion.so? Context is an internal compliance review for data handling risk."},{"title":"Supplier onboarding risk assessment","prompt":"We have a new logistics supplier at https://example-logistics.co — can you gather observable security signals from their public website? We're trying to assess third-party risk before signing the contract."}],"resultDescription":"Returns a structured evidence pack including TLS certificate metadata (issuer, expiry, chain), observed HTTP response headers (HSTS, CSP, X-Frame-Options, etc.), security header grades, and other observable public signals for the target vendor URL — formatted to support human review in a due diligence process.","failureModes":["Invalid or unreachable URL returns an error indicating the target could not be fetched","Private or intranet URLs not accessible from the public internet will fail","Missing required 'url' or 'decisionContext' query parameters returns a validation error","Cloudflare Tunnel downtime may cause intermittent 5xx errors","Vendor sites with aggressive bot blocking may return incomplete or blocked responses"],"whenToPreferThis":"Choose this endpoint when you need a quick, bounded public evidence pack for vendor due diligence that covers TLS, HTTP, and security-header signals in a single call — especially when you have a specific decision context (e.g. procurement, compliance review, contract signing) and want structured, human-reviewable output. Prefer this over raw TLS or header checkers when you need a holistic, decision-focused artifact rather than a single-signal inspection.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:38:28.033Z","isFirstParty":false}