# What does this x402 endpoint charge?

**0.006000 USDC per request** on `eip155:8453` · risk LOW (100/100, v1)

## ENDPOINT

| Field       | Value                                       |
| ----------- | ------------------------------------------- |
| URL         | https://2s.io/api/vehicle/vin-decode        |
| Canonical   | https://2s.io/api/vehicle/vin-decode        |
| Endpoint id | b7f1bc69289f6c6857e05039892a6ebc            |
| HTTP status | 402                                         |
| Latency     | 55 ms                                       |
| Redirects   | 0                                           |
| TLS         | handshake ok                                |
| Wire form   | both the v2 header and a v1 body            |
| Bytes read  | 7022                                        |
| Observed at | 2026-08-15T15:14:58Z                        |
| Decoder     | accepted — decodePaymentRequired from tx402 |

## PAYMENT

These terms were accepted by the strict decoder tx402 uses before it pays.

| Field                   | Value                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Price                   | 0.006000 USDC                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Amount (atomic)         | 6000                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Scheme                  | exact                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Network                 | eip155:8453 · in the tx402 signed manifest                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Asset                   | USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 · in the manifest                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Pay to                  | 0x2b6D4988Db4723E6908Db86Ab2b8dFBc51FC32C5                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Pay to declared dynamic | no                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Authorization window    | 60s                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Resource                | https://2s.io/api/vehicle/vin-decode                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MIME type               | application/json                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Description             | Decode a 17-character VIN to manufacturer-supplied vehicle metadata via NHTSA's vPIC database. Returns identity (year, make, model, trim, series, body class, manufacturer), assembly plant (city, state, country), engine (cylinders, displacement, HP, fuel type, configuration, engine model), transmission (style, speeds), and body/weight specs. Curated to the ~30 fields agents actually use from vPIC's ~140-field response. Backed by NHTSA.gov; data is public-domain US government records. |
| Facilitator             | not observed                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

This endpoint offers 2 ways to pay. The report describes the first, which is the order the server stated its own preference in.

| # | Requirement                                                           |
| - | --------------------------------------------------------------------- |
| 1 | 0.006000 USDC · eip155:8453 · exact                                   |
| 2 | 6000 (atomic units) · solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp · exact |

## OBSERVED

| Field              | Value                |
| ------------------ | -------------------- |
| First seen         | 2026-08-15T04:00:12Z |
| Last seen          | 2026-08-15T15:14:58Z |
| Scans recorded     | 3                    |
| Availability (30d) | not measured yet     |
| Latency p50        | not measured yet     |

| Changed at           | What changed                                                                                    |
| -------------------- | ----------------------------------------------------------------------------------------------- |
| 2026-08-15T05:15:57Z | first_seen: challenge_hash — → 109f7e050844ed57bb1d54817ba2245187aabde66b9b6f70ed2998d5c5b0f0e8 |

## SECURITY

17 checks ran and none failed. A check that could not run reports `skip` and is never counted as a pass.

| Check                              | Detail                                                         |
| ---------------------------------- | -------------------------------------------------------------- |
| pass  wire_form_detected           | Served as both.                                                |
| pass  base64_strict                | The strict decoder accepted the header's base64 framing.       |
| pass  json_wellformed              | —                                                              |
| pass  x402_version_known           | Declared x402Version 2.                                        |
| pass  accepts_present              | The challenge offers 2 ways to pay.                            |
| pass  size_within_limit            | Read 7022 bytes, within the probe's cap.                       |
| pass  network_caip2_wellformed     | network: eip155:8453                                           |
| pass  network_recognized           | Recognized means present in the tx402 signed release manifest. |
| pass  asset_recognized             | Recognized means present in the tx402 signed release manifest. |
| pass  amount_atomic_canonical      | —                                                              |
| pass  amount_positive              | —                                                              |
| pass  pay_to_wellformed            | —                                                              |
| pass  max_timeout_sane             | —                                                              |
| pass  resource_origin_match        | —                                                              |
| pass  scheme_known                 | —                                                              |
| skip  facilitator_known            | The challenge named no facilitator.                            |
| pass  mime_type_wellformed         | mimeType: application/json                                     |
| pass  extra_wellformed             | `extra` carries 2 field(s), preserved verbatim.                |
| skip  amount_within_observed_range | No prior observations of this endpoint.                        |
| skip  recipient_matches_observed   | No prior observations of this endpoint.                        |

## RISK — LOW  (100/100)

score_version `v1` · confidence `static_only` · 12 signals scored

A band describes how much of what we check we were able to confirm. It is not a judgement about the operator of an endpoint.

| Signal                          | Weight  Finding                                                                       |
| ------------------------------- | ------------------------------------------------------------------------------------- |
| pass  challenge_decodes         |  25     The challenge decodes under the strict x402 decoder tx402 uses before paying. |
| pass  resource_origin_match     |  15     The challenge describes the endpoint that served it.                          |
| pass  amount_canonical          |  12     The amount is a canonical atomic integer.                                     |
| pass  pay_to_wellformed         |  12     The recipient is a well-formed address for the declared network.              |
| pass  network_recognized        |   8     The network is in the tx402 signed release manifest.                          |
| pass  asset_recognized          |   8     The asset is in the tx402 signed release manifest for this network.           |
| skip  facilitator_known         |   0     The challenge named no facilitator.                                           |
| pass  scheme_known              |   6     The payment scheme is one tx402 can route.                                    |
| pass  tls_ok                    |   5     The endpoint was reached over a valid TLS connection.                         |
| pass  timeout_sane              |   4     The authorization window is within the maximum tx402 will sign for.           |
| pass  redirect_scheme_downgrade |   3     No redirect downgraded the connection.                                        |
| pass  wire_form                 |   3     The endpoint serves the x402 v2 header form.                                  |
| pass  amount_magnitude_band     |   2     The amount is within the range we see for x402 endpoints.                     |

Methodology: https://tools.tx402.io/methodology?v=v1

## TEST WITH TX402

Nothing below sends a key anywhere. tx402 commits policy and budget before the signer is reachable,
so a refusal is a payment that was never authorized.

```bash
npx tx402 call "https://2s.io/api/vehicle/vin-decode" \
  --max-spend "0.006000 USDC" \
  --network "eip155:8453" \
  --dry-run

# --dry-run stops after the policy decision. Nothing is signed and nothing is spent.
```

```ts
import { createTx402Client } from "tx402";
// Your signer stays in your process. tools.tx402.io never sees a key,
// never asks for one, and cannot build a payment.
import { signers } from "./signers.js";

const tx402 = createTx402Client({
  signers,
  policy: {
    maxPerRequest: "0.006000 USDC",
    allowedDomains: ["2s.io"],
    allowedNetworks: ["eip155:8453"],
  },
});

// Policy and budget are committed before the signer is reachable, so a
// refusal here is a payment that was never authorized.
const response = await tx402.fetch("https://2s.io/api/vehicle/vin-decode");
```

```python
from tx402 import Tx402Client, Policy

# Your signer stays in your process. tools.tx402.io never sees a key,
# never asks for one, and cannot build a payment.
tx402 = Tx402Client(
    evm_signer=evm,
    policy=Policy(
        max_per_request="0.006000 USDC",
        allowed_domains=["2s.io"],
        allowed_networks=["eip155:8453"],
    ),
)

# Policy and budget are committed before the signer is reachable, so a
# refusal here is a payment that was never authorized.
response = tx402.fetch("https://2s.io/api/vehicle/vin-decode")
```

---

| Representation | URL |
| -------------- | --- |
| HTML     | https://tools.tx402.io/inspect?url=https%3A%2F%2F2s.io%2Fapi%2Fvehicle%2Fvin-decode |
| Markdown | https://tools.tx402.io/inspect.md?url=https%3A%2F%2F2s.io%2Fapi%2Fvehicle%2Fvin-decode |
| JSON     | https://tools.tx402.io/api/v1/inspect?url=https%3A%2F%2F2s.io%2Fapi%2Fvehicle%2Fvin-decode |
| History  | https://tools.tx402.io/history?url=https%3A%2F%2F2s.io%2Fapi%2Fvehicle%2Fvin-decode |

Decoded by `tx402@0.2.0` — the same strict decoder the SDK runs before it pays.
