SameDayDesk x402 Data Gateway
About
Thirteen live MCP tools for x402 and MPP data, web extraction, agent discoverability, security audits, Morpho decisions, and work preflight.
Details
- Author
- epistemedeus
- Categories
- Developer Tools
Jump to
Setup
Install SameDayDesk x402 Data Gateway in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/epistemedeus/x402-url-extractor
Follow the installation instructions in the repository README, then restart your MCP client.
Thirteen live MCP tools for x402 and MPP data, web extraction, agent discoverability, security audits, Morpho decisions, and work preflight.
Every paid HTTP response advertises/.well-known/agent-payment-evidence.jsonthrough the standard HTTPdescribedbylink relation. The bounded free manifest joins each exact method and route to its seller-declared read-only effect, recursively guaranteed JSON paths, response-schema digest, exact replay binding, receipt behavior, and the existing signed deployment statement. It does not change x402 or MPP terms and is not authorization to spend; buyers must still verify the live challenge, paid output, receipt, and settlement.
Twenty pay-per-call tools for deterministic agent-work opportunity preflight, machine-service discoverability, payment-offer preflight, Morpho borrower and market decisions, protection plans, URL extraction, Markdown reading, repository security scans, company and wallet enrichment, structured data generation, transaction receipt evidence, delegated-signer policy conformance, settlement proof, and AI-search readiness audits.
- Product page:https://samedaydesk.com/x402
- Smithery:https://smithery.ai/servers/epistemedeus/x402-data-gateway
- Remote MCP:https://agents.samedaydesk.com/mcp
- Live resource manifest:https://agents.samedaydesk.com/.well-known/x402
- OpenAPI:https://agents.samedaydesk.com/openapi.json
- Official MPP OpenAPI:https://agents.samedaydesk.com/mpp-openapi.json
- Skill contract:https://agents.samedaydesk.com/skill.md
- Action catalog:https://agents.samedaydesk.com/api/actions
- A2A agent card:https://agents.samedaydesk.com/.well-known/agent-card.json
- Global A2A Registry:https://www.a2a-registry.org/agent/9cb0b8e6-cb1f-422b-a604-861d0a79e24b
- Settlement Radar:https://agents.samedaydesk.com/platforms
- Platform health JSON:https://agents.samedaydesk.com/v0/cards.json
- Aggregate machine-demand telemetry:https://agents.samedaydesk.com/v0/commerce-demand.json
- Morpho position risk:GET /defi/morpho-position?address=0x...&shocks=-10,-20,-30
- Morpho protection quote:GET /defi/morpho-protection?address=0x...&targetHealthFactor=1.25&protectAgainstShockPct=-10
- Morpho market underwriting:GET /defi/morpho-market-underwrite?marketId=0x...
- Morpho PreLiquidation replay:GET /defi/morpho-preliquidation-replay?transactionHash=0x...
- Opportunity preflight:GET /work/opportunity-preflight?rewardUsd=10&hours=0.25&hourlyCostUsd=4&selectionProbabilityPct=20
- Agent discoverability audit:GET /distribution/agent-discoverability-audit?origin=https://example.com&intent=extract+a+public+website+into+structured+JSON&route=/extract&runtimeUrl=https%3A%2F%2Fexample.com%2Fextract%3Furl%3Dhttps%253A%252F%252Fexample.org&surfaceAudit=true
- Payment offer preflight:GET /commerce/payment-offer-preflight?url=https://example.com/paid-route
- Seller integrity audit:GET /commerce/seller-integrity-audit?origin=https://seller.example&route=/paid-route&method=GET&requiredPaths=data.attributes
- Contract-qualified search:GET /commerce/contract-qualified-search?query=service+domain+ownership+code+provenance&requiredPaths=data.sourceRepositoryreturns a bounded advisory OpenAPI repair plan for missing buyer-required paths without mutating seller files or inferring undeclared property types.
- Base USDC settlement proof:GET /commerce/settlement-proof?transactionHash=0x...&recipient=0x...&amountAtomic=5000
- Base or Ethereum transaction receipt:GET /chain/transaction-receipt?transactionHash=0x...&network=base
- Wallet policy conformance:POST /security/wallet-policy-conformance
- Wallet policy conformance contract:GET /schemas/wallet-policy-conformance-v1.json
- Stateful wallet policy conformance:POST /security/stateful-wallet-policy-conformance
- Stateful wallet policy contract:GET /schemas/stateful-wallet-policy-conformance-v1.json
- Material-change alert probe:https://agents.samedaydesk.com/alerts
- Agoragentic seller callback:POST /integrations/agoragentic/ai-readiness-audit
- the402 signed fulfillment webhook:POST /integrations/the402/webhook
No API key or subscription is required. Every paid HTTP route advertises x402 and native MPP Payment authentication in the same 402 response. Both protocols settle the same exact USDC amount to the same Base mainnet merchant wallet. MCP tool calls remain x402-gated.
The Morpho route is read-only. It calculates LTV, LLTV, health factor, liquidation headroom, and collateral-price shock scenarios from integer protocol values, then cross-checks indexed collateral, borrow shares, and oracle price against direct Base RPC state. Scenarios are calculations rather than probabilities or transaction recommendations. The separate protection route uses a fresh direct-RPC oracle read and direct confirmation of collateral and borrow shares to calculate exact partial-repay and add-collateral amounts. It returns unsigned token-approval and Morpho-call templates, explicit execution buffers, revalidation requirements, and economic postconditions. It never accesses a wallet, signs, broadcasts, or takes custody.
The service also keeps a privacy-safe demand telescope on a persistent Railway volume. It records route families, query key names, challenge/success classes, and pseudonymous repeat-use signals. External fetches are acquisition signals, not verified buyers, because unidentified automated indexers can remain. Recognized crawler and agent-indexer user agents are reduced at ingestion to a controlled source label and reported in a separate machine-discovery lens with source and route coverage. Those observations measure fetches, not authenticated catalog referrals, intent, or demand. Unmatched requests are reported separately from a conservative semantic-candidate subset; neither becomes demand until an independent caller repeats or converts. It does not record raw IP addresses, user agents, URLs, query values, bodies, payment headers, marketplace payloads, or credentials. Public output is aggregate only; owner traffic is excluded and crawler traffic remains excluded from demand even when its controlled discovery counts are reported separately. Common exploit probes such as.env,.git, and WordPress discovery paths are classified as scanner traffic and excluded as well.
Version 1.9.4 adds explicit paid-traffic classes without exposing buyer addresses.COMMERCE_PAYER_CLASSESaccepts a JSON array of{ "address", "class" }records. Controlled classes areinternal,validation,incentivized,affiliated, andindependent. Addresses are converted to the same secret-keyed payer pseudonyms already used by telemetry and classified at read time, which also permits retroactive correction without storing a raw address. Unknown payers remainunclassified; unfamiliar wallets never become independent demand by inference. The public snapshot reports paid success by class plus independent and repeat-independent actor counts.
Version 1.9.5 adds route-level paid-success counts inside each evidence class. This lets downstream monitors treat marketplace validation as accounting and transport evidence, alert on unclassified paid use for investigation, and advance the demand thesis only for explicitly independent or repeat-independent buyers.
Version 1.9.6 privately captures a valid Base transaction hash from successful x402PAYMENT-RESPONSEor MPPPayment-Receiptheaders after an explicit evidence baseline. Public telemetry exposes only proof coverage, distinct-count, and missing-reference counts by payment class. Raw headers and transaction references stay on the private volume. A missing reference becomes a material settlement-integrity event without exposing the reference itself.
Version 1.11.2 content-negotiates the root without changing its machine contract. Browser navigation with an explicitAccept: text/htmlreceives a responsive human map of the fourteen tools, payment flow, and authoritative discovery links. JSON clients, curl's wildcard accept header, and agents keep the stable JSON descriptor. The response varies onAccept, and the human page duplicates no payment schema.
Version 1.11.2 also adds the source-attributed machine-discovery lens. It keeps raw user agents and network addresses out of the public snapshot, reports exact future indexer observations by controlled source and route, and gives the radar only first-source and first-route coverage changes as material events. Repeated crawl volume remains visible data without becoming an attention alert or demand.
Version 1.11.3 makes that reach lens prospective and self-excluding. A distinctCOMMERCE_AGENT_DISCOVERY_SINCEbaseline prevents pre-instrumentation crawler history from becoming attributed reach, while SameDayDesk-owned monitor user agents are excluded from both discovery and external-demand observations. This keeps integrity sweeps, brand-blind benchmarks, and radar probes from creating their own acquisition signal.
Version 1.11.4 preserves paying agents even when their user agent identifies as a crawler or indexer. A valid submitted x402 or MPP credential moves the event into economic telemetry before crawler classification, while the controlled user-agent label records source-to-paid conversion by source and route. Channel labels are still self-declared rather than authenticated referral proof, and independent demand still requires the explicit payer-class policy.
Version 1.11.5 separates paid-route reach from challenge delivery. Prospective agent/indexer observations now report paid-route probes, HTTP 402 challenges, distinct and repeat challenge actors, challenge rate, and controlled source and route breakdowns. This identifies whether the machine funnel stops before the paywall, at the challenge, or after a submitted credential without treating an indexer probe as purchase intent.
Version 1.11.6 adds a conservative challenge-to-payment cohort. A paid success counts as continuation only when the same secret-keyed network-and-user-agent actor returns after its first prospective challenge. The public snapshot reports converted calls, converted actors, independent converted actors, conversion rate, and controlled source and evidence-class totals without actor IDs. Network or user-agent drift can only create false negatives, so the metric is a lower bound rather than an identity claim.
Version 1.11.7 adds project-owned Glama connector verification at/.well-known/glama.jsonusing the public SameDayDesk business email. Glama requests have their own controlled discovery-source label, so a propagated directory claim can be measured without becoming demand.
Version 1.11.8 starts a separate credential-attempt funnel. After a declared baseline, a parseable attempt must include a syntactically complete x402 v2 exact binding or MPP evm/charge credential. Signature validity and settlement remain later outcomes. Public aggregates separate header noise from parseable attempts and report protocol, result, route, controlled source, and explicit payer class without raw credentials, actor IDs, or addresses.
Version 1.11.9 improves MCP tool selection without renaming or duplicating any tool. Every tool now has a unique action-oriented title. The overlapping web and company tools explicitly say when to chooseextractversusread,enrichversusschemaforge, and the combineddeep_audit;wallet_enrichalso states that its input is an EVM address rather than a company domain. The payment routes, names, prices, schemas, and handlers are unchanged.
Version 1.11.10 adds explicit descriptions to everyopportunity_preflightinput and to the three Morpho protection controls. This improves machine call construction while leaving names, routes, prices, required inputs, defaults, payment gates, and execution behavior unchanged.
Version 1.11.11 gives all four Morpho MCP tools explicit sibling-selection guidance. Borrower diagnosis, future protection planning, market underwriting, and historical PreLiquidation replay are now distinct machine choices without renaming a tool or changing its route, price, schema, payment gate, or handler.
Version 1.11.12 starts a prospective MCP transport-friction probe. It separates four common client expectations,/mcp/sse,/mcp/messages,/mcp/tools, and/mcp/events, from arbitrary/mcp/misses without serving a guessed alias. Public aggregates expose only route counts and secret-keyed actor totals. A compatibility route is justified only by repeated independent use or conversion.
Version 1.11.13 repairs the pre-payment response contract exposed to machine buyers. All thirteen routes already authored explicit JSON output schemas, but the Bazaar v2 helper expects that schema underoutput.schema; the previous top-leveloutputSchemafield was silently ignored. A single tested adapter now places each authored schema at the protocol-defined location, so an unpaid 402 challenge exposes both the example and the concrete required response fields before an agent authorizes payment. Routes, inputs, prices, settlement, and handlers are unchanged.
Version 1.11.14 projects the same thirteen response contracts into the free OpenAPI and action catalog. Discovery agents can now inspect concrete required fields and an example before probing a paid route;/readis also described as the JSON object its handler actually returns rather than a raw Markdown string. One route-keyed contract map drives the x402 challenge, OpenAPI, and action catalog to prevent the three machine surfaces from drifting apart.
Version 1.11.16 links the versioned, credential-freeagent-payment-policyreference from the machine root, OpenAPI service metadata, andllms.txt. The reference has no wallet executor, payment signer, custody, or hosted paid verifier. It gives machine buyers a stable policy and evidence primitive without changing the merchant's routes, prices, payment requirements, or settlement.
Version 1.13.1 advances that machine-facing buyer reference to public package 0.4.0. The root, OpenAPI metadata, andllms.txtnow advertise exact execution-shape authorization plus fourteen-dimension control-coverage schema v2. This follows first-person Tempo and Solana evidence that provider-native method and instruction allow rules can admit duplicated approved actions. No merchant route, price, handler, payment requirement, or settlement changes.
Version 1.14.0 turns the cross-chain delegated-signer failure we encountered into a credential-free paid product.POST /security/wallet-policy-conformanceaccepts only a bounded standardized allow, deny, and error matrix. It separates operation allowlisting from exact execution-shape control, credits only an explicit provider policy denial as provider-native enforcement, and returnsconformant,partial, orunsafewith no opaque score. Invalid or secret-bearing shapes are rejected before payment. The evaluator accepts no wallet credential, signature, transaction body, wallet access, or broadcast authority and does not claim to have executed the caller's provider tests.
Version 1.14.1 publishes the exact standardized cases, evidence classes, input schema, output schema, method, protocols, and atomic price at the free canonical/schemas/wallet-policy-conformance-v1.jsoncontract. The paid route, price, decision logic, payment gates, and settlement remain unchanged. Machine clients can now construct and validate the matrix without decoding a payment challenge.
Version 1.14.2 moves the taxonomy, strict validator, offline evaluator, and JSON Schemas into publicagent-payment-policy@0.5.0; the hosted product now imports that package instead of maintaining a private duplicate. The public package also provideswallet-policy-init,wallet-policy-check, andwallet-policy-schemaCLI commands. An unrun intended case is correctlypartial, while a proven blocked intended action or an allowed mutation remainsunsafe. The hosted route, 0.01-USDC price, payment terms, and credential-free boundary remain unchanged.
Version 1.14.3 advances the public standard dependency toagent-payment-policy@0.5.1. Provider-native control credit now requires every observed case for that control to pass. A denied optional shape case can no longer mask an allowed duplicate-approved-action case. The Privy Tempo and Solana adapters both classify exact execution shape as unverified and the overall native policies as unsafe, matching the first-person evidence. Route, price, payment, and credential boundaries remain unchanged.
Version 1.15.0 adds a separate stateful wallet-policy product from the project's first-person Privy cumulative-cap experiment.POST /security/stateful-wallet-policy-conformanceevaluates seven safe standardized cases for sequential caps, signed-but-unbroadcast accounting, ABI extraction, concurrent oversubscription, counter-reference failure, and application serialization.GET /schemas/stateful-wallet-policy-conformance-v1.jsonpublishes the free construction contract. The evaluator comes from publicagent-payment-policy@0.6.0, accepts no credentials or raw provider payloads, and keeps provider-policy and application enforcement separate.
Version 1.15.1 turns first-person stale-catalog evidence into a bounded discoverability-audit feature. Callers can provideexpectedPriceUsdtogether with an exact route to compare catalog-advertised route prices across the ten public discovery views. The result distinguishes matched, drifted, mixed, unknown-price, and absent-route states and returns a one-canary maximum remediation sequence only after owned live terms agree. It never treats the caller expectation as runtime truth, makes no catalog payment, and leaves asynchronous propagation to event-driven monitoring.
Version 1.15.2 repairs the measurement path for the two free wallet-policy contracts and their matching paid evaluators. All four routes now have exact commerce classifications. Historical/schemas/events remain in the raw unmatched count but are excluded from semantic-demand interpretation because the privacy-safe ledger did not retain enough path detail to reclassify them. New exact events produce aggregate same-client funnels from successful free contract read to paid-route challenge, parseable credential, and delivery. The public snapshot exposes no actor, credential, raw path, wallet, or provider payload, and contract reads remain reach evidence rather than demand.
Version 1.16.0 upgrades payment-offer preflight from protocol parity alone to optional catalog-to-runtime coherence. A caller can submit one exact catalog candidate with the POST or MCP form, and the product compares it only with the matching live unsigned protocol offer across request, protocol, amount, network, asset, recipient, and expiry using publicagent-payment-policy@0.7.0. Explicit drift producesreview_required; missing catalog fields remain a visible partial result. The x402 validity window is derived frommaxTimeoutSeconds, malformed catalog input is rejected before payment, and the request still uses no target credential, wallet, signature, settlement, redirect, or response body.
Version 1.16.1 upgrades the existing agent-discoverability audit without adding another product or changing its 0.05-USDC price. An optionalruntimeUrlmust use the audited origin and exact requested route. The audit makes one credential-free, DNS-pinned, headers-only request, accepts a price reference only when the live unsigned x402 and MPP terms are parseable and coherent, and then compares that canonical Base-USDC amount with every registry observation. Caller-supplied expectations remain supported and clearly labeled, while a disagreement with runtime truth becomes its own finding. The result still signs nothing, sends no target payment, follows no redirect, and reads no target response body.
Version 1.16.2 adds route-level listing identity to that same audit. Each catalog observation now reports whether the exact route is canonical, duplicated, alias-only, or split across canonical and non-canonical origins. An alias candidate requires an explicit payTo and exact-route match, and the output states that this does not prove hostname ownership. This catches stale marketplace aliases and URL-keyed duplicate listings alongside price drift, while preserving the same 0.05-USDC product, request boundary, and no-spend catalog sweep.
Version 1.16.3 makes the identity evidence boundary explicit. A non-canonical record that shares the caller-supplied payTo and exact route is an alias candidate, not proof that the seller owns the hostname. Every source now returnsidentityBasis,ownershipProven, and a plain-language evidence boundary so an automated repair can preserve the canonical record without retiring a third-party endpoint on circumstantial evidence.
Version 1.16.4 replaced the route-audit's private identity classifier with the public, provenance-bearingagent-payment-policy@0.8.0primitive. Catalogs that return no matching records are now still recorded as checked androute_absent; canonical origin matches remain observations rather than ownership claims. This creates one shared, installable contract for the live seller and independent buyer tooling without adding credentials, wallet access, signing, payment, or retained settlement identities.
Version 1.18.3 completes machine-constructible examples for the Base settlement proof and Solana receipt routes and gives the Circle Gateway alias the same authored success-response schema as the canonical payment-offer preflight.
Version 1.18.2 publishes recursive response reports under their immutable v2 schema identifier.
Version 1.18.1 adds recursively guaranteed response paths to the bounded report, so a seller that requires only a top-leveldataenvelope does not appear to promise a nesteddata.attributesdecision payload.
Version 1.18.0 keeps the signed catalog-alias identity control and adds a bounded seller response-contract check to payment-offer preflight. The route now reads the exact seller's same-origin public OpenAPI document under a strict size cap and reports whether the exact GET operation declares a self-contained JSON success schema with typed required fields. It never reads the paid target body, and the seller declaration remains advisory until a paid response passes the buyer's independently authorized output validator.
Version 1.22.3 turns seller declarations that exceed the bounded audit byte ceiling into the specificopenapi_too_largegap instead of a generic bounded audit failure. The ceiling remains unchanged and no schema is inferred.
Version 1.22.2 excludes both the canonical SameDayDesk origin and its known former Railway catalog alias from contract-qualified search. Agent402 ranked both records for the first live buyer-language query, proving that excluding only the canonical hostname did not exclude owned supply at the service- identity level.
Version 1.22.1 adds mandatory MCP selection metadata for the new search tool and strengthens the production startup smoke test so a release cannot pass merely because HTTP is listening while the asynchronous MCP mount failed.
Version 1.22.0 adds a paid contract-qualified machine-service search. A buyer supplies a capability intent and recursively required JSON response paths. The route searches Agent402 and the official MPP catalog, excludes owned supply and unresolved routes before audit, and returns bounded machine-buyable or contract-ready candidates plus controlled rejection codes. It uses no credential or wallet, sends no seller POST or target payment, reads no paid body, and returns only a query digest. The signed deployment statement now binds twenty-three exact HTTP method and path pairs.
Version 1.17.0 closed the catalog-alias ambiguity with an optional signed deployment statement fromagent-payment-policy@0.9.0. The short-lived JWS at/.well-known/agent-payment-policy-service-deployment.jsonbinds the canonicalagents.samedaydesk.comorigin to the then-current paid HTTP method and path pairs and to the exact Base USDC x402 and MPP settlement identities. Each deployment origin carries its own route and settlement scope, so a future alias cannot inherit another origin's authority.
The public Ed25519 key at/.well-known/agent-payment-policy-service-deployment.pemis the same raw key as theagentWalletin SameDayDesk's Solana ERC-8004 registration. The signing key remains offline and is not deployed. The JWS response stays a strict envelope; its key and registration pointers use HTTPLinkheaders and the ERC-8004 registration document./healthzreports the statement ID, key fingerprint, route count, expiry, and active state so rotation can be monitored. The statement proves control of that registered key and the declared service binding. It does not authorize, sign, or send a buyer payment.
Version 1.11.15 validates every Bazaar declaration against its own JSON Schema before startup. Six newer routes previously settled successfully while Coinbase rejected their discovery metadata because their output examples omitted fields marked required by the same schemas. The examples now conform, andbazaar-contract-audit.mjschecks every live CDP Bazaar-eligible paid route through credential-free HTTP 402 probes without retaining headers or query values. Alternate x402 settlement rails are reported as explicit exclusions instead of being misclassified as failed Bazaar declarations.
Version 1.11.18 adds a source-quality funnel to the public aggregate. Each controlled discovery source now reports observations alongside distinct and repeat actors at discovery, paid-route, challenge, credential-attempt, and paid success stages. Challenge rates are available both per request and per actor, so one high-frequency crawler no longer looks like broad machine reach. Challenge-to-payment conversions are attributed to the source of the first observed challenge. Raw user agents, network addresses, and actor identifiers remain private and are not returned.
Version 1.11.19 starts a separate prospective AI-provider source cohort. It uses exact provider-published HTTP tokens to distinguish OpenAI, Anthropic, and Perplexity search, user-fetch, and training traffic plus Google Cloud Vertex agent crawls.Google-Extendedis intentionally excluded because Google states that it has no distinct HTTP user-agent string. The detail cohort has its own baseline, preserves historical generic records, reports the same actor funnel, and treats every label as an unauthenticated observation rather than referral proof.
Version 1.11.20 repairs the resource metadata consumed by payment-capable wallet agents. Every one of the fourteen x402 v2 challenges now carries the validated provider-levelserviceNameand five bounded route capability tags in the standard top-level resource object. Startup fails closed if paid-route coverage and metadata coverage diverge. The Bazaar contract audit now rejects a route whose extension is valid but whose resource name or tags are absent or invalid. Prices, outputs, settlement, privacy, routes, and native MPP terms are unchanged.
Version 1.12.0 adds/chain/transaction-receiptat 0.002 USDC after a live market experiment found provider-level settlement for cheap chain utilities but two zero-spend delivery failures from a heavily viewed competing receipt route. The new route accepts one mined Base or Ethereum transaction hash and returns normalized status, block time, gas and fee fields, decoded ERC-20 Transfer events, and canonical USDC transfers. Invalid hashes and unsupported networks are rejected before payment. Raw logs, wallet access, signing, and broadcast are outside the product boundary.
Version 1.12.1 repairs the authenticated delivery boundary for the Solana/commerce/payment-offer-preflightstorefront. After the Solana gateway has verified and settled its own x402 or MPP payment, its private internal header now reaches the deterministic product directly instead of encountering a second Base payment gate. Requests without the exact private header retain the ordinary Base x402 and MPP behavior. Target credentials and target payments remain outside the preflight product boundary.
Version 1.12.2 keeps seller-owned discovery surfaces synchronized with the canonical paid action catalog. The A2A Agent Card now uses the actual service version, retains the aggregate catalog skill first, and appends one explicit discovery-only skill per paid route. The ERC-8004 registration document retains its protocol entry points and adds the same direct paid action URLs. The A2A descriptor reuses the canonical aggregate skill ID, and inbound messages must carry the normative user role, message ID, and at least one part. These changes improve route discovery but do not claim support for unimplemented A2A task operations.
Version 1.12.3 turns that discovery lesson into an optional seller audit. SetsurfaceAudit=trueon the existing paid discoverability route to check whether the expected route appears in the target's public A2A Agent Card, ERC-8004 registration document, and action catalog. The target fetch is restricted to three fixed same-origin JSON paths, pins a fully public DNS answer, rejects redirects, caps each response at 512 KiB, and times out after five seconds. The default remains catalog-only and does not fetch the target origin.
Version 1.12.4 gives the JSONPOST /work/opportunity-preflightprobe the same complete Bazaar input and output contract as the existing GET route. This removes machine-discovery schema errors without changing the price, validation, handler, response, or payment behavior. Empty unauthenticated POST remains a discovery-only challenge; a paid call must still supply and bind the required body.
Version 1.13.0 adds a 0.002-USDC finalized Solana transaction-receipt product. It validates the signature and any optional mint, recipient, amount, and payer claim before payment, then returns bounded finalized status, fee, SPL-token owner deltas, canonical-USDC deltas, and deterministic match findings. It reads public RPC state only after settlement and has no wallet, signing, custody, or broadcast authority. The route is available through Base x402, native MPP, MCP, A2A, and the separate Solana payment gateway.
Version 1.11.23 adds a narrow compatibility bridge for MCP clients that retry a paidtools/callwith the x402PAYMENT-SIGNATUREHTTP header but fail to copy the same signed payload into_meta["x402/payment"]. The merchant decodes only a bounded, object-shaped header ontools/call, never overrides canonical MCP metadata, and passes the result to the existing@x402/mcpverifier. The bridge does not trust the header, change payment terms, or bypass signature, amount, asset, network, nonce, or settlement validation.
Version 1.11.24 publishes each tool's exact live x402 payment options in MCPtools/listmetadata. Compatible clients can inspect price, asset, network, recipient, and scheme before calling, then attach a fresh signed payload to the firsttools/callinstead of relying on a challenge retry. Runtime verification and settlement remain authoritative, and the unpaid challenge path is unchanged.
…
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





