{"uid":"cap_vq6rW1gsPqwmNFtHQ4iYD","slug":"minia2a-x402-payment-audit-black-box-buyer-trust-check-fd86ee72","name":"minia2a x402 Payment Audit (Black-Box Buyer Trust Check)","description":"Black-box check: does the x402 endpoint verify payment (reject forged txHash/signature/replay) before delivering? Buyer-side trust check before you pay. Returns SAFE/RISK/NOT_X402.","url":"https://minia2a.uk/x402/x402-payment-audit","method":"GET","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object","properties":{"type":{"type":"string"},"method":{"type":"string"},"bodyType":{"type":"string"},"queryParams":{"type":"object"}}},"output":{"type":"object","properties":{"type":{"type":"string"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"5","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$5/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NKoHxSMzO2Hc-zLGnsnGR","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"5","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a black-box security audit of an x402 payment endpoint to verify it properly rejects forged transaction hashes, invalid signatures, and replay attacks before you pay — returning SAFE, RISK, or NOT_X402.","exampleAgentPrompt":"Before I pay this x402 API, run a black-box audit on it to check whether it actually validates payments — I need to know if it would reject a forged txHash or a replayed signature, and get back a SAFE, RISK, or NOT_X402 verdict.","exampleUseCases":[{"title":"Pre-payment buyer trust verification","prompt":"I found an x402 endpoint I want to call, but before I hand over any USDC I want to know if it actually enforces payment — can you run a black-box audit on it and tell me if it comes back SAFE, RISK, or NOT_X402?"},{"title":"Replay attack vulnerability check","prompt":"Can you probe this x402 API to see if it would accept a replayed payment transaction? I need to know if it's vulnerable before I integrate it into my app."},{"title":"Forged signature rejection test","prompt":"I'm evaluating an x402 service for my agent workflow — audit it to see whether it properly rejects forged transaction hashes and bad signatures, and give me the trust verdict."}],"resultDescription":"Returns one of three verdict strings: SAFE (the endpoint correctly rejects forged txHash, invalid signatures, and replay attacks — safe to pay), RISK (the endpoint has detectable weaknesses in payment verification — payment fraud possible), or NOT_X402 (the endpoint does not appear to implement the x402 payment protocol at all). May include additional detail on which specific checks passed or failed.","failureModes":["Endpoint unreachable or returns non-HTTP response — audit cannot complete","Target endpoint uses non-standard x402 implementation that confuses probing — may return NOT_X402 incorrectly","Network timeout probing the target — incomplete verdict","Target endpoint rate-limits audit probe requests — partial results","Ambiguous payment verification behavior — may return RISK with low confidence"],"whenToPreferThis":"Use this endpoint when you are a buyer or agent about to pay an x402-gated API and want to confirm the endpoint actually enforces payment integrity before committing USDC. Prefer this over manual inspection when you cannot read the server-side source code (black-box scenario). Also prefer this over the white-box source audit endpoint when you only have the live URL and no access to the implementation code.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:08:53.707Z","isFirstParty":false}