x402-revenue-proof-kit
Verify x402 paywalls and existing Base USDC settlement receipts with keyless Node.js checks, without signing or broadcasting payments.
| Size | Folder | Inside |
|---|---|---|
| 13.4 kB | src/ | 3 source files |
| 5.6 kB | test/ | 3 test files |
| 266 B | .github/ | 1 CI file |
| 3 kB | (root) | 2 docs · 1 config file |
| Size | Path |
|---|---|
| 266 B | .github/workflows/test.yml |
| 1.1 kB | LICENSE |
| 1.4 kB | README.md |
| 519 B | package.json |
| 3 kB | src/common.mjs |
| 5.6 kB | src/probe.mjs |
| 4.8 kB | src/settlement.mjs |
| 1.1 kB | test/common.test.mjs |
| 2.2 kB | test/probe.test.mjs |
| 2.4 kB | test/settlement.test.mjs |
Already bought this?
View your purchasesREADME
x402 Revenue Proof Kit
A keyless Node.js toolkit for checking x402 payment challenges and verifying already-mined Base USDC transfers.
What it checks
- Whether an unpaid endpoint returns HTTP 402 with a parseable payment challenge.
- Whether the challenge matches the expected Base network, USDC token, pay-to address, and price.
- Whether an existing Base transaction has a successful receipt and a matching USDC transfer to the destination wallet.
Install
Requires Node.js 20 or later. The core modules use built-in Node.js APIs and have no runtime dependencies.
Modules
src/probe.mjsexportsprobeEndpoint.src/settlement.mjsexportsverifySettlement.src/common.mjsexports shared address, amount, and report helpers.
Evidence limits
An HTTP 402 response is not a payment. A successful on-chain transfer proves a transfer only; it does not prove an independent buyer, commercial demand, or service delivery. Correlate a transaction with the request ID, paid order, and delivered result before calling it verified revenue.
Security
The modules never ask for a private key, sign a transaction, or broadcast payments. Run endpoint checks only against services you are authorized to test. Reports may contain public URLs, wallet addresses, transaction hashes, and response details; review before sharing.
License: MIT.
Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- no dependency manifests to check
- OSV
- known vulnerabilities
- no dependency manifests to check
- OSV
- dependency behaviour
- nothing on a direct dependency · 1 in transitive packages
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- listed below
- X402 Git
What this can do
- Tools
- none
- Runs
- .github/workflows/test.yml (push, pull_request)
- Talks to
- api.example.com
- mainnet.base.org
- Reads
- no environment variables
- At install
- nothing runs
Findings (4)
- MODERATE.github/workflows/test.yml — A GitHub Actions workflow runs on push, pull_request
- LOWtest/probe.test.mjs — Talks to api.example.com
- LOWsrc/settlement.mjs — Talks to mainnet.base.org
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
Releases 1
- v1.0.02026-10-11
Test Base USDC receipt verification with mocked RPC data