{"id":11922,"name":"x402lint","description":"x402lint scans an x402 seller origin end-to-end: 402 challenge validity, accepts[] schema, price integrity, OpenAPI x402 conventions, agent docs surface, robots policy, favicon, and live standing on x402scan and Bazaar. Returns an A-F grade with per-check evidence and one-line fixes. 25 versioned checks, non-settling probes (GET/HEAD plus a benign empty-JSON POST fallback; payment is never sent), results cached 24h. Cached full reports are free; a paid $0.05 scan forces a fresh run. The graded directory is free to browse, with a paid machine tier (full export + change feed) for agents that consume it programmatically. Built by the Hexanon fleet, which runs seven live x402 products.","card_url":"https://api.x402lint.dev/.well-known/agent-card.json","endpoint":"https://api.x402lint.dev/a2a","protocol_version":"0.3.0","first_seen":"2026-10-10T13:31:24.763538+00:00","last_verified":"2026-10-10T16:22:51.411706+00:00","card":{"url":"https://api.x402lint.dev/a2a","name":"x402lint","x402":{"assets":["USDC"],"version":2,"networks":["eip155:8453"]},"skills":[{"id":"scan","name":"Priority fresh re-scan","tags":["x402lint","scan"],"priceUsd":0.05,"description":"Paid ($0.05). ALWAYS runs a fresh 25-check scan of the origin (non-settling GET/HEAD + benign empty-POST probes), bypassing the 24h cache — use free GET /v1/report to read the cached result. Concurrent requests for the same origin join the in-flight scan rather than double-scanning. Returns grade, score, per-check status + evidence + fix instructions, and a shareable report URL. Unreachable/broken origins are a valid graded result (F). 504 processing responses and errors are never charged."},{"id":"export","name":"Full directory export (machine tier)","tags":["x402lint","export"],"priceUsd":0.1,"description":"Paid ($0.10). The entire graded directory in one machine-shaped response: every listed origin with grade, score, grade history, legitimacy signals, branding, verification and featured status — the same record shape as /v1/directory plus gradeHistory, firstSeenAt, and scanCount. Capped at 10,000 records (truncated:true if hit). Grades measure protocol conformance only and are NOT endorsements."},{"id":"changes","name":"Directory change feed","tags":["x402lint","changes"],"priceUsd":0.03,"description":"Paid ($0.03). Everything that changed in the graded directory since a timestamp: newly listed origins (changeType \"new\"), grade changes (\"grade_changed\", with previousGrade/previousScore), and plain re-scans (\"rescanned\"). Poll this to keep a local copy of the directory fresh without re-buying the full export. An invalid since/limit is an uncharged 400."}],"version":"0.3.0","provider":{"url":"https://api.x402lint.dev","organization":"x402lint"},"endpoints":[{"path":"/v1/status","method":"GET","params":["url"],"priceUsd":0,"description":"Free. Returns whether an origin has been scanned, scan freshness, and the grade summary (grade, score, pass/warn/fail counts) — no per-check findings. Real data from prior scans; full findings are free at GET /v1/report while a fresh result exists; POST /v1/scan runs a fresh scan."},{"path":"/v1/checks","method":"GET","params":[],"priceUsd":0,"description":"Free. The full conformance check catalog: every check's id, title, severity, and category, plus category summaries. Per-origin results (pass/warn/fail, evidence, one-line fixes) are delivered by the paid scan (POST /v1/scan) and cached report (GET /v1/report)."},{"path":"/v1/scan","method":"POST","params":["url"],"priceUsd":0.05,"description":"Paid ($0.05). ALWAYS runs a fresh 25-check scan of the origin (non-settling GET/HEAD + benign empty-POST probes), bypassing the 24h cache — use free GET /v1/report to read the cached result. Concurrent requests for the same origin join the in-flight scan rather than double-scanning. Returns grade, score, per-check status + evidence + fix instructions, and a shareable report URL. Unreachable/broken origins are a valid graded result (F). 504 processing responses and errors are never charged."},{"path":"/v1/report","method":"GET","params":["url"],"priceUsd":0,"description":"Free. Returns the full cached scan report (same shape as POST /v1/scan) if a fresh (<24h) result exists; otherwise an uncharged 404 pointing at POST /v1/scan. The zero-cost way to read any origin's latest findings — scan reports land here for 24h."},{"path":"/v1/directory/export","method":"GET","params":[],"priceUsd":0.1,"description":"Paid ($0.10). The entire graded directory in one machine-shaped response: every listed origin with grade, score, grade history, legitimacy signals, branding, verification and featured status — the same record shape as /v1/directory plus gradeHistory, firstSeenAt, and scanCount. Capped at 10,000 records (truncated:true if hit). Grades measure protocol conformance only and are NOT endorsements."},{"path":"/v1/changes","method":"GET","params":["since","limit"],"priceUsd":0.03,"description":"Paid ($0.03). Everything that changed in the graded directory since a timestamp: newly listed origins (changeType \"new\"), grade changes (\"grade_changed\", with previousGrade/previousScore), and plain re-scans (\"rescanned\"). Poll this to keep a local copy of the directory fresh without re-buying the full export. An invalid since/limit is an uncharged 400."},{"path":"/v1/directory","method":"GET","params":["sort","category","verified","q","page","pageSize"],"priceUsd":0,"description":"Free. Paginated list of origins x402lint has scanned and graded, with conformance grade, auto-collected UNVERIFIED third-party branding, and ecosystem legitimacy signals. Sort by recency (default) or grade; filter by category, verification, or host substring. A grade measures protocol conformance only and is NOT an endorsement or a safety/legitimacy assessment. hasRecentSettlement is true or null (null = not observed in a bounded most-active-sellers walk, not proof of no settlements)."},{"path":"/v1/featured","method":"GET","params":[],"priceUsd":0,"description":"Free. Origins that scored an A on their most recent scan within the last 30 days, recency-ranked. Featured placement is a free consequence of a recent A-grade scan; it expires 30 days after the scan (re-scan to refresh). Conformance only — NOT an endorsement. hasRecentSettlement is true or null (null = not observed in a bounded most-active-sellers walk, not proof of no settlements)."},{"path":"/v1/project","method":"GET","params":["host"],"priceUsd":0,"description":"Free. The public directory record for one origin (grade, branding, legitimacy signals, verification + featured status). 404 uncharged if the origin is unknown or has opted out. hasRecentSettlement is true or null (null = not observed in a bounded most-active-sellers walk, not proof of no settlements)."},{"path":"/v1/verify/start","method":"POST","params":["url"],"priceUsd":0,"description":"Free. Begin domain-control verification of an origin you operate. Returns a one-time token to place at /.well-known/x402lint-challenge on that origin, then call POST /v1/verify/confirm."},{"path":"/v1/verify/confirm","method":"POST","params":["url"],"priceUsd":0,"description":"Free. x402lint fetches /.well-known/x402lint-challenge over HTTPS and, if it matches the unexpired token from /v1/verify/start, marks the origin owner-verified."},{"path":"/v1/listing","method":"POST","params":["url","listed","suppressEnrichment"],"priceUsd":0,"description":"Free. For owner-verified origins only (else 403). Opt the origin out of the public directory (listed=false) and/or suppress auto-collected branding (suppressEnrichment=true)."}],"openApiUrl":"https://api.x402lint.dev/openapi.json","description":"x402lint scans an x402 seller origin end-to-end: 402 challenge validity, accepts[] schema, price integrity, OpenAPI x402 conventions, agent docs surface, robots policy, favicon, and live standing on x402scan and Bazaar. Returns an A-F grade with per-check evidence and one-line fixes. 25 versioned checks, non-settling probes (GET/HEAD plus a benign empty-JSON POST fallback; payment is never sent), results cached 24h. Cached full reports are free; a paid $0.05 scan forces a fresh run. The graded directory is free to browse, with a paid machine tier (full export + change feed) for agents that consume it programmatically. Built by the Hexanon fleet, which runs seven live x402 products.","capabilities":{"streaming":false,"extensions":[{"uri":"https://github.com/google-a2a/a2a-x402/v0.1","params":{"asset":"USDC","scheme":"exact","networks":["eip155:8453"],"x402Version":2},"required":false,"description":"Paid endpoints settle via the x402 protocol (on-chain USDC). On an unpaid paid-route request the server returns HTTP 402 whose accepts[] lists one exact USDC rail per network; sign one rail and retry with PAYMENT-SIGNATURE (x402 V2) or X-PAYMENT (legacy). Free endpoints need no payment."}],"pushNotifications":false,"stateTransitionHistory":false},"authentication":{"schemes":["none","x402"],"description":"Free endpoints need no auth. Paid endpoints use the x402 V2 HTTP-402 flow: on an unpaid request the server returns a 402 whose accepts[] lists an exact USDC rail per network. Sign one rail and retry with the PAYMENT-SIGNATURE header (x402 V2) or legacy X-PAYMENT header. Per-call pricing."},"termsOfService":"https://api.x402lint.dev/terms.txt","protocolVersion":"0.3.0","documentationUrl":"https://api.x402lint.dev/llms.txt","defaultInputModes":["application/json"],"defaultOutputModes":["application/json"],"preferredTransport":"JSONRPC"},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-10T16:22:51.411706+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Agent Tools Catalog","source_url":"https://agent-tools.cloud","last_check":{"checked_at":"2026-10-10T16:22:51.411706+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://api.x402lint.dev/.well-known/agent-card.json"],"skills":[{"skill_id":"changes","name":"Directory change feed","description":"Paid ($0.03). Everything that changed in the graded directory since a timestamp: newly listed origins (changeType \"new\"), grade changes (\"grade_changed\", with previousGrade/previousScore), and plain re-scans (\"rescanned\"). Poll this to keep a local copy of the directory fresh without re-buying the full export. An invalid since/limit is an uncharged 400.","tags":["x402lint","changes"],"quality_warning":false},{"skill_id":"export","name":"Full directory export (machine tier)","description":"Paid ($0.10). The entire graded directory in one machine-shaped response: every listed origin with grade, score, grade history, legitimacy signals, branding, verification and featured status — the same record shape as /v1/directory plus gradeHistory, firstSeenAt, and scanCount. Capped at 10,000 records (truncated:true if hit). Grades measure protocol conformance only and are NOT endorsements.","tags":["x402lint","export"],"quality_warning":false},{"skill_id":"scan","name":"Priority fresh re-scan","description":"Paid ($0.05). ALWAYS runs a fresh 25-check scan of the origin (non-settling GET/HEAD + benign empty-POST probes), bypassing the 24h cache — use free GET /v1/report to read the cached result. Concurrent requests for the same origin join the in-flight scan rather than double-scanning. Returns grade, score, per-check status + evidence + fix instructions, and a shareable report URL. Unreachable/broken origins are a valid graded result (F). 504 processing responses and errors are never charged.","tags":["x402lint","scan"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":2,"passed":2},"recent_checks":[{"card_url":"https://api.x402lint.dev/.well-known/agent-card.json","checked_at":"2026-10-10T16:22:51.411706+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://api.x402lint.dev/.well-known/agent-card.json","checked_at":"2026-10-10T13:31:24.763538+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T16:22:51.411706+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T13:31:24.763538+00:00","state":"a2a_response","http_status":200,"detail":"A2A task-not-found response to a read-only task lookup"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://api.x402lint.dev/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T16:22:51.411706+00:00","latest_card_check":{"checked_at":"2026-10-10T16:22:51.411706+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-10T16:22:51.411706+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T16:22:51.411706+00:00","endpoint_tls_reachable":true,"protocol_check_state":"a2a_response","protocol_checked_at":"2026-10-10T13:31:24.763538+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}