Skip to content

Protocol inspection workbench

Know what an x402 endpoint declares before payment.

One bounded public GET. Conform402 inspects HTTP 402 behavior, x402 V2 structure, network identity, and Algorand payment terms without a wallet or payment.

  • Read-only
  • No wallet
  • No payment
  • No transaction signing
  • DNS-pinned

01 / COVERAGE

What Conform402 checks

An inspection matrix for the public response and declared terms. Each output stays bounded to evidence the endpoint exposes.

  1. 01

    HTTP RESPONSE

    QuestionDoes the public resource return the expected HTTP 402 response?

    OutputStatus, redirects, final URL

  2. 02

    X402 V2 CHALLENGE

    QuestionIs the PAYMENT-REQUIRED challenge present and parseable?

    OutputParser state, version, options

  3. 03

    CORE SCHEMA

    QuestionDoes the challenge satisfy the Foundation/core shape?

    OutputCompatibility diagnostics

  4. 04

    NETWORK IDENTITY

    QuestionAre declared networks compatible and canonically represented?

    OutputCAIP representation

  5. 05

    ALGORAND PROFILE

    QuestionAre network, ASA, amount, and recipient declarations valid?

    OutputAVM payment-term analysis

  6. 06

    FINDINGS

    QuestionWhat needs to change before integration?

    OutputScore, remediation, evidence

02 / Probe sequence

How it works

One bounded method from target resolution to a sanitized report. This is the audit contract, not simulated runtime progress.

  1. 01

    RESOLVE

    Resolve the public host through the bounded target policy.

  2. 02

    PIN

    Pin the approved public address for each request hop.

  3. 03

    GET

    Send one unauthenticated, read-only request chain.

  4. 04

    PARSE

    Decode the returned x402 V2 challenge and declared terms.

  5. 05

    VERIFY

    Run core, CAIP, and Algorand profile diagnostics locally.

  6. 06

    REPORT

    Return the score, findings, remediation, and evidence.

03 / Execution boundary

What it never does

It performs one public GET. No wallet, no payment, and no transaction signing are ever part of the audit path.

ActivityConform402
Public unauthenticated GETYES
Wallet connectionNO
Private keyNO
Payment creationNO
Transaction signingNO
Facilitator / settlementNO
Stored audit historyNO

Passing the checked rules is not certification and does not establish complete endpoint security.

04 / Interfaces

One audit engine, multiple interfaces

The web auditor is available now. CLI and continuous-integration surfaces remain explicitly pre-release.

  • Web auditor

    Available now

    /audit

  • CLI

    Developer Preview

    Not publicly published to npm

  • GitHub Action

    Developer Preview

    Not released on Marketplace

05 / NEXT STEP

Inspect one public endpoint before integrating it.

Open auditor