{"uid":"cap_jjjgkhzHBqCQ0O9AJadl0","slug":"orcpin-x402-door-audit-1f15c847","name":"Orcpin x402 Door Audit","description":"Signed four-part audit of one x402 endpoint, by buying from it: the quote (what the 402 asks, and whether the seller's manifest and public catalog agree), real purchases with Orcpin's audit wallet (quoted vs signed vs settled vs chain vs delivered; replay and bad-payment behaviour), the door's inbound books from the chain (settlements, revenue, distinct and repeat payers), and unit cost against priced doors listed. Ed25519-signed and logged; facts, no verdict. No purchase settled, no charge.","url":"https://orcpin.dev/v1/door-audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"The x402 endpoint to audit — a public http(s) URL that answers an unpaid request with a 402 challenge."},"body":{"type":"object","description":"JSON body to send to a POST door (the request an agent would actually make). Implies method POST."},"method":{"enum":["GET","POST"],"type":"string","description":"The door's verb. Default: GET, retried as POST if GET looks like the wrong verb."},"purchases":{"type":"integer","description":"Real purchases to make, 1–5. Default 3. Their total must fit the audit's purchase budget."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"50","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$50/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"50","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"50","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_TTA6y_j0Cwvzl5wptxBCY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"50","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a signed four-part audit of an x402 endpoint by actually purchasing from it, covering quote verification, real purchase behavior, on-chain settlement tracking, and cost benchmarking.","exampleAgentPrompt":"Run a full Orcpin door audit on https://api.example.com/premium-data using GET and make 3 real test purchases, so I can see whether the quote matches the manifest, how settlement lands on-chain, and how the price compares to similar x402 endpoints.","exampleUseCases":[{"title":"Pre-integration trust check for x402 API","prompt":"Before I build my agent on top of that x402 weather API at https://weather.example.com/forecast, run a door audit with 2 purchases so I can see if the quote matches their manifest, payments actually settle on-chain, and their price is competitive."},{"title":"Verifying replay attack resistance","prompt":"I want to know if the x402 door at https://data.example.com/records handles replay attacks and bad payments correctly — run a 5-purchase Orcpin audit using POST with body {\"query\":\"test\"} and give me the signed results."},{"title":"On-chain revenue and payer analysis","prompt":"Can you audit the x402 endpoint at https://api.example.com/signals with 3 purchases and pull the on-chain settlement records, including how many distinct payers have used it and what revenue it's collected?"}],"resultDescription":"A signed, four-part audit report covering: (1) quote analysis — what the 402 challenge asks and whether it matches the seller's manifest and public catalog; (2) purchase behavior — comparing quoted vs signed vs settled vs chain-confirmed vs delivered responses, plus replay and bad-payment handling; (3) inbound on-chain books — settlement records, total revenue, and distinct/repeat payer counts; (4) cost benchmarking against other priced x402 doors. The report is Ed25519-signed and logged, presenting only facts with no verdict. No net charges to the caller beyond the audit fee if no purchase settles.","failureModes":["Target URL does not respond with a valid 402 challenge — audit cannot proceed","Purchase budget exceeded by requested number of purchases","Target endpoint is unreachable or returns non-HTTP-402 errors","On-chain settlement data unavailable for the target door","Manifest or catalog lookup fails for the target x402 seller","Invalid method/body combination causing all test purchases to fail"],"whenToPreferThis":"Choose this endpoint when you need a comprehensive, cryptographically signed audit of an x402 endpoint before integrating it into an agent workflow, when you want to verify on-chain settlement behavior and replay resistance, or when you need to benchmark cost against comparable paywalled APIs. Prefer this over a simple reliability pre-flight (Orcpin's probe endpoint) when you need full purchase lifecycle verification and on-chain accounting, not just uptime and latency stats.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-03T12:39:14.317Z","isFirstParty":false,"canonicalSlug":"orcpin-x402-door-audit-1f15c847"}