Skip to content
onelayer.
All tools

Tool detail

x402 security audit

Probes a URL's x402 402 payment challenge (no actual payment) and returns a letter-grade security audit: TLS, cache hygiene, error handling and payment-terms findings.

Categories: Security

Use when

  • check an x402 seller's payment security before integrating it
  • grade a paid API's TLS and cache-hygiene posture
  • spot info leakage in a 402 payment challenge

Not for

  • not a guarantee - insider or active testing can reveal more
  • never pays or executes a transaction itself

Inputs

GET query params: url (string, required); method (string, optional, default GET)

Admitted input schema

{
  "type": "object",
  "properties": {
    "method": {
      "type": "string",
      "minLength": 0,
      "maxLength": 4096,
      "description": "HTTP method to probe with (default GET)"
    },
    "url": {
      "type": "string",
      "minLength": 0,
      "maxLength": 4096,
      "description": "URL of the paid resource to audit"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}

Endpoint

Method
GET
URL
https://agent402.tools/api/x402-audit

Payment

Protocol
x402
Listed price
0.01 USDC per call on Base
Payment method
exact
Network
eip155:8453
Asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Listed terms are catalog metadata. The caller supplies inputs and calls the tool outside Onelayer. If payment is required, the caller uses a compatible wallet to pay.

Source

Record
GET https://agent402.tools/api/x402-audit
Retrieved
2026-09-30T20:37:07.382Z
Catalog file SHA-256
6837ccddf886f0007cf3727ea9d27faaa5047b51b4f425345c554ce1c271a524
Catalog built
2026-09-30T22:31:58.034Z