X402 Git

x402-revenue-proof-kit

Verify x402 paywalls and existing Base USDC settlement receipts with keyless Node.js checks, without signing or broadcasting payments.

Top level of the repository
SizeFolderInside
13.4 kBsrc/3 source files
5.6 kBtest/3 test files
266 B.github/1 CI file
3 kB(root)2 docs · 1 config file
10 files · 22.2 kB · computed 2026-10-11
SizePath
266 B.github/workflows/test.yml
1.1 kBLICENSE
1.4 kBREADME.md
519 Bpackage.json
3 kBsrc/common.mjs
5.6 kBsrc/probe.mjs
4.8 kBsrc/settlement.mjs
1.1 kBtest/common.test.mjs
2.2 kBtest/probe.test.mjs
2.4 kBtest/settlement.test.mjs
computed 2026-10-11 00:49 UTC · analyzer 0.1.0

Already bought this?

View your purchases

README

x402 Revenue Proof Kit

A keyless Node.js toolkit for checking x402 payment challenges and verifying already-mined Base USDC transfers.

What it checks

  • Whether an unpaid endpoint returns HTTP 402 with a parseable payment challenge.
  • Whether the challenge matches the expected Base network, USDC token, pay-to address, and price.
  • Whether an existing Base transaction has a successful receipt and a matching USDC transfer to the destination wallet.

Install

Requires Node.js 20 or later. The core modules use built-in Node.js APIs and have no runtime dependencies.

Modules

  • src/probe.mjs exports probeEndpoint.
  • src/settlement.mjs exports verifySettlement.
  • src/common.mjs exports shared address, amount, and report helpers.

Evidence limits

An HTTP 402 response is not a payment. A successful on-chain transfer proves a transfer only; it does not prove an independent buyer, commercial demand, or service delivery. Correlate a transaction with the request ID, paid order, and delivered result before calling it verified revenue.

Security

The modules never ask for a private key, sign a transaction, or broadcast payments. Run endpoint checks only against services you are authorized to test. Reports may contain public URLs, wallet addresses, transaction hashes, and response details; review before sharing.

License: MIT.

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
.github/workflows/test.yml (push, pull_request)
Talks to
  • api.example.com
  • mainnet.base.org
Reads
no environment variables
At install
nothing runs
Findings (4)
  • MODERATE.github/workflows/test.yml — A GitHub Actions workflow runs on push, pull_request
  • LOWtest/probe.test.mjs — Talks to api.example.com
  • LOWsrc/settlement.mjs — Talks to mainnet.base.org
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible

Releases 1

  1. v1.0.02026-10-11

    Test Base USDC receipt verification with mocked RPC data

$9updates $3

Buy — go to the order block