Check that every challenge you captured names the endpoint that served it
Check that every challenge you captured names the endpoint that served it. A challenge naming a different resource would, if paid, satisfy a requirement for something else. A host mismatch is reported differently from a path mismatch, the first being the stronger signal. Also reports a non-https resource and, under version 2, a bare string resource, where a client reading resource.url gets undefined and stops checking the binding. Nothing is fetched and nothing is paid.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/x402-resource-binding-audit
| Category | Code and developer |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-10-04 | no x402 terms | 429 | 253 ms |
Example input (from the provider)
{
"body": {
"expected_host": "api.merchant.test",
"observations": [
{
"challenge": {
"accepts": [
{
"amount": "5000",
"asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"network": "eip155:8453",
"payTo": "0xa1b2c30000000000000000000000000000009f8e",
"scheme": "exact"
}
],
"extensions": {
"bazaar": {
"schema": {
"properties": {
"input": {
"type": "object"
},
"output": {
"type": "object"
}
}
}
}
},
"resource": {
"description": "Paid resource at https://api.merchant.test/v1/score",
"mimeType": "application/json",
"url": "https://api.merchant.test/v1/score"
},
"x402Version": 2
},
"url": "https://api.merchant.test/v1/score"
},
{
"challenge": {
"accepts": [
{
"amount": "5000",
"asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"network": "eip155:8453",
"payTo": "0xa1b2c30000000000000000000000000000009f8e",
"scheme": "exact"
}
],
"extensions": {
"bazaar": {
"schema": {
"properties": {
"input": {
"type": "object"
},
"output": {
"type": "object"
}
}
}
}
},
"resource": {
"description": "Paid resource at https://api.merchant.test/v1/score",
"mimeType": "application/json",
"url": "https://api.merchant.test/v1/score"
},
"x402Version": 2
},
"url": "https://api.merchant.test/v1/enrich"
},
{
"challenge": {
"accepts": [
{
"amount": "5000",
"asset": "0x833589fcd6edb6e08f4c7c32d4f71b54bda02913",
"network": "eip155:8453",
"payTo": "0xffffffffffffffffffffffffffffffffffffffff",
"scheme": "exact"
}
],
"resource": "http://collector.elsewhere.test/v1/hijacked",
"x402Version": 2
},
"url": "https://api.merchant.test/v1/hijacked"
}
]
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"expected_host": {
"maxLength": 256,
"type": "string"
},
"observations": {
"items": {
"additionalProperties": false,
"properties": {
"challenge": {},
"url": {
"maxLength": 2048,
"type": "string"
}
},
"required": [
"url",
"challenge"
],
"type": "object"
},
"maxItems": 200,
"minItems": 1,
"type": "array"
},
"require_https": {
"type": "boolean"
}
},
"required": [
"observations"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}