Quartermaster

Security

Quartermaster takes payments but never takes custody, and it fetches URLs you give it without becoming a proxy into private networks. Here is how.

Payments: no custody

Request safety (SSRF hardening)

Tools that fetch a URL you supply (extract, meta, the x402 inspector and audit) validate the target before and after redirects:

Verify what you install

The Quartermaster Lens browser extension is read-only (no keys, no signing, no custody). Verify the binaries by SHA-256:

Firefox .xpi (v1.0.1)   adafd94dd0b0c122497fa508a222fa117ba07640075020f2f674b42d38389464
Source .zip (v1.1.2)    6b0898b5ba0641ca3e0c41889ff7cda90d0ef1ce36170c7936bd448f4cf1a995

Signing keys

The MCP registry publisher key (ed25519) is published at /.well-known/mcp-registry-auth. Discovery ownership proofs are served under /.well-known/.

Responsible disclosure

Found something? Email dev@surewhynot.app with details and steps to reproduce. We will acknowledge and fix; no bug-bounty program yet, but credit is given.

See also Privacy and Transparency.