{"service":"probe402","what_this_is":"An arms-length health, price and history layer for the x402 agent-payment rail. We probe known endpoints on a clock, keep every capture immutably, and answer questions about what we observed. We never state what an endpoint IS — only what it did, when, from our vantage.","non_affiliation":"probe402 is not affiliated with, endorsed by, or compensated by any endpoint or operator it grades. Every claim here is a dated observation from our vantage, never a statement about what an endpoint is.","who_we_are":{"operator":"probe402","operator_name":"Zach Bucheister","contact":"hello@probe402.com","accountability":"probe402 is run by one named person. Corrections, disputes and requests to stop probing an endpoint go to the contact address above and are answered on the published window; every correction ever filed is at https://probe402.com/corrections, including the ones where we were right.","method":"https://probe402.com/method"},"what_we_send":{"user_agent":"probe402/0.1.0 (+https://probe402.com/method; contact hello@probe402.com)","handshake":"The 402 quote handshake only — the protocol's own discovery mechanism. No content extraction, no paywall circumvention, no auth bypass, no scanning to find endpoints.","body_budget":{"max_bytes":2097152,"rule":"We read at most 2 MiB of any response and then stop pulling. It is a limit on US, not on you: an unbounded read means one endpoint can kill the whole hourly cycle, and a collector that dies leaves a permanent gap in an archive that cannot be backfilled. When it fires, the capture records `body_truncated` so the evidence says what it is, and truncation can only make us MISS a signal, never invent one - a cut-off block page falls to `Answered, no quote`, a cut-off challenge yields no quote rather than a price."},"cannot_pay":"The collector is STRUCTURALLY unable to pay: the request builder accepts no header parameter at all, and a test walks the import graph and fails if anything signing-capable becomes reachable. Some endpoints we probe place real phone calls when paid.","robots":{"rule":"We read robots.txt for every host we probe, not only the ones we already excluded, and we honour it per RFC 9309. An endpoint whose robots.txt forbids its path is not probed and is recorded as Not probed with the exact rule that decided it. If that Disallow is later lifted, probing resumes automatically on the next check, with no manual step.","user_agent_match":"A robots.txt group reaches us when its user-agent token IS `probe402` or starts with it — `probe402`, `probe402/1.0`. A SHORTER token does not: a group written for some other product whose name happens to be a prefix of ours is not a group about us, and reading it as one could let somebody else's Allow override your wildcard Disallow.","excluded_entries":"Separately, a handful of seed entries are marked EXCLUDED and are never probed at all. We still re-read their robots.txt every tick and record what it now says. If it stops forbidding the path we FLAG the entry for promotion on a dated record — we do not silently start probing it. `excluded` also records operator requests and costs we chose not to impose, and those look identical to a robots rule from here, so putting us back on the wire is a deliberate seed edit made by a person.","user_agent_token":"probe402","recheck_hours":24,"recheck_basis":"RFC 9309 section 2.4 says a crawler SHOULD NOT use a cached robots.txt for more than 24 hours. That is the ceiling the standard sets, so that is our interval - it is not a number we chose for our own convenience. It also caps the exposure: a Disallow added today is honoured within a day, and one robots.txt request per host per day is the entire cost of that.","unavailable_4xx":"RFC 9309 section 2.3.1.3 - a 404 or 403 robots.txt means allowed.","unreachable_5xx":"RFC 9309 section 2.3.1.4 - a 5xx robots.txt means complete disallow. We stop.","stated_departure":"ONE departure, stated rather than hidden. RFC 9309 section 2.3.1.4 also treats a NETWORK failure on robots.txt as complete disallow. We do not. When robots.txt fails at transport level - DNS failure, connection refused, reset, timeout - we make exactly one further connection attempt, to the endpoint itself, and record what happened. Two reasons. The rule protects a server that is up but unable to state its policy, and a host that answers nothing is not being protected by our silence. And every dead endpoint's robots.txt is also unreachable, so following the rule literally would convert every death in this archive from a measurement into a claim about permission. Both readings are on the record: each observation carries what robots.txt said AND what we did. An operator who objects can say so and the endpoint moves to excluded."},"backoff":{"rule":"Any observation of Blocked or challenged stops us probing that endpoint for a while. We never retry inside a cycle and we never retry through a challenge, so backoff means we do not schedule the next probe, not that we wait and try again.","first_wait_hours":2,"max_wait_hours":24,"schedule":"Doubling per consecutive block, capped: 2h, 4h, 8h, 16h, 24h, 24h...","retry_after":"When a Retry-After is given we wait at least that long, and longer if our own schedule says longer - being told we MAY return in a minute is not an instruction that we should. A skipped cycle is recorded as Not probed with the reason, so the gap is visible rather than silent.","retry_after_ceiling_hours":168,"retry_after_ceiling":"We honour a Retry-After up to 168 hours. Beyond that we wait the ceiling and then look once. The number is published because a floor with no stated bound is not a commitment either side can check: one response header would otherwise be able to end a series indefinitely, and the days lost from this archive cannot be recovered afterwards. When the ceiling applies, the skipped cycles say so in words. If you need longer quiet than that, ask us and the endpoint moves to excluded - that is a policy decision we record, not a header we guess at.","recovery":"One answer that is not a block clears it. Unreachable clears it too - a dead endpoint is a measurement we owe our readers, not a host to throttle."}},"vocabulary":{"terms":["Quoted","Answered, no quote","Blocked or challenged","Unreachable","Not probed"],"note":"There is deliberately no healthy/dead pair. Rollups are stated as counts. `Insufficient history` is a rollup answer and never appears on an observation."},"rubric":{"url":"https://probe402.com/rubric","version":5,"governing_rule":"`Blocked or challenged` requires POSITIVE evidence — a vendor-identifying header, a body signature, or a content-type flip. Ambiguity defaults to `Answered, no quote` or `Unreachable` plus a sub-code, never to a blocked claim. Misclassifying a bare 403 as blocked is recoverable; publishing a blocked claim we cannot support is not.","quote_guarded_rules":["R11","R12","R13"]},"corrections":{"url":"https://probe402.com/corrections","acknowledge_within_days":2,"resolve_or_interim_within_days":7,"how":"Contest a reading at hello@probe402.com. We re-probe, check the retained capture, and respond in writing inside the window above.","where_the_record_lives":"Every dispute becomes a numbered issue in probe402/disputes, a PRIVATE repository. Each correction we file carries an opaque `dispute/<issue-number>` handle that resolves there and nowhere else. We keep the record on a third party's timestamps deliberately: a clock we run ourselves cannot show we met a window we set ourselves. The repository is private because a dispute names an endpoint and carries our judgement of it, and because the person raising it should never become public for having done so. What IS public is this process and every outcome - see the corrections log, which names the observation and the remedy and never the complainant.","when_the_clock_starts":"A dispute arrives as email and a person opens the issue, so the 2-day clock starts when that mail is READ, not when it is received. At today's volume that is the honest arrangement and automating it would be premature - but it is a real gap between the promise and the mechanism, and you are being told about it here rather than discovering it during a dispute. If a reply matters to you, say so in the subject line.","three_classes":{"instrument-error":"We were wrong. The affected range is ANNOTATED and carries a series-break marker. No record is ever edited.","endpoint-changed":"The endpoint changed after we looked. The observation was true when made; the remedy is a fresh probe, and we name the tick that ran it.","method-disagreement":"A disagreement about the method. Resolved in the method changelog, never by touching records."}},"gate_exclusions":{"what":"STRATEGY §3's FULL settlement conditions are: on mainnet, from a wallet we do not control, and unattended. A funded third-party prober satisfies all three literally. A grader that pays our routes on a loop to check that we answer is on mainnet, is not our wallet, and is emphatically unattended — and nothing in the gate distinguishes it from the thing the gate exists to detect. So a settlement is excluded from the gate when the payer's behaviour shows it was testing WHETHER THE ENDPOINT ANSWERS AT ALL rather than wanting this answer.","written_before_it_could_cost_us_anything":"Recorded 2026-08-24, when no settlement of any kind had ever occurred (series (c) = 0, both mainnet wallets at 0 ETH / 0 USDC on a public RPC). This rule can therefore only ever make our own verdict worse. Written after a prober's payment had made a week read FULL it would be post-hoc softening; the date is the only thing separating those two.","criteria":{"named-grader":"The payer wallet is attributable to a published grader, index, monitor, scanner or facilitator that probes x402/MPP endpoints as its stated business. The list is below, in the open, so anyone can check it — never a private judgement.","interchangeability":"The request pattern shows the endpoint, not the answer, was the object: a fixed interval, no variation in the parameters a buyer would vary, and no follow-up depending on what came back. This is the softer of the two criteria and is labelled as such; one part of it (the same shape applied across many unrelated hosts) is not observable from our own logs, and every exclusion made on it says so."},"named_graders":[{"name":"Dexter / OpenDexter","url":"https://dexter.cash","basis":"States it will fund ongoing tests against listed endpoints. A payment made to check that a listing answers is a payment for which any endpoint would have done. This is the instance that produced the class: a listing was declined on 2026-08-23 pending this rule.","wallets":[],"wallets_note":"No wallet has ever been attributed to this grader, because no settlement has ever occurred. An entry with no wallets excludes nothing: it is a declaration of who we would exclude, made before it could cost us anything."},{"name":"PulseFeed","url":"https://pulsefeed.xyz","basis":"Publishes x402 endpoint health and uptime; probing endpoints is the product.","wallets":[],"wallets_note":"No wallet has ever been attributed to this grader, because no settlement has ever occurred. An entry with no wallets excludes nothing: it is a declaration of who we would exclude, made before it could cost us anything."},{"name":"402index","url":"https://402index.com","basis":"Indexes and grades x402/MPP endpoints, including a degraded/healthy verdict per host.","wallets":[],"wallets_note":"No wallet has ever been attributed to this grader, because no settlement has ever occurred. An entry with no wallets excludes nothing: it is a declaration of who we would exclude, made before it could cost us anything."},{"name":"x402scan","url":"https://x402scan.com","basis":"Scans and lists x402 resources; validates discovery documents as its function.","wallets":[],"wallets_note":"No wallet has ever been attributed to this grader, because no settlement has ever occurred. An entry with no wallets excludes nothing: it is a declaration of who we would exclude, made before it could cost us anything."},{"name":"x402-trust","url":"https://x402-trust.com","basis":"Scores x402 endpoint trustworthiness, which requires probing them.","wallets":[],"wallets_note":"No wallet has ever been attributed to this grader, because no settlement has ever occurred. An entry with no wallets excludes nothing: it is a declaration of who we would exclude, made before it could cost us anything."},{"name":"Merona","url":"https://merona.dev","basis":"Publishes a dated correction record over x402 endpoint observations — the competitor we cite in STRATEGY. Grading endpoints is the business.","wallets":[],"wallets_note":"No wallet has ever been attributed to this grader, because no settlement has ever occurred. An entry with no wallets excludes nothing: it is a declaration of who we would exclude, made before it could cost us anything."},{"name":"Assay / Nominal Labs","url":"https://assay.nominal-labs.com","basis":"Probes and grades x402 endpoints as its product, publishing a per-endpoint settlement result and a daily Merkle root anchored to Bitcoin via OpenTimestamps. It states that it spends real USDC to check that endpoints answer — a payment made to test whether a route responds is a payment for which any route would have done. The wallet 0x8a1A037b4fb377fceCd0F8A0B91A6A35df78Aa53 is self-published and linked from Assay's own homepage, which is attribution at its cleanest: we are not inferring who this is. Recorded here because its prober announces NO User-Agent, so ADR-046's demand-side crawler filter cannot reach it and this wallet is the only handle on it.","wallets":["0x8a1a037b4fb377fcecd0f8a0b91a6a35df78aa53"],"wallets_note":"Attributed wallets. A payment from one of these does not count toward the gate."}],"guards":{"everything_else_counts":"Including a payer we cannot identify. Ambiguity resolves TOWARD counting — the direction that hurts us least to be wrong about in your eyes and most in our own.","never_silent":"Every exclusion is itemised in the weekly verdict with the payer, the amount, the criterion met and the evidence. An exclusion that does not appear there did not happen.","changes_the_rung_out_loud":"If an exclusion changes the rung, the verdict says so in its headline sentence: \"this week would read FULL but for N excluded prober settlement(s), itemised below\". You can re-run our arithmetic and disagree with us.","never_retroactive":"A settlement already counted in a published verdict stays counted. If we later learn the payer was a grader, that is a correction — appended and visible — not a re-cut of history.","excluded_is_not_deleted":"The settlement is still archived, still published, still a real event. It leaves the gate series; it does not leave the record."}},"demand_exclusions":{"what":"The gate's demand reading (`agent_demand`) and series (b) count requests to the METERED surface. A crawler that fetches a listed resource to establish that the endpoint exists and what it quotes is doing ADDRESS work, not demand work - the catalogue entry is the object, not the answer, and any x402 endpoint would have done. Those requests are excluded, by the same test ADR-040 applies to payers one series over: did the caller want THIS answer?","written_when_it_cost_us_our_only_positive_reading":"Recorded 2026-08-24. It cost us the only PARTIAL this project has ever read: 2026-W34 stood on exactly 10 requests from 3 sources against a pre-registered floor of 10 and 2, and one of those requests and one of those sources was a discovery crawler. Applying this rule moves that week to FAIL, and that correction is published beside the verdict. Written after a favourable week it would be worthless.","announced_identity_only":"The exclusion requires the caller to SAY what it is in its user-agent. It is never a behavioural guess about an anonymous caller. Unattributed clients - `Go-http-client/1.1`, `node` - keep counting as demand, because ambiguity resolves TOWARD counting: the direction that hurts us least to be wrong about in your eyes and most in our own.","excluded_identities":[{"name":"Coinbase Bazaar discovery crawler","user_agent_substring":"coinbasebazaardiscovery","basis":"Announces itself as Coinbase's Bazaar DISCOVERY crawler and links to CDP's x402 documentation. It fetches a listed resource to establish that the endpoint exists and what it quotes — the catalogue entry is the object, not the answer. Any x402 endpoint would have done. Measured 2026-08-24: 1 request on the metered surface, matching none of the eight terms in the crawler/monitor/scanner list, and therefore counted as agent demand.","url":"https://docs.cdp.coinbase.com/x402/","excluded_since":"2026-08-24"}],"guards":{"never_silent":"Every excluded request is itemised in the weekly verdict's gate block with its reason and its count, and the number of announced identities the filter consulted is printed every week whether or not it fired. An exclusion that does not appear there did not happen.","changes_the_rung_out_loud":"If the exclusion changes the rung, the verdict says so in its headline sentence: \"this week would read PARTIAL but for N request(s) excluded as announced discovery crawling\". The counterfactual - what the gate input would have read without the filter - is printed every week, so you can re-run our arithmetic and disagree with us.","excluded_is_not_deleted":"The request is still in series (a), still in the request log, still in the archive. It leaves the gate input and series (b); it does not leave the record.","if_this_ever_gets_big":"If discovery crawlers ever become a material share of metered traffic, this itemised block is the measurement of how much of the 'market' is indexing infrastructure - which is a finding about the rail worth publishing, not a reason to start counting them."}},"pricing":{"free":"Current observation plus 7 days of counts. Always free.","paid":[{"tier":"depth-30","days":30,"price_usd":0.005},{"tier":"depth-180","days":180,"price_usd":0.02},{"tier":"depth-full","days":null,"price_usd":0.05}],"principle":"The grade is free. Money buys depth of history, never a better verdict."},"versions":{"lookup":"0.1.0","rubric":5,"normalizer":1,"prober":"0.1.0","observation_schema":3},"instrument_alarms":{"note":"Thresholds at which we stop and look at ourselves before publishing a cycle. Published because an alarm nobody can check is a claim, and because each of these exists to stop OUR failure being reported as the ecosystem's.","block_share":{"threshold":0.2,"sustained_ticks":6,"says":"If more than this share of the endpoints we probe refuses us, for this many consecutive hours, we stop and decide what to do about our standing - reduce cadence, seek allow-listing, or publish that we are being blocked. Never a workaround, and never anything that makes this prober harder to identify."},"fleet_simultaneity":{"threshold":0.25,"says":"Endpoints run by unrelated operators do not fail at network level in the same minute. If this share of them appears to, the shared thing is us, and the cycle is flagged for review before it is published. Records are flagged, never edited."},"vantage":"All reference canaries failing marks the whole cycle Not probed - our failure, recorded as ours."},"mcp":{"status":"unlisted","says":"We serve the same lookup over MCP, and it is NOT listed in the CDP Bazaar catalogue. The reason is mechanical, not strategic: the shipped SDK's paid-tool helper has no parameter for the discovery declaration, so the declaration cannot ride the MCP payment challenge, and a server-side declaration no paying client echoes catalogues nothing. Hand-rolling the challenge ourselves would mean diverging from the SDK on a payment path. We would rather say the surface is unlisted than be clever there. The HTTP route is listable and is the one we list."},"self_grading":"probe402's own endpoint is in the seed list and is graded by the same code, with no special case. A test asserts no code path branches on the self flag except the one that sets it. Our own entry probes a METERED route, so the self-observation is the same shape as every other entry: a real payment challenge. The endpoint id it binds is a reserved sentinel that we do not cover - binding our own id would be circular, and binding a peer endpoint would tie our identity to theirs. The prober runs on Cloudflare, which also supplies bot-defence products this rubric classifies. We disclose that rather than leaving it to be discovered."}