Audit a merchant estate across all its endpoints at once
Audit a merchant estate across all its endpoints at once. The findings that matter are the ones no single-challenge check can see: endpoints paying different addresses, sitting on different networks, or declaring different protocol versions. Also checks each challenge against a contract you declare - expected payee, network, asset, host and price ceiling. Nothing is fetched, so this works on a merchant you do not control.
Answers HTTP 429 without x402 payment termsour last check, 2026-10-04
0 of 1checks answered this week
n/amedian answer time
$0.18listed price per call
n/aprice it asked us
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/x402-merchant-contract-audit
| Category | Code and developer |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-10-04 | no x402 terms | 429 | 254 ms |
Example input (from the provider)
{
"body": {
"challenges": [
{
"challenge": {
"accepts": [
{
"amount": "5000",
"asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"network": "eip155:8453",
"payTo": "0xa1b2c30000000000000000000000000000009f8e",
"scheme": "exact"
}
],
"extensions": {
"bazaar": {
"schema": {
"properties": {
"input": {
"type": "object"
},
"output": {
"type": "object"
}
}
}
}
},
"resource": {
"description": "Paid resource at https://api.merchant.test/v1/score",
"mimeType": "application/json",
"url": "https://api.merchant.test/v1/score"
},
"x402Version": 2
},
"url": "https://api.merchant.test/v1/score"
},
{
"challenge": {
"accepts": [
{
"amount": "12000",
"asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"network": "eip155:8453",
"payTo": "0xa1b2c30000000000000000000000000000009f8e",
"scheme": "exact"
}
],
"extensions": {
"bazaar": {
"schema": {
"properties": {
"input": {
"type": "object"
},
"output": {
"type": "object"
}
}
}
}
},
"resource": {
"description": "Paid resource at https://api.merchant.test/v1/enrich",
"mimeType": "application/json",
"url": "https://api.merchant.test/v1/enrich"
},
"x402Version": 2
},
"url": "https://api.merchant.test/v1/enrich"
},
{
"challenge": {
"accepts": [
{
"amount": "90000",
"asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"network": "eip155:1",
"payTo": "0xffffffffffffffffffffffffffffffffffffffff",
"scheme": "exact"
}
],
"extensions": {},
"resource": {
"description": "Paid resource at https://legacy.merchant.test/v1/stale",
"mimeType": "application/json",
"url": "https://legacy.merchant.test/v1/stale"
},
"x402Version": 1
},
"url": "https://legacy.merchant.test/v1/stale"
}
],
"contract": {
"expected_asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"expected_host": "api.merchant.test",
"expected_network": "eip155:8453",
"expected_payee": "0xa1b2c30000000000000000000000000000009f8e",
"max_amount_atomic": "20000"
}
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"challenges": {
"items": {},
"maxItems": 200,
"minItems": 1,
"type": "array"
},
"contract": {
"additionalProperties": false,
"properties": {
"expected_asset": {
"maxLength": 128,
"type": "string"
},
"expected_host": {
"maxLength": 256,
"type": "string"
},
"expected_network": {
"maxLength": 128,
"type": "string"
},
"expected_payee": {
"maxLength": 128,
"type": "string"
},
"max_amount_atomic": {},
"require_schemas": {
"type": "boolean"
}
},
"type": "object"
}
},
"required": [
"challenges"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}