X402 Git

genesiscode2026/icp-multi-exchange-price-oracle · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Pack · 1 source file · 1 test file · 12 docs · 5 config files · 1 asset · 1 other file · 21 files · text 70 kB · binary 1.4 kB (2%) · Rust 100% · licence undetermined

scan passed 2026-09-16 · scanner 2026.09.1 · 1 release · last release today · 5% of files seen elsewhere

computed 2026-09-16 21:19 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
none in 5 packages
OSV
known vulnerabilities
none in 5 packages
OSV
dependency behaviour
3 direct packages declare install scripts, filesystem access, environment variables and more · 100 more in transitive packages · 3 packages flagged for review
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
nothing
Talks to
  • api.coinbase.com
  • data-api.binance.vision
  • github.com
  • www.okx.com
Reads
no environment variables
At install
nothing runs
Links to
  • ic0.app
  • img.shields.io
  • internetcomputer.org
Findings (22)
  • flagged for reviewblock-buffer 0.10.4 — block-buffer 0.10.4 (transitive) — flagged for review by Socket's classifier as a security risk
  • MODERATEserde 1.0.229 — serde 1.0.229 (direct) — ships compiled native code
  • MODERATEserde_json 1.0.151 — serde_json 1.0.151 (direct) — ships compiled native code
  • MODERATEserde 1.0.229 — serde 1.0.229 (direct) — install scripts run when installed
  • MODERATEserde_json 1.0.151 — serde_json 1.0.151 (direct) — install scripts run when installed
  • MODERATEblock-buffer 0.10.4 — block-buffer 0.10.4 (transitive) — has a known vulnerability GHSA-qwgh-2vcv-g2f7 GHSA-qwgh-2vcv-g2f7
  • LOWfutures 0.3.34 — futures 0.3.34 (direct) — reads environment variables
  • LOWserde 1.0.229 — serde 1.0.229 (direct) — reads environment variables
  • LOWserde_json 1.0.151 — serde_json 1.0.151 (direct) — reads environment variables
  • LOWserde 1.0.229 — serde 1.0.229 (direct) — reads or writes files
  • LOWsrc/lib.rs — Talks to api.coinbase.com
  • LOWsrc/lib.rs — Talks to data-api.binance.vision
  • LOWCargo.lock — Talks to github.com
  • LOWsrc/lib.rs — Talks to www.okx.com
  • flagged for reviewgptAnomaly — 2 transitive packages, e.g. anyhow@1.0.104, num-bigint@0.4.8
  • MODERATEhasNativeCode — 22 transitive packages, e.g. anyhow@1.0.104, ar_archive_writer@0.5.3, binrw@0.15.2
  • MODERATEinstallScripts — 22 transitive packages, e.g. anyhow@1.0.104, autocfg@1.5.1, binrw@0.15.2
  • MODERATEshellAccess — 7 transitive packages, e.g. autocfg@1.5.1, darling_core@0.20.11, libc@0.2.189
  • MODERATEnetworkAccess — 3 transitive packages, e.g. arrayvec@0.5.2, object@0.39.1, quote@1.0.47
  • LOWenvVars — 27 transitive packages, e.g. anyhow@1.0.104, ar_archive_writer@0.5.3, autocfg@1.5.1
  • LOWfilesystemAccess — 13 transitive packages, e.g. ar_archive_writer@0.5.3, autocfg@1.5.1, either@1.18.0
  • LOWurlStrings — 2 transitive packages, e.g. libc@0.2.189, unicode-width@0.2.2

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Rust/ICP multi-exchange price oracle with Binance, Coinbase and OKX HTTPS outcalls, provenance and validation safeguards.

When to use it. When requiring verified ICP / Market Data functionality in autonomous workflows

Readme

ICP Multi-Exchange Price Oracle Canister

Multi-Venue Spot Market Data & Candlestick Oracle for the Internet Computer

Tests Target License


1. WHAT IS THIS?

The ICP Multi-Exchange Price Oracle Canister is a production-ready Rust smart contract for the Internet Computer (ICP). It fetches, validates, normalizes, and caches real-time and historical candlestick (OHLCV) market data from three Tier-1 exchanges (Binance, Coinbase, OKX) via deterministic HTTPS outcalls, serving queries to frontend clients with zero cycle fees.

2. WHO IS IT FOR?

  • Web3 DeFi & DEX Developers: Needing validated multi-timeframe OHLCV bars and multi-exchange spread data for interactive charting and on-chain trade logic.
  • DAO Treasuries: Requiring automated asset valuation without recurring third-party oracle subscription fees.
  • Canister Architects: Requiring a secure reference implementation for rate-limited, single-flight HTTPS outcalls with cycle reserve protection.

3. WHAT PROBLEM DOES IT SOLVE?

The official DFINITY Exchange Rate Canister (XRC) provides single spot price cross-rates but has structural limitations for interactive applications:

  1. Cycles Attached on Query: XRC requires the caller to attach cycles to every query call, making direct, unauthenticated frontend web client queries impossible.
  2. No Candlestick (OHLCV) Series: XRC returns a single spot price; it does not aggregate, normalize, or cache multi-timeframe OHLCV series required for charting.
  3. Black-Box Aggregation: XRC hides individual exchange order-book/candle provenance.
  4. Bankruptcy Risk: Naive outcall loops can rapidly exhaust a canister cycle balance during upstream network disruptions.

4. WHY PAY FOR IT INSTEAD OF BUILDING IT?

  • Free Client Queries: An in-canister RAM cache serves authenticated query calls (cached_market_data) to browser frontends at zero cycle cost to the user.
  • Full OHLCV Candlestick Parsing: Parses and normalizes native candlestick streams across M1, M5, M15, H1, H4, D1, W1 timeframes.
  • Multi-Exchange Transparency: Queries Binance, Coinbase, and OKX concurrently, returning validated series and provenance alongside explicit failure tracking for each venue.
  • 100 Billion Cycle Reserve Protection: Automatically aborts outcalls if canister reserves drop below 100B cycles (~0.1 TC), preventing canister freeze.
  • Single-Flight Coalescing: Concurrent requests for the same asset/timeframe share an in-flight promise to eliminate duplicate outcall expenses.

5. WHAT IS VERIFIED?

  • 10 / 10 Automated Rust Unit Tests Passed: OHLCV validation, duplicate timestamp rejection, negative/zero price rejection, case-insensitive asset normalization, boundary calculation, and exchange parser error handling.
  • WASM Compilation: Compiles to optimized wasm32-unknown-unknown canister binary.
  • Candid Interface: Fully verified Candid contract (candid/market_oracle.did).

6. HOW DO I RUN IT?

# 1. Run unit tests
cargo test --manifest-path Cargo.toml

# 2. Build optimized canister WASM
cargo build --manifest-path Cargo.toml --target wasm32-unknown-unknown --release

# 3. Deploy locally with dfx
dfx start --background
dfx deploy market_oracle
dfx canister call market_oracle refresh_market_data '(record { asset = "BTC"; timeframe = variant { H1 }; limit = 20 })'

Contents

21 files · 71.3 kB · computed 2026-09-16
SizePath
25 B.gitignore
1.2 kBAGENT_EVAL.md
2.7 kBARCHITECTURE.md
503 BCHANGELOG.md
20.8 kBCargo.lock
369 BCargo.toml
399 BDEPENDENCIES.md
1.7 kBLICENSE.md
794 BLIMITATIONS.md
2.3 kBPREVIEW.md
1.3 kBQUICKSTART.md
3.6 kBREADME.md
1.6 kBSECURITY.md
624 BSUPPORT.md
1.5 kBTEST_REPORT.md
376 BVERIFICATION.md
1.4 kBcandid/market_oracle.did · binary
1.2 kBcommercial-manifest.json
254 Bdfx.json
2 kBrelease-manifest.json
26.8 kBsrc/lib.rs
computed 2026-09-16 21:19 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-16 21:19 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-09-16passrelease: v1.0.0 commercial source edition

Machine-readable at https://x402git.com/api/v/genesiscode2026/icp-multi-exchange-price-oracle/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $249 · new releases $59

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/icp-multi-exchange-price-oracle

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/icp-multi-exchange-price-oracle \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/genesiscode2026/icp-multi-exchange-price-oracle",
    "description": "genesiscode2026/icp-multi-exchange-price-oracle v1.0.0 — release. Rust/ICP multi-exchange price oracle with Binance, Coinbase and OKX HTTPS outcalls, provenance and validation safeguards. Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "icp-multi-exchange-price-oracle",
    "tags": [
      "pack",
      "source",
      "tests",
      "docs",
      "config"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "249000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "249000000",
      "resource": "https://x402git.com/api/r/genesiscode2026/icp-multi-exchange-price-oracle",
      "description": "genesiscode2026/icp-multi-exchange-price-oracle v1.0.0 — release. Rust/ICP multi-exchange price oracle with Binance, Coinbase and OKX HTTPS outcalls, provenance and validation safeguards. Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/genesiscode2026/icp-multi-exchange-price-oracle/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/genesiscode2026/icp-multi-exchange-price-oracle/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/genesiscode2026/icp-multi-exchange-price-oracle",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/genesiscode2026/icp-multi-exchange-price-oracle",
    "scan_badge_url": "https://x402git.com/api/label/genesiscode2026/icp-multi-exchange-price-oracle#scan",
    "update_price_micro": "59000000",
    "quote_id": "q_a95562d76254a57aaab88e79904299cf",
    "valid_before": "2026-09-17T03:24:58.012Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/icp-multi-exchange-price-oracle again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/icp-multi-exchange-price-oracle, and the free manifest at https://x402git.com/api/label/genesiscode2026/icp-multi-exchange-price-oracle shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/genesiscode2026/icp-multi-exchange-price-oracle",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/genesiscode2026/icp-multi-exchange-price-oracle
Manifest
https://x402git.com/api/label/genesiscode2026/icp-multi-exchange-price-oracle
Version
https://x402git.com/api/v/genesiscode2026/icp-multi-exchange-price-oracle
Artifact sha256
8ff0ea5b8687820bce04f272e3141d59f2f70e292053c2b35d63ed6c4a0a20e7

Later releases cost $59, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.