# What does this x402 endpoint charge?

**Challenge served, decoder refused it.** `https://agent402.tools/api/random` — Invalid PAYMENT-REQUIRED challenge: upstream-schema-invalid

## ENDPOINT

| Field          | Value                                                       |
| -------------- | ----------------------------------------------------------- |
| URL            | https://agent402.tools/api/random                           |
| Canonical      | https://agent402.tools/api/random                           |
| Endpoint id    | 99baffbc346ca400f386ee79c90beefd                            |
| HTTP status    | 402                                                         |
| Latency        | 260 ms                                                      |
| Redirects      | 0                                                           |
| TLS            | handshake ok                                                |
| Wire form      | x402 v2 — PAYMENT-REQUIRED header                           |
| Bytes read     | 277                                                         |
| Observed at    | 2026-08-15T15:14:32Z                                        |
| Decoder        | refused — TX402_PAYMENT_REQUIRED_INVALID                    |
| Decoder detail | Invalid PAYMENT-REQUIRED challenge: upstream-schema-invalid |

## PAYMENT

⚠️ The decoder REFUSED this challenge. The terms below were parsed from what the endpoint served so that whoever maintains it can see what we saw — they are **not** terms tx402 would pay.

| Field                   | Value                                                                                                                    |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| Price                   | 0.001000 USDC                                                                                                            |
| Amount (atomic)         | 1000                                                                                                                     |
| Scheme                  | exact                                                                                                                    |
| Network                 | eip155:8453 · in the tx402 signed manifest                                                                               |
| Asset                   | USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 · in the manifest                                                        |
| Pay to                  | 0xaBF4FAbd7c416fB67202E5f9002389Fc75e2a9D0                                                                               |
| Pay to declared dynamic | no                                                                                                                       |
| Authorization window    | 300s                                                                                                                     |
| Resource                | https://agent402.tools/api/random                                                                                        |
| MIME type               | application/json                                                                                                         |
| Description             | Cryptographically secure randomness. ?bytes=1..1024 returns hex; or ?min=&max= returns a uniform integer; ?count=1..100. |
| Facilitator             | not observed                                                                                                             |

## OBSERVED

| Field              | Value                |
| ------------------ | -------------------- |
| First seen         | 2026-08-15T04:00:12Z |
| Last seen          | 2026-08-15T15:14:32Z |
| Scans recorded     | 3                    |
| Availability (30d) | not measured yet     |
| Latency p50        | not measured yet     |

| Changed at           | What changed                                                                                    |
| -------------------- | ----------------------------------------------------------------------------------------------- |
| 2026-08-15T05:00:51Z | first_seen: challenge_hash — → 6729e416f2e15ba301eb7d6560d0cde3e2d532a656eb82fcce390ff6e5926e0c |

## SECURITY

**The strict decoder refused this challenge** (`TX402_PAYMENT_REQUIRED_INVALID`), which is the finding that matters most here. 0 failed, 1 warned, 15 passed. Those checks describe what could still be determined from what the endpoint served. A check that could not run reports `skip` and is never counted as a pass.

| Check                              | Detail                                                                        |
| ---------------------------------- | ----------------------------------------------------------------------------- |
| pass  wire_form_detected           | Served as v2-header.                                                          |
| skip  base64_strict                | The decoder refused the challenge; the framing cannot be reported separately. |
| pass  json_wellformed              | —                                                                             |
| pass  x402_version_known           | Declared x402Version 2.                                                       |
| pass  accepts_present              | The challenge offers 13 ways to pay.                                          |
| pass  size_within_limit            | Read 277 bytes, within the probe's cap.                                       |
| pass  network_caip2_wellformed     | network: eip155:8453                                                          |
| pass  network_recognized           | Recognized means present in the tx402 signed release manifest.                |
| pass  asset_recognized             | Recognized means present in the tx402 signed release manifest.                |
| pass  amount_atomic_canonical      | —                                                                             |
| pass  amount_positive              | —                                                                             |
| pass  pay_to_wellformed            | —                                                                             |
| warn  max_timeout_sane             | Authorization window 300s exceeds the tx402 maximum of 60s.                   |
| pass  resource_origin_match        | —                                                                             |
| pass  scheme_known                 | —                                                                             |
| skip  facilitator_known            | The challenge named no facilitator.                                           |
| pass  mime_type_wellformed         | mimeType: application/json                                                    |
| pass  extra_wellformed             | `extra` carries 2 field(s), preserved verbatim.                               |
| skip  amount_within_observed_range | No prior observations of this endpoint.                                       |
| skip  recipient_matches_observed   | No prior observations of this endpoint.                                       |

## RISK — MEDIUM  (72/100)

score_version `v1` · confidence `static_only` · 12 signals scored

A band describes how much of what we check we were able to confirm. It is not a judgement about the operator of an endpoint.

| Signal                          | Weight  Finding                                                                               |
| ------------------------------- | --------------------------------------------------------------------------------------------- |
| fail  challenge_decodes         |  25     The challenge does not decode under the strict x402 decoder tx402 uses before paying. |
| pass  resource_origin_match     |  15     The challenge describes the endpoint that served it.                                  |
| pass  amount_canonical          |  12     The amount is a canonical atomic integer.                                             |
| pass  pay_to_wellformed         |  12     The recipient is a well-formed address for the declared network.                      |
| pass  network_recognized        |   8     The network is in the tx402 signed release manifest.                                  |
| pass  asset_recognized          |   8     The asset is in the tx402 signed release manifest for this network.                   |
| skip  facilitator_known         |   0     The challenge named no facilitator.                                                   |
| pass  scheme_known              |   6     The payment scheme is one tx402 can route.                                            |
| pass  tls_ok                    |   5     The endpoint was reached over a valid TLS connection.                                 |
| warn  timeout_sane              |   4     The authorization window is outside the maximum tx402 will sign for.                  |
| pass  redirect_scheme_downgrade |   3     No redirect downgraded the connection.                                                |
| pass  wire_form                 |   3     The endpoint serves the x402 v2 header form.                                          |
| pass  amount_magnitude_band     |   2     The amount is within the range we see for x402 endpoints.                             |

Methodology: https://tools.tx402.io/methodology?v=v1

## TEST WITH TX402

Nothing below sends a key anywhere. tx402 commits policy and budget before the signer is reachable,
so a refusal is a payment that was never authorized.

```bash
npx tx402 call "https://agent402.tools/api/random" \
  --max-spend "0.001000 USDC" \
  --network "eip155:8453" \
  --dry-run

# --dry-run stops after the policy decision. Nothing is signed and nothing is spent.
```

```ts
import { createTx402Client } from "tx402";
// Your signer stays in your process. tools.tx402.io never sees a key,
// never asks for one, and cannot build a payment.
import { signers } from "./signers.js";

const tx402 = createTx402Client({
  signers,
  policy: {
    maxPerRequest: "0.001000 USDC",
    allowedDomains: ["agent402.tools"],
    allowedNetworks: ["eip155:8453"],
  },
});

// Policy and budget are committed before the signer is reachable, so a
// refusal here is a payment that was never authorized.
const response = await tx402.fetch("https://agent402.tools/api/random");
```

```python
from tx402 import Tx402Client, Policy

# Your signer stays in your process. tools.tx402.io never sees a key,
# never asks for one, and cannot build a payment.
tx402 = Tx402Client(
    evm_signer=evm,
    policy=Policy(
        max_per_request="0.001000 USDC",
        allowed_domains=["agent402.tools"],
        allowed_networks=["eip155:8453"],
    ),
)

# Policy and budget are committed before the signer is reachable, so a
# refusal here is a payment that was never authorized.
response = tx402.fetch("https://agent402.tools/api/random")
```

---

| Representation | URL |
| -------------- | --- |
| HTML     | https://tools.tx402.io/inspect?url=https%3A%2F%2Fagent402.tools%2Fapi%2Frandom |
| Markdown | https://tools.tx402.io/inspect.md?url=https%3A%2F%2Fagent402.tools%2Fapi%2Frandom |
| JSON     | https://tools.tx402.io/api/v1/inspect?url=https%3A%2F%2Fagent402.tools%2Fapi%2Frandom |
| History  | https://tools.tx402.io/history?url=https%3A%2F%2Fagent402.tools%2Fapi%2Frandom |

Decoded by `tx402@0.2.0` — the same strict decoder the SDK runs before it pays.
