Tools / x402 tools
x402 Audit $0.01 / call
Full scored audit of any x402 endpoint.
GET /v1/x402-audit
The workflow version of the inspector: one call runs the whole audit sequence builders otherwise do by hand. It verifies the 402 challenge, judges every payment field (version, network, asset, payTo), checks Bazaar discovery metadata, and probes the origin's discovery surfaces (llms.txt, openapi.json, .well-known/x402, discovery/resources). Returns a 0-100 score, pass/warn/fail checks with evidence, and concrete recommended fixes. Deterministic, read-only, no loops.
Parameters
url required | x402 paid endpoint to audit |
Example
macOS / Linux
curl -s "https://quartermaster.surewhynot.app/v1/x402-audit?url=https://x402-endpoints.onrender.com/web/extract"
Windows (cmd or PowerShell)
curl.exe -s "https://quartermaster.surewhynot.app/v1/x402-audit?url=https://x402-endpoints.onrender.com/web/extract"
Unpaid, these return 402 Payment Required with the payment details in the header (add -i to see them). curl.exe ships with Windows 10+ and works in cmd and both PowerShell versions. To actually pay, use an x402 client (see Connect) or call it as the MCP tool. Cost: $0.01 per call.
FAQ
How is this different from the $0.002 inspector?
The inspector decodes one 402 challenge. The audit runs the full sequence - challenge plus payment-field judgment plus Bazaar metadata plus four origin discovery probes - and returns a scored report with fixes. It replaces five separate calls and the judgment in between.
What does the score mean?
0-100, weighted toward the checks that block payments or Bazaar listing. 80+ with no critical failures is a pass; anything failing a payment-critical check is a fail regardless of score.
Is it safe to point at any URL?
Yes. The audit is read-only GETs against the target and its origin only - no POSTs, no payments to the target, no crawling beyond four fixed well-known paths, and private/internal addresses are refused.
How do I pay for this endpoint?
Call it with no payment and you receive HTTP 402 with machine-readable payment requirements. Attach a USDC payment on Base with any x402 client (for example @x402/fetch) and retry — the whole loop is two requests. This call costs $0.01 in USDC.
Do I need an account or API key?
No. There are no accounts, logins, or API keys anywhere in Quartermaster. Payment is per call over the x402 protocol; your wallet is your identity.
Can I call this as an MCP tool instead?
Yes. Quartermaster is also an MCP server at /mcp, so any MCP client (Claude Code, Claude.ai, Cursor) can mount this tool. See /connect for setup.
← All tools · Connect to an agent · OpenAPI