{"x402Version":2,"payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","resources":[{"id":8247,"slug":"8247","resource":"https://x402-api-catalog.onrender.com/api/trust-check","description":"npm package trust check / risk score / security audit: registry age, weekly downloads, GitHub org/stars, OSV.dev vulnerabilities, typosquat detection.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"20000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"package":"left-pad","repo":"left-pad/left-pad"},"type":"http"},"output":{"example":{"package":"left-pad","reasons":[],"score":72,"signals":{},"verdict":"trustworthy"},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"package":{"description":"npm package name to check","type":"string"},"repo":{"description":"owner/repo override if npm metadata lacks a repo link","type":"string"}},"required":["package"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"package":{"type":"string"},"score":{"type":"number"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"x402-api-catalog.onrender.com","lastUpdated":"2026-09-07T18:00:07.415Z","quality":{"calls30d":4,"uniquePayers30d":2,"lastCalledAt":"2026-09-07T18:00:06.935Z"},"liveness":{},"verified":false,"featured":false},{"id":8248,"slug":"8248","resource":"https://x402-api-catalog.onrender.com/api/mcp-audit","description":"MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+credential access). If a GitHub repo is supplied, folds in a real software-supply-chain signal too.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"60000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"repo":"example-org/example-mcp-server","url":"https://mcp.example.com/mcp"},"type":"http"},"output":{"example":{"findings":[],"score":90,"tools_found":3,"url":"https://mcp.example.com/mcp","verdict":"healthy: no red flags found"},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"repo":{"description":"optional owner/repo to fold in a GitHub supply-chain signal","type":"string"},"url":{"description":"base URL of the MCP server (streamable-HTTP transport)","type":"string"}},"required":["url"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"score":{"type":"number"},"url":{"type":"string"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"x402-api-catalog.onrender.com","lastUpdated":"2026-09-07T17:52:09.026Z","quality":{"calls30d":2,"uniquePayers30d":1,"lastCalledAt":"2026-09-07T17:52:08.646Z"},"liveness":{},"verified":false,"featured":false},{"id":8249,"slug":"8249","resource":"https://x402-api-catalog.onrender.com/api/contract-check","description":"EVM token contract safety check: honeypot detection, mint/blacklist/pausable/self-destruct capability, ownership renouncement, transfer tax, and a real token-impersonation check (does the symbol claim to be USDC/WETH/DAI/cbBTC at the wrong address — the token equivalent of npm typosquatting).","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"50000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"address":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chain":"base"},"type":"http"},"output":{"example":{"address":"0x...","reasons":[],"score":85,"signals":{},"verdict":"safe: no red flags found"},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"address":{"description":"0x-prefixed EVM token/contract address","type":"string"},"chain":{"description":"base (default), ethereum, polygon, or arbitrum","type":"string"}},"required":["address"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"address":{"type":"string"},"score":{"type":"number"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"x402-api-catalog.onrender.com","lastUpdated":"2026-09-07T17:52:05.686Z","quality":{"calls30d":2,"uniquePayers30d":1,"lastCalledAt":"2026-09-07T17:52:05.473Z"},"liveness":{},"verified":false,"featured":false},{"id":8250,"slug":"8250","resource":"https://x402-api-catalog.onrender.com/api/domain-check","description":"Domain liveness check / verify / audit: DNS resolution (A/MX/NS/TXT records), whether mail routing exists, HTTP reachability.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"20000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"domain":"example.com"},"type":"http"},"output":{"example":{"domain":"example.com","hasMailRouting":true,"hasWebPresence":true,"httpReachable":true,"verdict":"fully live"},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"domain":{"description":"domain to check, e.g. example.com","type":"string"}},"required":["domain"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"domain":{"type":"string"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"x402-api-catalog.onrender.com","lastUpdated":"2026-09-07T17:52:02.44Z","quality":{"calls30d":2,"uniquePayers30d":1,"lastCalledAt":"2026-09-07T17:52:02.105Z"},"liveness":{},"verified":false,"featured":false},{"id":8251,"slug":"8251","resource":"https://x402-api-catalog.onrender.com/api/repo-health","description":"GitHub repo health check / audit / verify: stars, forks, open issues, last commit age, archived status, license.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"20000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"repo":"facebook/react"},"type":"http"},"output":{"example":{"reasons":[],"repo":"facebook/react","score":85,"signals":{},"verdict":"healthy"},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"repo":{"description":"GitHub repo in owner/repo format","type":"string"}},"required":["repo"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"repo":{"type":"string"},"score":{"type":"number"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"x402-api-catalog.onrender.com","lastUpdated":"2026-09-07T17:51:57.352Z","quality":{"calls30d":2,"uniquePayers30d":1,"lastCalledAt":"2026-09-07T17:51:57.096Z"},"liveness":{},"verified":false,"featured":false},{"id":8246,"slug":"8246","resource":"https://x402-api-catalog.onrender.com/api/x402-doctor","description":"Audits another x402 service for the exact failure modes that cause aggregators (agent-tools.cloud, x402scan, Bazaar) to mark it 'down' or make its 402 challenge unreadable: missing/invalid /.well-known/x402 descriptor, an unpaid request returning 500/404 instead of a clean 402, a malformed or missing payment-required challenge, and drift between the descriptor's advertised terms and the live challenge. Returns a concrete diagnosis and fix for each failing check, not just pass/fail.","type":"http","x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","amount":"1000000","maxTimeoutSeconds":300}],"outputSchema":{"bazaar":{"info":{"input":{"method":"GET","queryParams":{"path":"/api/some-paid-endpoint","url":"https://example-service.onrender.com"},"type":"http"},"output":{"example":{"checks":[],"fixes":[],"score":40,"url":"https://example-service.onrender.com","verdict":"broken: aggregators will show this as down"},"type":"json"}},"schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"path":{"description":"a specific paid endpoint path to probe; omit to auto-discover from the service's /.well-known/x402","type":"string"},"url":{"description":"base URL of the x402 service to audit","type":"string"}},"required":["url"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"score":{"type":"number"},"url":{"type":"string"},"verdict":{"type":"string"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"}}},"tags":["bazaar"],"sourceHost":"x402-api-catalog.onrender.com","lastUpdated":"2026-09-07T18:04:47Z","quality":{"calls30d":1,"uniquePayers30d":1,"lastCalledAt":"2026-09-07T18:04:46.765Z"},"liveness":{},"verified":false,"featured":false}]}