Endpoint
scvd.store/api/buy/service_audit
Task: Get a signed point-in-time audit of an x402 endpoint that I can hand to a third party. Returns: A signed JSON audit report — verdict (ready, not_ready or unreachable), every check and advisory from the published preflight battery, dated, its evidence hash bound into the purchase certificate's attests field — plus a stable report URL serving the record free forever. Instant; one GET at one moment, never monitoring. Price: $5 USDC (x402 v2; network from the current quote). Latency: delivered in the purchase response, same request. Verify: GET /api/verify/{id} — free, unlimited, forever (live sample: cert_4dww28dx5j). Constraints: Give the endpoint in the url query parameter: https, default port, on the public internet, the URL a buyer would GET expecting a 402; A bounded endpoint probe with rail and cross-surface reads, signed; never a monitor — the week-long look is The Night Watch; The cited criteria are the v2 battery (GET /api/preflight/v2), the same battery the weekly census applies; also_under carries the frozen v1 score so a reader can see the overlap. Reports signed before 2026-09-01 cite v1 and keep that citation forever; We refuse our own hostname — an audit of ourselves signed by ourselves would be the instrument vouching for itself; The report URL is free to read forever. The Once-Over, Name an x402 endpoint (the url query parameter) and the store probes it, runs the published preflight battery with additional rail and cross-surface reads, and signs the whole readout: the current v2 verdict this series now cites (the same battery the weekly census applies), the same probe scored under the frozen v1 battery beside it (the two can disagree, and the report says when they do), every check, every advisory, dated. The free batteries are documented at /api/preflight; this paid audit also reads the rail and compares the published surfaces. What this buys is the artifact: a signed report whose evidence hash is bound into your purchase certificate, stored and served at a stable URL forever, so a directory, a counterparty, or your own future self can check it without trusting whoever commissioned it. One bounded audit, against published criteria. Not an endorsement, not an uptime claim, not a badge; an unreachable endpoint is reported as unreachable, which proves nothing about later.
Score
The score is built from observations we collect ourselves: how the endpoint responds, what the envelope contains, how stable the price and the recipient are, who pays and how often. It is deterministic — the same input always produces the same result.
We do not publish the exact methodology yet. If you own this endpoint, write to us and we will show you, item by item, what drags the score down.
Recent probes
| When | Code | Latency | Scheme and network | Recipient | Price | Findings |
|---|---|---|---|---|---|---|
| 6h ago | 402 | 29 ms | exact eip155:8453 |
0xDD35…9bd0 | 5.000000 | clean |
| 4d ago | 402 | 25 ms | exact eip155:8453 |
0xDD35…9bd0 | 5.000000 | clean |
| 4d ago | 402 | 30 ms | exact eip155:8453 |
0xDD35…9bd0 | 5.000000 | clean |
Reference
| URL | https://scvd.store/api/buy/service_audit |
| Sources | bazaar well-known |
| Recipient per catalogue | 0xDD350976B8cfFc65938C0464d39A2C78BE079bd0 |
| Price per catalogue | 5.000000 |
| Machine access | /v1/endpoint · /full · badge |
Is this your endpoint?
The score is built only from public observations. If something we recorded is wrong — say our prober hit you during maintenance — write to us. We will recheck and publish your reply next to the score.
We do not delete accurate observations. The prober makes at most one request per second per host and only asks for the payment challenge — it never pays and never takes content.