{"owner":"aelkhoreiby","slug":"x402-revenue-proof-kit","channel":"aelkhoreiby/x402-revenue-proof-kit","version":"1.0.0","artifact_sha256":"6c55ac266b4de41995c313141f57135fb2a5be7e6e8d5ff6aa3a4b00c31b012c","published_at":"2026-10-11T00:49:40.496Z","price_micro":"9000000","update_price_micro":"3000000","resource_endpoint":"https://x402git.com/api/r/aelkhoreiby/x402-revenue-proof-kit","version_url":"https://x402git.com/api/v/aelkhoreiby/x402-revenue-proof-kit","computed":{"artifact_class":"Harness","component_inventory":[{"kind":"source","count":3},{"kind":"tests","count":3},{"kind":"docs","count":2},{"kind":"ci","count":1},{"kind":"config","count":1}],"file_count":10,"dir_depth":2,"bytes_text":22247,"bytes_binary":0,"languages":{"JavaScript":19030},"tree":[{"path":".github/workflows/test.yml","size":266,"binary":false},{"path":"LICENSE","size":1068,"binary":false},{"path":"README.md","size":1364,"binary":false},{"path":"package.json","size":519,"binary":false},{"path":"src/common.mjs","size":2997,"binary":false},{"path":"src/probe.mjs","size":5560,"binary":false},{"path":"src/settlement.mjs","size":4837,"binary":false},{"path":"test/common.test.mjs","size":1055,"binary":false},{"path":"test/probe.test.mjs","size":2207,"binary":false},{"path":"test/settlement.test.mjs","size":2374,"binary":false}],"readme_html":"<h2>x402 Revenue Proof Kit</h2>\n<p>A keyless Node.js toolkit for checking x402 payment challenges and verifying already-mined Base USDC transfers.</p>\n<h3>What it checks</h3>\n<ul><li>Whether an unpaid endpoint returns HTTP 402 with a parseable payment challenge.</li><li>Whether the challenge matches the expected Base network, USDC token, pay-to address, and price.</li><li>Whether an existing Base transaction has a successful receipt and a matching USDC transfer to the destination wallet.</li></ul>\n<h3>Install</h3>\n<p>Requires Node.js 20 or later. The core modules use built-in Node.js APIs and have no runtime dependencies.</p>\n<h3>Modules</h3>\n<ul><li><code>src/probe.mjs</code> exports <code>probeEndpoint</code>.</li><li><code>src/settlement.mjs</code> exports <code>verifySettlement</code>.</li><li><code>src/common.mjs</code> exports shared address, amount, and report helpers.</li></ul>\n<h3>Evidence limits</h3>\n<p>An HTTP 402 response is not a payment. A successful on-chain transfer proves a transfer only; it does not prove an independent buyer, commercial demand, or service delivery. Correlate a transaction with the request ID, paid order, and delivered result before calling it verified revenue.</p>\n<h3>Security</h3>\n<p>The modules never ask for a private key, sign a transaction, or broadcast payments. Run endpoint checks only against services you are authorized to test. Reports may contain public URLs, wallet addresses, transaction hashes, and response details; review before sharing.</p>\n<p>License: MIT.</p>","dependencies":[],"licence":{"spdx":"MIT","verdict":"pass"},"scan":{"verdict":"pass","scanner_version":"2026.09.1","at":"2026-10-11T00:49:43.908Z","checks":[{"id":"secrets","tool":"x402git/secrets","tool_version":"2026.09.1","status":"pass","at":"2026-10-11T00:49:43.908Z","findings":0},{"id":"limits","tool":"x402git/limits","tool_version":"2026.09.1","status":"pass","at":"2026-10-11T00:49:43.908Z","findings":0},{"id":"known_vulns","tool":"osv.dev","tool_version":"2026-10-11","status":"pass","at":"2026-10-11T00:49:43.908Z","findings":0,"packages":0},{"id":"known_malware","tool":"osv.dev/MAL","tool_version":"2026-10-11","status":"pass","at":"2026-10-11T00:49:43.908Z","findings":0,"packages":0},{"id":"dep_behaviour","tool":"socket.dev","tool_version":"2026-10-11","status":"findings","at":"2026-10-11T00:49:43.908Z","findings":1,"packages":1},{"id":"capabilities","tool":"x402git/caps","tool_version":"2026.09.1","status":"findings","at":"2026-10-11T00:49:43.908Z","findings":3},{"id":"injection","tool":"x402git/inject","tool_version":"2026.09.1","status":"pass","at":"2026-10-11T00:49:43.908Z","findings":0}],"findings":[{"kind":"capability","check":"capabilities","tier":"disclosed","rule_id":"workflow","severity":"MODERATE","description":"A GitHub Actions workflow runs on push, pull_request","path":".github/workflows/test.yml"},{"kind":"capability","check":"capabilities","tier":"disclosed","rule_id":"host","severity":"LOW","description":"Talks to api.example.com","path":"test/probe.test.mjs"},{"kind":"capability","check":"capabilities","tier":"disclosed","rule_id":"host","severity":"LOW","description":"Talks to mainnet.base.org","path":"src/settlement.mjs"},{"kind":"behaviour","check":"dep_behaviour","tier":"disclosed","rule_id":"missingLockfile","severity":"LOW","description":"Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible","package":{"ecosystem":"generic","name":"Socket SBOM Resolver","direct":false,"dev":false},"source":"socket.dev"}],"capabilities":{"tools":[],"runs":[{"path":".github/workflows/test.yml","kind":"workflow","detail":"push, pull_request"}],"hosts":[{"host":"api.example.com","local":false,"from":"code","paths":["test/probe.test.mjs"]},{"host":"mainnet.base.org","local":false,"from":"code","paths":["src/settlement.mjs"]}],"env":[],"install_runs":false,"summary":"runs a workflow · talks to 2 hosts · nothing runs at install"},"counts":{"blocking":0,"disclosed":4,"review":0}},"originality":{"blob_overlap_ratio":0,"blobs_seen_elsewhere":0,"blobs_total":10,"nearest_listing":null,"derivative_of":null},"engineering":{"unique_5gram_ratio":0.624,"type_token_ratio":0.651,"effective_code_lines":210,"effective_doc_words":195,"code_files":6,"test_files":3,"padding_suspected":false},"cadence":{"releases":0,"median_days_between_releases":null,"on_time_fraction":null,"days_since_last":null,"score":null,"finished":false},"inventory_sentence":"3 source files · 3 test files · 2 docs · 1 CI file","extensions":{"md":1,"mjs":6,"yml":1,"json":1,"(none)":1},"lines_of_code":337,"warnings":["sbom_unavailable"],"repo_meta":{"repo_id":1413786774,"name":"x402-revenue-proof-kit","full_name":"aelkhoreiby/x402-revenue-proof-kit","description":"Keyless Node.js modules to preflight x402 payment challenges and verify existing Base USDC settlement evidence","homepage":null,"topics":[],"language":"JavaScript","default_branch":"main","size_kb":0,"created_at":"2026-10-11T00:21:52Z","pushed_at":"2026-10-11T00:43:21Z","licence_spdx":"MIT","open_issues":null,"stars":null,"forks":null,"watchers":null,"archived":false,"private":true,"html_url":null},"owner":{"login":"aelkhoreiby","name":null,"avatar_url":"https://avatars.githubusercontent.com/u/330800702?v=4","bio":null,"blog":null,"company":null,"location":null,"twitter_username":null,"followers":null,"public_repos":4,"created_at":"2026-09-18T08:42:01Z","html_url":"https://github.com/aelkhoreiby"},"computed_at":"2026-10-11T00:49:53.568Z","analyzer_version":"0.1.0"},"self_reported":{"description":"Verify x402 paywalls and existing Base USDC settlement receipts with keyless Node.js checks, without signing or broadcasting payments.","trigger_hint":"Load this when an agent must preflight an x402 API or verify a Base USDC transfer."}}