View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
View true402's full-sized avatar

Block or report true402

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
true402/README.md

true402

A machine-native marketplace where agents buy and sell services using HTTP 402 micropayments. No accounts. No API keys. No signup. No KYC. Wallet = identity.

The internet solved information exchange but left value exchange broken — intermediaries, accounts, KYC. x402 fixes payment at the protocol level, and true402 is a marketplace built on that fix: 27 live services, each priced per call in USDC on Base, each discoverable and payable by an agent with no human in the loop.

Live now at true402.dev · catalog · OpenAPI · MCP manifest

# no key, no account — the first few calls each day are free
curl -X POST https://true402.dev/api/v1/base/token-safety \
-H 'content-type: application/json' -d '{"token":"0x4200000000000000000000000000000000000006"}'

The two that matter most

Everything here is read-only and pay-per-call, but these two answer questions nothing else can, because they are built on a chain archive we have been keeping rather than a query anyone can run.

POST /v1/base/tx-preflight — check a transaction before you sign it · $0.008

Send an unsigned transaction and get three independent lenses:

  1. Does it revert? — simulated against current state. The largest single class of agent failure.
  2. What does it authorise? — the calldata decoded. An agent that cannot read a selector cannot tell transfer from approve(spender, 2²⁵⁶−1) — an unbounded claim on its balance that outlives the trade by design.
  3. Who is on the other side? — the counterparty checked against our liquidity-removal archive, including the other tokens drained in the same transactions.

It takes no private key and no signature.eth_call asserts the sender rather than proving it, so no signature is needed to learn what a transaction would do — and a preflight service that could sign would be a more attractive target than the transaction it was asked to inspect. There is no key material in the request, so it cannot broadcast, front-run, or lose custody of anything.

It never returns "safe". A clean result is risk: none-observed, and every response carries the limits that answer is subject to.

POST /v1/base/liquidity-history — what already happened · $0.005

Every liquidity-removal event we have observed on a Base token, with the amount, block and transaction hash so you can verify any row on-chain yourself — plus the other tokens drained in the same transaction, which is operator linkage with no heuristics behind it.

A live honeypot simulation structurally cannot see this: a pool drained last month simulates perfectly today if someone re-seeded it. You either recorded it as it happened or you do not have it.

Every answer carries the exact block range our removal index covers, so "none observed" is never dressed up as "safe". Live coverage: /v1/chain-coverage (free, no payment).

The rest of the floor

ServicePriceWhat it does
/v1/base/token-safety$0.005ERC-20 rug/honeypot pre-check → score, flags, liquidity depth + a gas-free buy/sell simulation
/v1/base/token-report$0.01The composite: safety + live rug/whale activity → one avoid/caution/ok verdict
/v1/base/address-safety$0.005What is this counterparty — EOA or contract, upgradeable proxy, ownership, balances
/v1/base/deployer-check$0.008Deployer reputation — wallet age and history behind a contract
/v1/base/new-pairs$0.003Newly created Base DEX pairs — fresh launches, as they happen
/v1/base/liquidity-pulls$0.003Liquidity-removal alerts on tracked pools
/v1/base/whale-swaps$0.005Large swaps by USD size — whale flow
/v1/prediction-markets$0.005Cross-venue search (Polymarket, Limitless, Manifold)
/v1/defi-yields$0.005Pool APY/TVL across lending and LST protocols
/v1/quant$0.003Pure-computation finance calculators (Black-Scholes, sizing, risk)
/v1/seo-audit$0.04/pageSEO + GEO (generative-engine) audit → structured report
/v1/screenshot$0.01Render a page to PNG behind an SSRF-filtered egress proxy
/v1/web-extract$0.005URL → clean text, markdown, links, metadata
/v1/link-preview$0.003URL → Open Graph / unfurl card
/v1/robots-check$0.003A site's AI-crawler policy (GPTBot, ClaudeBot, …) + sitemaps + llms.txt
/v1/headers-check$0.003HTTP security-header analysis + score
/v1/base/dossier$0.10The full pre-trade dossier — token-report plus deployer reputation and the durable archive
/v1/backlinks$0.10A domain's link graph — referring domains, the dofollow split that carries authority, spam score
/v1/keyword-volume$0.15Search volume, CPC and 12-month trend for up to 200 keywords in ONE call — priced per call, not per keyword
/v1/ranked-keywords$0.05The keywords a domain already ranks for, with position and the URL that ranks
/v1/keyword-ideas$0.05Long-tail keyword ideas from a seed term, with volume and search intent
/v1/chat/completionscost + 3%OpenAI-compatible inference across many models

Multi-chain:token-safety, token-report and address-safety are also mounted per chain at /v1/{ethereum,bsc}/…, and Solana has its own non-EVM path at /v1/solana/token-safety. The full, always-current list is the catalog — this table is written by hand and the API is authoritative.

Use it from an agent

PackageInstall
MCP server (Claude, and any MCP client)npx -y @true402.dev/mcp-server
LangChain toolsnpm i @true402.dev/langchain
Vercel AI SDK toolsnpm i @true402.dev/ai-sdk
Coinbase AgentKit actionsnpm i @true402.dev/agentkit
ElizaOS pluginnpm i elizaos-plugin-true402
CrewAI toolspip install crewai-true402
GAME (Virtuals) functionspip install game-true402
Terminal / CInpx @true402.dev/rugcheck 0x… [--history]

The MCP server discovers stalls from the live OpenAPI spec at startup, so a new service on the marketplace becomes a tool in your agent with no package update. The others carry an explicit tool list, so they gain new stalls on their next release.

An OpenClaw / Hermes skill is published too: openclaw skills install true402-token-safety.

The x402 flow

  1. Agent POSTs without payment → 402 with payment requirements.
  2. Agent signs a USDC authorization (Base, EIP-3009) and retries with an X-PAYMENT header.
  3. Server verifies via a no-KYC facilitator → serves the response → settles on-chain, async.

The rules that surprise people writing their own payer:

  • Pay the exact amount, not >=. Settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Overpayment is refused with 403 and never credited; underpayment is rejected. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only on a 2xx — if the endpoint errors or times out, your signed authorization is never submitted, so there is nothing to refund.

Full rules: true402.dev/terms. What is logged and kept — no cookies, no analytics, IPs stored only as a salted hash for the free-trial quota: true402.dev/privacy. See the API reference for the full endpoint list.

Payments & anonymity

  • Rail: USDC on Base (EIP-3009). Network and facilitator are env-driven.
  • No-KYC by design: the facilitator is self-hosted (src/facilitator) or another no-KYC one. Coinbase CDP is deliberately not used — a CDP account is an operator identity.
  • Lightning (BTC via BOLT11) is an optional second rail, off by default.
  • Free to list. Ranked by settlement history, not by payment to be listed.

Safety controls

  • CHAT_DISABLED / STALLS_DISABLED — instant kill switches.
  • MAX_REQUEST_PRICE_USD, DAILY_SPEND_CAP_USD — blast-radius caps.
  • SSRF guards on registration and on every outbound fetch; the render sidecar egresses only through a filtering proxy on an internal network.
  • Single-use payment authorizations, enforced atomically — a signed authorization cannot be replayed.

Docs

  • API.md — every endpoint, price and request body, generated from the live OpenAPI spec
  • OpenAPI — authoritative, machine-readable
  • llms.txt — plain-text summary for browsing LLMs
  • Catalog — the live floor, fetched from the running registry
  • Terms of trade · Privacy — what paying agrees to, and exactly what is retained. Written for the agent deciding whether to spend.

Machine discovery

Everything an agent needs is served without a human in the loop:

DocumentPurpose
/.well-known/x402-manifest.jsonx402 service catalog
/.well-known/mcp.jsonMCP tools → endpoints
/.well-known/ai-plugin.jsonOpenAI plugin descriptor
/.well-known/x402-service.jsonour own service descriptor
/openapi.jsonfull OpenAPI 3.1
/v1/chain-coveragehow much Base history actually backs the archive stalls

Popular repositories Loading

  1. x402scan x402scanPublic

    Forked from Merit-Systems/x402scan

    x402 Ecosystem Explorer

    TypeScript

  2. mcp-server mcp-serverPublic

    MCP server for true402 — pay-per-call AI + web + on-chain tools over x402 (USDC on Base). No accounts, no API keys; the agent's wallet is its identity. 11 tools incl. token rug/honeypot safety.

    TypeScript

  3. awesome-mcp-servers awesome-mcp-serversPublic

    Forked from punkpeye/awesome-mcp-servers

    A collection of MCP servers.

  4. awesome-mcp-servers-wong2 awesome-mcp-servers-wong2Public

    Forked from wong2/awesome-mcp-servers

    A curated list of Model Context Protocol (MCP) servers

  5. awesome-x402 awesome-x402Public

    Forked from xpaysh/awesome-x402

    🚀 Curated list of x402 resources: HTTP 402 Payment Required protocol for blockchain payments, crypto micropayments, AI agents, API monetization. Includes SDKs (TypeScript, Python, Rust), examples, …

  6. x402 x402Public

    Forked from coinbase/x402

    A payments protocol for the internet. Built on HTTP.

    TypeScript