FOUND Live Services
activeDeterministic machine-paid services. HTTP 402 responses provide x402 payment requirements. POST /v1/router/quote is unpaid and hands the caller an already-live paid route at that route's unchanged price.
Settled via Coinbase.
- Transactions · 30d
- 0
- Volume · 30d
- $0.00
- Unique buyers · 30d
- 0
- Uptime · 30d
- 70.6%
- Latency p50
- 7491ms
- Reported calls · 30d
- 206
Endpoints (304 live)
POST/x402/v1/security-header-diff— Compare a fixed list of ten security-relevant response headers across two releases and name the specific reverts. Reports a header removed, added or changed, and separately a reduced Strict-Transport-Security max-age, dropped includeSubDomains, a newly permitted unsafe-inline or unsafe-eval, and a Content-Security-Policy that moved from enforcing to report-only so it no longer blocks anything. Observable differences only, not an assessment of whether either configuration is adequate. (0.11 USDC on Base)POST/x402/v1/revenue-recognition-schedule-audit— Check that a revenue recognition schedule sums to its contract value exactly and covers its term with no gap or overlap. A cent either way means that amount is either never recognised or recognised without having been contracted, and both are reported with the exact figure. Periods are treated as inclusive day ranges, so the day after one ends is the day the next must begin, and a gap and an overlap are separate findings because they are opposite errors. (0.2 USDC on Base)POST/x402/v1/openapi-response-conformance-audit— Audit a real response against what the OpenAPI document promises for that operation. Resolves the declared status exactly, by range such as 2XX, or through default, checks declared response headers are present, and validates the body against the declared schema for its media type. Catches an implementation that has drifted from its own published contract. (0.14 USDC on Base)POST/x402/v1/lockfile-change-report— Compare two lockfiles and report what a manifest diff cannot see. Reports newly installed transitive packages, resolved version moves with breaking risk, a registry that changed, and the most serious finding available here: the same version with a different integrity hash, meaning the artifact behind a version that was supposed to be immutable is not the one that was there before. (0.18 USDC on Base)POST/x402/v1/company-evidence-pack— Company enrichment and KYB data for due diligence by domain: verify a counterparty, supplier or vendor before outreach, onboarding or payment. Returns firmographics (legal name, LEI, SEC CIK, industry, HQ, founded, employees), domain intelligence (age, email provider, SPF/DMARC), public role emails, socials, plus OFAC SDN and EU sanctions screening. Source-cited; unknowns null. Company data only, not personal contacts or compliance clearance. Unresolvable domains not charged. (0.06 USDC on Base)POST/x402/v1/telemetry-attribute-contract-audit— Audit telemetry attributes against a contract, and against the thing a schema cannot see: cardinality. Reports missing required attributes, undeclared attributes, an attribute appearing as two types across the batch, and an attribute whose distinct values exceed your limit - because in a metrics backend each distinct value is a separate series, and that is how an index or a bill explodes. (0.12 USDC on Base)POST/x402/v1/kubernetes-manifest-audit— Audit a set of Kubernetes manifests against a contract the caller states. Reports an image with no tag or the latest tag, which changes under you; absent resource requests or limits; absent readiness or liveness probes; a missing required label; hostNetwork, hostPID, a hostPath volume or a privileged container; and a credential-shaped environment variable set to a literal, whose value is never echoed. YAML parsing surprises are reported rather than inherited. (0.16 USDC on Base)POST/x402/v1/tabular-contract-audit— Audit your own delimited data against a contract you declare, and get one pass/fail plus the exact row and clause of every breach. Checks types, required values, enums, numeric bounds, lengths, patterns, uniqueness, composite primary keys, null-rate ceilings, header drift and encoding damage in one pass. A pass means the audit was complete and nothing broke, so a file beyond the bounds reports incomplete rather than passing. Nothing is fetched: you supply the rows. (0.12 USDC on Base)POST/x402/v1/openapi-endpoint-inventory-diff— See which operations were added, removed, deprecated or renamed between two OpenAPI documents. Flags a removal that was never preceded by a deprecation, an operationId change that renames the method in every generated client, and a duplicated operationId that no generator can resolve. (0.1 USDC on Base)POST/x402/v1/json-schema-compatibility— Decide whether a schema change breaks your clients, and which ones. Classifies every change by the audience it breaks: producers construct the payload, consumers read it. Adding a required field breaks senders; adding an enum value breaks readers. A change it cannot classify is reported as unclassified and never counted as safe. (0.15 USDC on Base)POST/x402/v1/dkim-record-audit— Audit DKIM selector records. The key length follows from the length of the encoded public key, so a short RSA key is readable from the record itself with no cryptography. Reports a key shorter than a stated minimum; a selector left in testing mode, which asks receivers to treat a failure as unsigned so it cannot contribute to DMARC alignment however correctly it signs; a revoked key, with its consequence; and a key type verifiers do not implement. (0.18 USDC on Base)POST/x402/v1/structured-data-contract-audit— Audit the JSON-LD a supplied page declares against a contract the caller states. Entities inside @graph and nested inside other entities are flattened first, because reading only the top level misses every entity a real page declares that way. Reports required types absent, required properties missing per entity, unmentioned types when unknown types are forbidden, entities with no @type, and blocks with no @context. Only JSON-LD is read, and that is stated rather than treated as conformant. (0.13 USDC on Base)POST/x402/v1/json-schema-migration-impact— Decide whether a schema change is safe to ship, with evidence. Returns the compatibility verdict for your clients and, separately, how many of the real payloads you supply would newly be rejected, with the failing constraints ranked by how many payloads each costs. A breaking change nothing relies on is a different decision from one that rejects a tenth of your traffic. (0.22 USDC on Base)POST/x402/v1/openapi-parameter-contract-audit— Audit a real request against the OpenAPI document it should satisfy. Matches the operation the way a router would, checks every path, query and header parameter against its declared schema, validates the body against the declared media type, and reports whether the credential the declared security scheme expects is present. You supply the request, so this works against an API nothing external can reach. (0.14 USDC on Base)POST/x402/v1/ci-workflow-contract-audit— Audit a CI workflow for what it leaves movable or undeclared. Reports actions pinned to a tag rather than a commit - a tag can be moved by whoever owns the action, so the code a step runs can change without this file changing - missing permissions and timeouts, a job depending on one that is not declared, a pull_request_target trigger, and an expression interpolated straight into a shell command. (0.12 USDC on Base)POST/x402/v1/api-response-contract-audit— Audit an HTTP response you captured against a contract you declare: expected status or status class, required and forbidden headers, header value rules, and a body schema. Header names compare case-insensitively. You supply the response, so this works against an API behind authentication or on a private network. (0.12 USDC on Base)POST/x402/v1/pagination-contract-audit— Audit a pagination contract for the ways it loses or repeats rows. The central finding is the one almost every paginated API has at first: a sort on a non-unique field with no unique tiebreaker, so rows that compare equal have no defined order and a caller walking the pages can get one row twice and never get its neighbour, with nothing failing. Also reports offset pagination over a mutable sort, an unbounded page size, contradictory bounds, and a cursor contract that also takes an offset. (0.24 USDC on Base)POST/x402/v1/x402-endpoint-health— Is this paid endpoint answering right now? Returns whether it serves a payment challenge, how many well-formed priced offers it carries, which warnings would actually break a payment as opposed to merely making the call harder to construct, and a single payable_now flag. Reports only what was observed; it makes no judgement about the seller. (0.004 USDC on Base)POST/x402/v1/oauth-client-registration-audit— Audit an OAuth client registration. Reports a wildcard redirect URI, where any matching host receives authorization codes; a plaintext redirect outside loopback; a registered URI that carries its own redirect parameter, so a code can be forwarded off the client's origin while still matching; the implicit and password grants; a public client registering a grant that needs a secret; and a client secret committed into the registration document itself. No secret value is ever reported. (0.3 USDC on Base)POST/x402/v1/sql-migration-blast-radius— Read migration statements and report what each one touches and what it costs. Names the statements that rewrite a table, the ones that scan every row while holding a lock, the ones that discard data irreversibly, and the renames that break every client still deployed with the old name the instant they commit. Reports tables and columns touched so a reviewer can see the reach of a migration without reading every statement. (0.3 USDC on Base)
+284 more endpoints.
First seen · last seen · last active