{"uid":"cap_wBtlv-0Bm4beg3qTgJPfb","slug":"minia2a-x402-payment-audit-black-box-79e85451","name":"minia2a x402 Payment Audit (Black-Box)","description":"Black-box check: does the x402 endpoint verify payment (reject forged txHash/signature/replay) before delivering? Buyer-side trust check before you pay. Returns SAFE/RISK/NOT_X402.","url":"https://minia2a.uk/x402/payment-audit","method":"GET","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object","properties":{"type":{"type":"string"},"method":{"type":"string"},"bodyType":{"type":"string"},"queryParams":{"type":"object"}}},"output":{"type":"object","properties":{"type":{"type":"string"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"5","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$5/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm__4IXIzJk5hy5lKZqvyPhd","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"5","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Black-box security check that probes an x402 endpoint to verify it properly rejects forged transaction hashes, invalid signatures, and replay attacks before delivering paid content — returning SAFE, RISK, or NOT_X402.","exampleAgentPrompt":"Before I pay to use that x402 endpoint at api.example.com/premium-data, can you run a black-box payment audit on it to check whether it properly rejects forged transaction hashes and replay attacks — I want to know if it's SAFE or RISK before I spend any money.","exampleUseCases":[{"title":"Buyer trust check before first payment","prompt":"I'm about to pay to use an x402 API for the first time — can you audit the endpoint at payments.someservice.io/data using a GET method to check if it actually validates payment signatures and rejects replay attacks before I send any USDC?"},{"title":"Vetting a new x402 marketplace listing","prompt":"I found a new x402 service listed on a marketplace and want to make sure it's legitimate — run a black-box payment audit on it to see if it returns SAFE, RISK, or NOT_X402 so I can decide whether to integrate it into my agent."},{"title":"Security review of competitor x402 integration","prompt":"We're evaluating several x402-based APIs for our data pipeline — can you black-box audit each one starting with api.datavendor.com/stream to check if their payment verification would catch a forged txHash or replay attack?"}],"resultDescription":"Returns a verdict of SAFE (the endpoint properly rejects forged/replayed payments), RISK (the endpoint has detectable vulnerabilities in payment verification), or NOT_X402 (the target does not appear to implement the x402 payment protocol). This helps buyers assess trustworthiness before submitting payment.","failureModes":["Target endpoint is unreachable or times out — audit cannot complete","Target endpoint returns unexpected non-x402 responses — classified as NOT_X402","Network restrictions prevent probing the target URL","Invalid or malformed input URL causes request to fail","Ambiguous endpoint behavior may yield inconclusive RISK classification"],"whenToPreferThis":"Use this endpoint when you are a buyer or agent considering paying an x402-gated API and want to verify it has legitimate payment verification before committing funds. Prefer this over white-box code audits when you only have access to the live endpoint (not the source code). Choose this for quick pre-payment trust checks, marketplace vetting, or due diligence on unfamiliar x402 services.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:09:56.331Z","isFirstParty":false}