These are observations, not accusations. A band of LOW, MEDIUM or HIGH describes how much of what we check we were able to confirm — it is not a judgement about the operator of an endpoint. Every signal, its weight and its rationale are published on the methodology page, and any operator can claim an endpoint, correct a fact or opt out.

What does this x402 endpoint charge?

https only. We fetch it once, read the 402, and stop.

0.002500 USDC per request

https://2s.io/api/medical/icd10
Risk band: LOW 100/100

Observed 2026-08-15T14:32:37Z · 63 ms · HTTP 402 · v1 methodology

  • WIRE_FORMS_DISAGREEBoth wire forms were served and they describe different terms.

Endpoint

What we observed about the endpoint
URL https://2s.io/api/medical/icd10
Canonical https://2s.io/api/medical/icd10
Endpoint id 1b67ffc6d68e44f572cb247963cc7068
HTTP status 402
Latency 63 ms
Redirects 0
TLS handshake okThe negotiated TLS version is not exposed to a Worker.
Wire form both the v2 header and a v1 body
Bytes read 7967
Strict decoder accepteddecodePaymentRequired, imported from tx402 — the same code the SDK runs before it pays.

Payment

accepted by the decoder

These terms were accepted by the strict decoder tx402 uses before it pays.

The payment terms this endpoint asks for
Price 0.002500 USDC
Amount (atomic) 2500
Scheme exact
Network eip155:8453 in manifestRecognized means present in the tx402 signed release manifest. Nothing more is claimed.
Asset USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 in manifestRecognized means present in the tx402 signed release manifest. Nothing more is claimed.
Pay to 0x2b6D4988Db4723E6908Db86Ab2b8dFBc51FC32C5
Pay to declared dynamic nox402 v2 has no on-the-wire declaration of a dynamic payTo, so this is usually unobservable.
Authorization window 60s
Resource https://2s.io/api/medical/icd10
MIME type application/json
Description Verify and search ICD-10-CM diagnosis codes against the official US code set (FY2026, ~98k entries). Pass code (with or without the dot, e.g. E11.9 or E119) to confirm the code exists and list its more-specific child codes, or q to keyword-search code descriptions (e.g. "type 2 diabetes neuropathy"). Optional billable_only=true restricts results to codes valid for claim submission; limit caps results (1-50, default 10). Returns a verified flag, the exact match if any, and matched codes with billable status plus short and long descriptions. Data: CMS/NCHS ICD-10-CM (public domain), refreshed each US fiscal year. Use to confirm diagnosis codes are real and current before placing them in claims, prior authorizations, or clinical documents.
Facilitator not observed

This endpoint offers 2 ways to pay. The card above describes the first, which is the order the server stated its own preference in.

Other accepted ways to pay
Alternative 2 2500 (atomic units) · solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp · exact

Risk

Band: LOW 100/100 · v1 · static_only

A band describes how much of what we check we were able to confirm. It is not a judgement about the operator of an endpoint.

  • Result: pass 25 The challenge decodes under the strict x402 decoder tx402 uses before paying. challenge_decodes
  • Result: pass 15 The challenge describes the endpoint that served it. resource_origin_match
  • Result: pass 12 The amount is a canonical atomic integer. amount_canonical
  • Result: pass 12 The recipient is a well-formed address for the declared network. pay_to_wellformed
  • Result: pass 8 The network is in the tx402 signed release manifest. network_recognized
  • Result: pass 8 The asset is in the tx402 signed release manifest for this network. asset_recognized
  • Result: skip The challenge named no facilitator. facilitator_known
  • Result: pass 6 The payment scheme is one tx402 can route. scheme_known
  • Result: pass 5 The endpoint was reached over a valid TLS connection. tls_ok
  • Result: pass 4 The authorization window is within the maximum tx402 will sign for. timeout_sane
  • Result: pass 3 No redirect downgraded the connection. redirect_scheme_downgrade
  • Result: pass 3 The endpoint serves the x402 v2 header form. wire_form
  • Result: pass 2 The amount is within the range we see for x402 endpoints. amount_magnitude_band
Weights, thresholds and the rationale for each signal are published at the methodology page. Adding up the weights above reproduces the score — that reproducibility is how a verdict can be argued with.

Security

nothing failing

A check that could not run reports skip, and a skip is never counted as a pass.

  • Result: pass wire_form_detected Served as both.
  • Result: pass base64_strict The strict decoder accepted the header's base64 framing.
  • Result: pass json_wellformed
  • Result: pass x402_version_known Declared x402Version 2.
  • Result: pass accepts_present The challenge offers 2 ways to pay.
  • Result: pass size_within_limit Read 7967 bytes, within the probe's cap.
  • Result: pass network_caip2_wellformed network: eip155:8453
  • Result: pass network_recognized Recognized means present in the tx402 signed release manifest.
  • Result: pass asset_recognized Recognized means present in the tx402 signed release manifest.
  • Result: pass amount_atomic_canonical
  • Result: pass amount_positive
  • Result: pass pay_to_wellformed
  • Result: pass max_timeout_sane
  • Result: pass resource_origin_match
  • Result: pass scheme_known
  • Result: skip facilitator_known The challenge named no facilitator.
  • Result: pass mime_type_wellformed mimeType: application/json
  • Result: pass extra_wellformed `extra` carries 2 field(s), preserved verbatim.
  • Result: skip amount_within_observed_range needs our data No prior observations of this endpoint.
  • Result: skip recipient_matches_observed needs our data No prior observations of this endpoint.
Checks marked “needs our data” compare this scan against the corpus, which is still filling up.

Observed

What the corpus knows about this endpoint
First seen 2026-08-15T04:00:12Z
Last seen 2026-08-15T14:32:37Z
Scans recorded 3
Availability (30d) not measured yet
Latency p50 not measured yet
Recorded changes to this endpoint's terms
2026-08-15T06:15:45Z availability_state: status unreachable → active
2026-08-15T06:15:45Z first_seen: challenge_hash — → 8390a7c82710e7272ac3b4dc18d4cef5f2d4263949a7909360286b8f3c5c6a3a

Test with tx402 →

Pre-filled with this endpoint's real terms. Your signer stays in your process — this service never sees a key, never asks for one, and cannot build a payment.

CLI — dry run, nothing is signed
npx tx402 call "https://2s.io/api/medical/icd10" \
  --max-spend "0.002500 USDC" \
  --network "eip155:8453" \
  --dry-run

# --dry-run stops after the policy decision. Nothing is signed and nothing is spent.
TypeScript
import { createTx402Client } from "tx402";
// Your signer stays in your process. tools.tx402.io never sees a key,
// never asks for one, and cannot build a payment.
import { signers } from "./signers.js";

const tx402 = createTx402Client({
  signers,
  policy: {
    maxPerRequest: "0.002500 USDC",
    allowedDomains: ["2s.io"],
    allowedNetworks: ["eip155:8453"],
  },
});

// Policy and budget are committed before the signer is reachable, so a
// refusal here is a payment that was never authorized.
const response = await tx402.fetch("https://2s.io/api/medical/icd10");
Python
from tx402 import Tx402Client, Policy

# Your signer stays in your process. tools.tx402.io never sees a key,
# never asks for one, and cannot build a payment.
tx402 = Tx402Client(
    evm_signer=evm,
    policy=Policy(
        max_per_request="0.002500 USDC",
        allowed_domains=["2s.io"],
        allowed_networks=["eip155:8453"],
    ),
)

# Policy and budget are committed before the signer is reachable, so a
# refusal here is a payment that was never authorized.
response = tx402.fetch("https://2s.io/api/medical/icd10")
This report, as JSON or Markdown
curl -sS 'https://tools.tx402.io/api/v1/inspect?url=https%3A%2F%2F2s.io%2Fapi%2Fmedical%2Ficd10'

# The same result as Markdown, for a terminal or an agent:
curl -sS -H 'Accept: text/markdown' 'https://tools.tx402.io/inspect?url=https%3A%2F%2F2s.io%2Fapi%2Fmedical%2Ficd10'

Share this report

Share links expire. Nothing is recorded about who created one.

The challenge, as served

Public data: the endpoint serves this to anyone who asks. It is shown exactly as it arrived, truncated to the documented cap.

raw challenge
eyJ4NDAyVmVyc2lvbiI6MiwiYWNjZXB0cyI6W3sic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoiZWlwMTU1Ojg0NTMiLCJhbW91bnQiOiIyNTAwIiwiYXNzZXQiOiIweDgzMzU4OWZDRDZlRGI2RTA4ZjRjN0MzMkQ0ZjcxYjU0YmRBMDI5MTMiLCJwYXlUbyI6IjB4MmI2RDQ5ODhEYjQ3MjNFNjkwOERiODZBYjJiOGRGQmM1MUZDMzJDNSIsIm1heFRpbWVvdXRTZWNvbmRzIjo2MCwiZXh0cmEiOnsibmFtZSI6IlVTRCBDb2luIiwidmVyc2lvbiI6IjIifX0seyJzY2hlbWUiOiJleGFjdCIsIm5ldHdvcmsiOiJzb2xhbmE6NWV5a3Q0VXNGdjhQOE5KZFRSRXBZMXZ6cUtxWkt2ZHAiLCJhbW91bnQiOiIyNTAwIiwiYXNzZXQiOiJFUGpGV2RkNUF1ZnFTU3FlTTJxTjF4enliYXBDOEc0d0VHR2tad3lURHQxdiIsInBheVRvIjoiVFc2bnRhR3p2ajYzWmdQanN6ZDRGQ0dtVlRHZnp2MU1BWVpialljeVdobiIsIm1heFRpbWVvdXRTZWNvbmRzIjo2MCwiZXh0cmEiOnsibmFtZSI6IlVTREMiLCJ2ZXJzaW9uIjoiMSIsImZlZVBheWVyIjoiR1ZKSjdyZEdpWHI1eGFZYlJ3UmJqZmFKTDdmbXdSeWdGaTFINmFHcUR2ZWIifX1dLCJyZXNvdXJjZSI6eyJ1cmwiOiJodHRwczovLzJzLmlvL2FwaS9tZWRpY2FsL2ljZDEwIiwiZGVzY3JpcHRpb24iOiJWZXJpZnkgYW5kIHNlYXJjaCBJQ0QtMTAtQ00gZGlhZ25vc2lzIGNvZGVzIGFnYWluc3QgdGhlIG9mZmljaWFsIFVTIGNvZGUgc2V0IChGWTIwMjYsIH45OGsgZW50cmllcykuIFBhc3MgY29kZSAod2l0aCBvciB3aXRob3V0IHRoZSBkb3QsIGUuZy4gRTExLjkgb3IgRTExOSkgdG8gY29uZmlybSB0aGUgY29kZSBleGlzdHMgYW5kIGxpc3QgaXRzIG1vcmUtc3BlY2lmaWMgY2hpbGQgY29kZXMsIG9yIHEgdG8ga2V5d29yZC1zZWFyY2ggY29kZSBkZXNjcmlwdGlvbnMgKGUuZy4gXCJ0eXBlIDIgZGlhYmV0ZXMgbmV1cm9wYXRoeVwiKS4gT3B0aW9uYWwgYmlsbGFibGVfb25seT10cnVlIHJlc3RyaWN0cyByZXN1bHRzIHRvIGNvZGVzIHZhbGlkIGZvciBjbGFpbSBzdWJtaXNzaW9uOyBsaW1pdCBjYXBzIHJlc3VsdHMgKDEtNTAsIGRlZmF1bHQgMTApLiBSZXR1cm5zIGEgdmVyaWZpZWQgZmxhZywgdGhlIGV4YWN0IG1hdGNoIGlmIGFueSwgYW5kIG1hdGNoZWQgY29kZXMgd2l0aCBiaWxsYWJsZSBzdGF0dXMgcGx1cyBzaG9ydCBhbmQgbG9uZyBkZXNjcmlwdGlvbnMuIERhdGE6IENNUy9OQ0hTIElDRC0xMC1DTSAocHVibGljIGRvbWFpbiksIHJlZnJlc2hlZCBlYWNoIFVTIGZpc2NhbCB5ZWFyLiBVc2UgdG8gY29uZmlybSBkaWFnbm9zaXMgY29kZXMgYXJlIHJlYWwgYW5kIGN1cnJlbnQgYmVmb3JlIHBsYWNpbmcgdGhlbSBpbiBjbGFpbXMsIHByaW9yIGF1dGhvcml6YXRpb25zLCBvciBjbGluaWNhbCBkb2N1bWVudHMuIiwibWltZVR5cGUiOiJhcHBsaWNhdGlvbi9qc29uIiwic2VydmljZU5hbWUiOiIycyIsImljb25VcmwiOiJodHRwczovLzJzLmlvL2ljb24tNTEyLnBuZyIsInRhZ3MiOlsicHVibGljLXJlY29yZHMiLCJpZGVudGlmaWVycyIsImFpLWFnZW50cyIsInVzLWdvdi1kYXRhIiwieDQwMiIsInVwdG8tYmlsbGluZyIsImFpLWdhdGV3YXkiLCJhZ2VudC1pbmZyYXN0cnVjdHVyZSJdfSwiZXJyb3IiOiJQQVlNRU5ULVNJR05BVFVSRSByZXF1aXJlZCIsImV4dGVuc2lvbnMiOnsiYmF6YWFyIjp7ImluZm8iOnsiaW5wdXQiOnsidHlwZSI6Imh0dHAiLCJtZXRob2QiOiJHRVQiLCJxdWVyeVBhcmFtcyI6eyJjb2RlIjoieHh4IiwicSI6Inh4eCIsImJpbGxhYmxlX29ubHkiOmZhbHNlLCJsaW1pdCI6MX19fSwic2NoZW1hIjp7IiRzY2hlbWEiOiJodHRwczovL2pzb24tc2NoZW1hLm9yZy9kcmFmdC8yMDIwLTEyL3NjaGVtYSIsInR5cGUiOiJvYmplY3QiLCJwcm9wZXJ0aWVzIjp7ImlucHV0Ijp7InR5cGUiOiJvYmplY3QiLCJwcm9wZXJ0aWVzIjp7InR5cGUiOnsiY29uc3QiOiJodHRwIn0sIm1ldGhvZCI6eyJjb25zdCI6IkdFVCJ9LCJxdWVyeVBhcmFtcyI6eyJ0eXBlIjoib2JqZWN0IiwicHJvcGVydGllcyI6eyJjb2RlIjp7InR5cGUiOiJzdHJpbmciLCJtaW5MZW5ndGgiOjMsIm1heExlbmd0aCI6OSwiZGVzY3JpcHRpb24iOiJJQ0QtMTAtQ00gY29kZSB0byB2ZXJpZnksIHdpdGggb3Igd2l0aG91dCB0aGUgZG90IChlLmcuIEUxMS45IG9yIEUxMTkpLiBSZXR1cm5zIHRoZSBleGFjdCBtYXRjaCBwbHVzIG1vcmUtc3BlY2lmaWMgY2hpbGQgY29kZXMuIFByb3ZpZGUgZWl0aGVyIGNvZGUgb3IgcSwgbm90IGJvdGguIn0sInEiOnsidHlwZSI6InN0cmluZyIsIm1pbkxlbmd0aCI6MywibWF4TGVuZ3RoIjoxMjAsImRlc2NyaXB0aW9uIjoiS2V5d29yZCBzZWFyY2ggb3ZlciBvZmZpY2lhbCBjb2RlIGRlc2NyaXB0aW9ucyAoZS5nLiBcInR5cGUgMiBkaWFiZXRlcyBuZXVyb3BhdGh5XCIpLiBFdmVyeSB3b3JkIG11c3QgbWF0Y2guIFByb3ZpZGUgZWl0aGVyIGNvZGUgb3IgcSwgbm90IGJvdGguIn0sImJpbGxhYmxlX29ubHkiOnsidHlwZSI6ImJvb2xlYW4iLCJkZXNjcmlwdGlvbiI6IldoZW4gdHJ1ZSwgb25seSByZXR1cm4gY29kZXMgdmFsaWQgZm9yIGNsYWltIHN1Ym1pc3Npb24gKGV4Y2x1ZGVzIGNhdGVnb3J5IGhlYWRlcnMpLiJ9LCJsaW1pdCI6eyJ0eXBlIjoiaW50ZWdlciIsIm1pbmltdW0iOjEsIm1heGltdW0iOjUwLCJkZXNjcmlwdGlvbiI6Ik1heGltdW0gY29kZXMgcmV0dXJuZWQgKDEtNTAsIGRlZmF1bHQgMTApLiJ9fSwiYWRkaXRpb25hbFByb3BlcnRpZXMiOmZhbHNlfX0sInJlcXVpcmVkIjpbInR5cGUiLCJtZXRob2QiLCJxdWVyeVBhcmFtcyJdfX0sInJlcXVpcmVkIjpbImlucHV0Il19fX19

SHA-256 of the canonicalized challenge: 8390a7c82710e7272ac3b4dc18d4cef5f2d4263949a7909360286b8f3c5c6a3a

Raw signals

The exact input the scoring function was given. A signal we could not determine has observed: false and contributes nothing to the score — it is never counted as a failure.

signals
[
  {
    "id": "probe_ok",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "challenge_served",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "challenge_decodes",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "wire_form",
    "value": "both",
    "observed": true,
    "detail": null
  },
  {
    "id": "x402_version",
    "value": 2,
    "observed": true,
    "detail": null
  },
  {
    "id": "tls_ok",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "tls_protocol",
    "value": null,
    "observed": false,
    "detail": "The negotiated TLS version is not exposed to the probe."
  },
  {
    "id": "redirect_count",
    "value": 0,
    "observed": true,
    "detail": null
  },
  {
    "id": "redirect_scheme_downgrade",
    "value": false,
    "observed": true,
    "detail": "Cross-scheme redirects are refused."
  },
  {
    "id": "resource_origin_match",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "network_recognized",
    "value": true,
    "observed": true,
    "detail": "Recognized means present in the tx402 signed release manifest."
  },
  {
    "id": "asset_recognized",
    "value": true,
    "observed": true,
    "detail": "Recognized means present in the tx402 signed release manifest."
  },
  {
    "id": "facilitator_known",
    "value": null,
    "observed": false,
    "detail": "The challenge named no facilitator."
  },
  {
    "id": "amount_canonical",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "amount_magnitude_band",
    "value": "micro",
    "observed": true,
    "detail": null
  },
  {
    "id": "pay_to_wellformed",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "pay_to_declared_dynamic",
    "value": false,
    "observed": true,
    "detail": null
  },
  {
    "id": "timeout_sane",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "scheme_known",
    "value": true,
    "observed": true,
    "detail": null
  },
  {
    "id": "requirement_count",
    "value": 2,
    "observed": true,
    "detail": null
  },
  {
    "id": "challenge_size_bytes",
    "value": 7967,
    "observed": true,
    "detail": null
  },
  {
    "id": "first_seen_age_days",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "scan_count",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "availability_30d",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "latency_p50_ms",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "price_changes_90d",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "recipient_changes_90d",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "recipient_unstable_undeclared",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  },
  {
    "id": "terms_changed_within_24h",
    "value": null,
    "observed": false,
    "detail": "No history yet."
  }
]

JSON Markdown Methodology Error reference