Paste a paid endpoint's URL. I send it one unpaid request and grade the 402 it sends back.
Nothing is stored. One request to the URL you give, plus a read of /openapi.json and
/.well-known/x402.json at the same origin. Private / link-local targets are refused.
If the route only meters one method, switch GET/POST and retry.
PAYMENT-REQUIRED header present and base64-decodes to JSONx402Version: 2 (number), top-level resource objectaccepts[]: scheme:"exact", CAIP-2 network, atomic-unit amount string, checksummed asset / payToextensions.bazaar.schema input/output blocks at the exact nesting x402scan readsx-payment-info operation, info.x-guidance, a documented 402This is an independent, best-effort checker based on the published
x402scan discovery spec and the x402 v2 specification. It is
not the official @agentcash/discovery tool — run that too before you submit a listing:
npx -y @agentcash/discovery@latest discover <your-origin>.