X402 Git

aelkhoreiby/x402-revenue-proof-kit · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Harness · 3 source files · 3 test files · 2 docs · 1 CI file · 1 config file · 10 files · text 22.2 kB · no binaries · JavaScript 100% · MIT, resale permitted

scan passed 2026-10-11 · scanner 2026.09.1 · 1 release · last release today · 0% of files seen elsewhere

computed 2026-10-11 00:49 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
.github/workflows/test.yml (push, pull_request)
Talks to
  • api.example.com
  • mainnet.base.org
Reads
no environment variables
At install
nothing runs
Findings (4)
  • MODERATE.github/workflows/test.yml — A GitHub Actions workflow runs on push, pull_request
  • LOWtest/probe.test.mjs — Talks to api.example.com
  • LOWsrc/settlement.mjs — Talks to mainnet.base.org
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Verify x402 paywalls and existing Base USDC settlement receipts with keyless Node.js checks, without signing or broadcasting payments.

When to use it. Load this when an agent must preflight an x402 API or verify a Base USDC transfer.

Readme

x402 Revenue Proof Kit

A keyless Node.js toolkit for checking x402 payment challenges and verifying already-mined Base USDC transfers.

What it checks

  • Whether an unpaid endpoint returns HTTP 402 with a parseable payment challenge.
  • Whether the challenge matches the expected Base network, USDC token, pay-to address, and price.
  • Whether an existing Base transaction has a successful receipt and a matching USDC transfer to the destination wallet.

Install

Requires Node.js 20 or later. The core modules use built-in Node.js APIs and have no runtime dependencies.

Modules

  • src/probe.mjs exports probeEndpoint.
  • src/settlement.mjs exports verifySettlement.
  • src/common.mjs exports shared address, amount, and report helpers.

Evidence limits

An HTTP 402 response is not a payment. A successful on-chain transfer proves a transfer only; it does not prove an independent buyer, commercial demand, or service delivery. Correlate a transaction with the request ID, paid order, and delivered result before calling it verified revenue.

Security

The modules never ask for a private key, sign a transaction, or broadcast payments. Run endpoint checks only against services you are authorized to test. Reports may contain public URLs, wallet addresses, transaction hashes, and response details; review before sharing.

License: MIT.

Contents

10 files · 22.2 kB · computed 2026-10-11
SizePath
266 B.github/workflows/test.yml
1.1 kBLICENSE
1.4 kBREADME.md
519 Bpackage.json
3 kBsrc/common.mjs
5.6 kBsrc/probe.mjs
4.8 kBsrc/settlement.mjs
1.1 kBtest/common.test.mjs
2.2 kBtest/probe.test.mjs
2.4 kBtest/settlement.test.mjs
computed 2026-10-11 00:49 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-10-11 00:49 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-10-11pass—Test Base USDC receipt verification with mocked RPC data

Machine-readable at https://x402git.com/api/v/aelkhoreiby/x402-revenue-proof-kit/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $9 · new releases $3

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/aelkhoreiby/x402-revenue-proof-kit \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit",
    "description": "aelkhoreiby/x402-revenue-proof-kit v1.0.0 — release. Verify x402 paywalls and existing Base USDC settlement receipts with keyless Node.js checks, without signing or broadcasting payments. Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "x402-revenue-proof-kit",
    "tags": [
      "harness",
      "source",
      "tests",
      "docs",
      "ci"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "9000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "9000000",
      "resource": "https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit",
      "description": "aelkhoreiby/x402-revenue-proof-kit v1.0.0 — release. Verify x402 paywalls and existing Base USDC settlement receipts with keyless Node.js checks, without signing or broadcasting payments. Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/aelkhoreiby/x402-revenue-proof-kit/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/aelkhoreiby/x402-revenue-proof-kit",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/aelkhoreiby/x402-revenue-proof-kit",
    "scan_badge_url": "https://x402git.com/api/label/aelkhoreiby/x402-revenue-proof-kit#scan",
    "update_price_micro": "3000000",
    "quote_id": "q_7aa00acb95fb243f1852310087b55e42",
    "valid_before": "2026-10-11T02:37:45.688Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/aelkhoreiby/x402-revenue-proof-kit, and the free manifest at https://x402git.com/api/label/aelkhoreiby/x402-revenue-proof-kit shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/aelkhoreiby/x402-revenue-proof-kit",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit
Manifest
https://x402git.com/api/label/aelkhoreiby/x402-revenue-proof-kit
Version
https://x402git.com/api/v/aelkhoreiby/x402-revenue-proof-kit
Artifact sha256
6c55ac266b4de41995c313141f57135fb2a5be7e6e8d5ff6aa3a4b00c31b012c

Later releases cost $3, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by aelkhoreiby. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.