These are observations, not accusations. A band of LOW, MEDIUM or HIGH describes how much of what we check we were able to confirm — it is not a judgement about the operator of an endpoint. Every signal, its weight and its rationale are published on the methodology page, and any operator can claim an endpoint, correct a fact or opt out.
What does this x402 endpoint charge?
0.003000 USDC per request
https://edgar.apitoll.cloud/v1/edgar/filingsEndpoint
| URL | https://edgar.apitoll.cloud/v1/edgar/filings |
|---|---|
| Canonical | https://edgar.apitoll.cloud/v1/edgar/filings |
| Endpoint id | 6653c926d2bc55d53d88c4dd8577fe65 |
| HTTP status | 402 |
| Latency | 585 ms |
| Redirects | 0 |
| TLS | handshake okThe negotiated TLS version is not exposed to a Worker. |
| Wire form | x402 v2 — PAYMENT-REQUIRED header |
| Bytes read | 217 |
| Strict decoder | accepteddecodePaymentRequired, imported from tx402 — the same code the SDK runs before it pays. |
Payment
accepted by the decoderThese terms were accepted by the strict decoder tx402 uses before it pays.
| Price | 0.003000 USDC |
|---|---|
| Amount (atomic) | 3000 |
| Scheme | exact |
| Network | eip155:8453 in manifestRecognized means present in the tx402 signed release manifest. Nothing more is claimed. |
| Asset | USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 in manifestRecognized means present in the tx402 signed release manifest. Nothing more is claimed. |
| Pay to | 0x58BdAD5e654691aC5eD4631758f3d8DA00666B6c |
| Pay to declared dynamic | nox402 v2 has no on-the-wire declaration of a dynamic payTo, so this is usually unobservable. |
| Authorization window | 300s |
| Resource | https://edgar.apitoll.cloud/v1/edgar/filings |
| MIME type | application/json |
| Description | Latest SEC EDGAR filings for any US-listed company by stock ticker or CIK: 10-K annual reports, 10-Q quarterly reports, and 8-K material events. Resolves ticker to CIK via SEC's official index and returns the parsed filing (company, form type, dated items). Sourced live from data.sec.gov. |
| Facilitator | not observed |
This endpoint offers 2 ways to pay. The card above describes the first, which is the order the server stated its own preference in.
| Alternative 2 | 3000 (atomic units) · solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp · exact |
|---|
Risk
Band: LOW 96/100 · v1 · static_onlyA band describes how much of what we check we were able to confirm. It is not a judgement about the operator of an endpoint.
- Result: pass 25 The challenge decodes under the strict x402 decoder tx402 uses before paying. challenge_decodes
- Result: pass 15 The challenge describes the endpoint that served it. resource_origin_match
- Result: pass 12 The amount is a canonical atomic integer. amount_canonical
- Result: pass 12 The recipient is a well-formed address for the declared network. pay_to_wellformed
- Result: pass 8 The network is in the tx402 signed release manifest. network_recognized
- Result: pass 8 The asset is in the tx402 signed release manifest for this network. asset_recognized
- Result: skip — The challenge named no facilitator. facilitator_known
- Result: pass 6 The payment scheme is one tx402 can route. scheme_known
- Result: pass 5 The endpoint was reached over a valid TLS connection. tls_ok
- Result: warn 4 The authorization window is outside the maximum tx402 will sign for. timeout_sane
- Result: pass 3 No redirect downgraded the connection. redirect_scheme_downgrade
- Result: pass 3 The endpoint serves the x402 v2 header form. wire_form
- Result: pass 2 The amount is within the range we see for x402 endpoints. amount_magnitude_band
Security
1 to look at
A check that could not run reports skip, and a skip is never counted as a pass.
- Result: pass wire_form_detected Served as v2-header.
- Result: pass base64_strict The strict decoder accepted the header's base64 framing.
- Result: pass json_wellformed
- Result: pass x402_version_known Declared x402Version 2.
- Result: pass accepts_present The challenge offers 2 ways to pay.
- Result: pass size_within_limit Read 217 bytes, within the probe's cap.
- Result: pass network_caip2_wellformed network: eip155:8453
- Result: pass network_recognized Recognized means present in the tx402 signed release manifest.
- Result: pass asset_recognized Recognized means present in the tx402 signed release manifest.
- Result: pass amount_atomic_canonical
- Result: pass amount_positive
- Result: pass pay_to_wellformed
- Result: warn max_timeout_sane Authorization window 300s exceeds the tx402 maximum of 60s.
- Result: pass resource_origin_match
- Result: pass scheme_known
- Result: skip facilitator_known The challenge named no facilitator.
- Result: pass mime_type_wellformed mimeType: application/json
- Result: pass extra_wellformed `extra` carries 2 field(s), preserved verbatim.
- Result: skip amount_within_observed_range needs our data No prior observations of this endpoint.
- Result: skip recipient_matches_observed needs our data No prior observations of this endpoint.
Observed
| First seen | 2026-08-15T04:00:12Z |
|---|---|
| Last seen | 2026-08-15T14:34:02Z |
| Scans recorded | 2 |
| Availability (30d) | not measured yet |
| Latency p50 | not measured yet |
| 2026-08-15T04:45:31Z | first_seen: challenge_hash — → c21f6a12671c3a6c628096a2a3512f511d36aa28c2386f379c70497ec3c380d7 |
|---|
Test with tx402 →
Pre-filled with this endpoint's real terms. Your signer stays in your process — this service never sees a key, never asks for one, and cannot build a payment.
npx tx402 call "https://edgar.apitoll.cloud/v1/edgar/filings" \
--max-spend "0.003000 USDC" \
--network "eip155:8453" \
--dry-run
# --dry-run stops after the policy decision. Nothing is signed and nothing is spent.
import { createTx402Client } from "tx402";
// Your signer stays in your process. tools.tx402.io never sees a key,
// never asks for one, and cannot build a payment.
import { signers } from "./signers.js";
const tx402 = createTx402Client({
signers,
policy: {
maxPerRequest: "0.003000 USDC",
allowedDomains: ["edgar.apitoll.cloud"],
allowedNetworks: ["eip155:8453"],
},
});
// Policy and budget are committed before the signer is reachable, so a
// refusal here is a payment that was never authorized.
const response = await tx402.fetch("https://edgar.apitoll.cloud/v1/edgar/filings");
from tx402 import Tx402Client, Policy
# Your signer stays in your process. tools.tx402.io never sees a key,
# never asks for one, and cannot build a payment.
tx402 = Tx402Client(
evm_signer=evm,
policy=Policy(
max_per_request="0.003000 USDC",
allowed_domains=["edgar.apitoll.cloud"],
allowed_networks=["eip155:8453"],
),
)
# Policy and budget are committed before the signer is reachable, so a
# refusal here is a payment that was never authorized.
response = tx402.fetch("https://edgar.apitoll.cloud/v1/edgar/filings")
curl -sS 'https://tools.tx402.io/api/v1/inspect?url=https%3A%2F%2Fedgar.apitoll.cloud%2Fv1%2Fedgar%2Ffilings'
# The same result as Markdown, for a terminal or an agent:
curl -sS -H 'Accept: text/markdown' 'https://tools.tx402.io/inspect?url=https%3A%2F%2Fedgar.apitoll.cloud%2Fv1%2Fedgar%2Ffilings'
The challenge, as served
Public data: the endpoint serves this to anyone who asks. It is shown exactly as it arrived, truncated to the documented cap.
eyJ4NDAyVmVyc2lvbiI6MiwiZXJyb3IiOiJQYXltZW50IHJlcXVpcmVkIiwicmVzb3VyY2UiOnsidXJsIjoiaHR0cHM6Ly9lZGdhci5hcGl0b2xsLmNsb3VkL3YxL2VkZ2FyL2ZpbGluZ3MiLCJkZXNjcmlwdGlvbiI6IkxhdGVzdCBTRUMgRURHQVIgZmlsaW5ncyBmb3IgYW55IFVTLWxpc3RlZCBjb21wYW55IGJ5IHN0b2NrIHRpY2tlciBvciBDSUs6IDEwLUsgYW5udWFsIHJlcG9ydHMsIDEwLVEgcXVhcnRlcmx5IHJlcG9ydHMsIGFuZCA4LUsgbWF0ZXJpYWwgZXZlbnRzLiBSZXNvbHZlcyB0aWNrZXIgdG8gQ0lLIHZpYSBTRUMncyBvZmZpY2lhbCBpbmRleCBhbmQgcmV0dXJucyB0aGUgcGFyc2VkIGZpbGluZyAoY29tcGFueSwgZm9ybSB0eXBlLCBkYXRlZCBpdGVtcykuIFNvdXJjZWQgbGl2ZSBmcm9tIGRhdGEuc2VjLmdvdi4iLCJtaW1lVHlwZSI6ImFwcGxpY2F0aW9uL2pzb24iLCJzZXJ2aWNlTmFtZSI6IkFwaVRvbGwgU0VDIEZpbGluZ3MiLCJ0YWdzIjpbInNlYyIsImVkZ2FyIiwiZmlsaW5ncyIsIjEwLUsiLCIxMC1RIiwiOC1LIiwiYW5udWFsLXJlcG9ydCIsImZpbmFuY2UiLCJhcGl0b2xsIl19LCJhY2NlcHRzIjpbeyJzY2hlbWUiOiJleGFjdCIsIm5ldHdvcmsiOiJlaXAxNTU6ODQ1MyIsImFtb3VudCI6IjMwMDAiLCJhc3NldCI6IjB4ODMzNTg5ZkNENmVEYjZFMDhmNGM3QzMyRDRmNzFiNTRiZEEwMjkxMyIsInBheVRvIjoiMHg1OEJkQUQ1ZTY1NDY5MWFDNWVENDYzMTc1OGYzZDhEQTAwNjY2QjZjIiwibWF4VGltZW91dFNlY29uZHMiOjMwMCwiZXh0cmEiOnsibmFtZSI6IlVTRCBDb2luIiwidmVyc2lvbiI6IjIifX0seyJzY2hlbWUiOiJleGFjdCIsIm5ldHdvcmsiOiJzb2xhbmE6NWV5a3Q0VXNGdjhQOE5KZFRSRXBZMXZ6cUtxWkt2ZHAiLCJhbW91bnQiOiIzMDAwIiwiYXNzZXQiOiJFUGpGV2RkNUF1ZnFTU3FlTTJxTjF4enliYXBDOEc0d0VHR2tad3lURHQxdiIsInBheVRvIjoiN2tQV2lFYkRYdTMzRm9tS0c2bUdhN1I4SEdTZlVHRnNBb0tGWmVCRVJKYUgiLCJtYXhUaW1lb3V0U2Vjb25kcyI6MzAwLCJleHRyYSI6eyJmZWVQYXllciI6IkhjM3NkRUFzQ0dRY3BnZml2eXdvZzl1d3RrOGdVQlVaZ3N4ZE1FMUVKeTg4In19XSwiZXh0ZW5zaW9ucyI6eyJiYXphYXIiOnsiaW5mbyI6eyJpbnB1dCI6eyJ0eXBlIjoiaHR0cCIsInF1ZXJ5UGFyYW1zIjp7InRpY2tlciI6IkFBUEwiLCJmb3JtIjoiMTAtSyIsImxpbWl0Ijo1fSwibWV0aG9kIjoiR0VUIn0sIm91dHB1dCI6eyJ0eXBlIjoianNvbiIsImV4YW1wbGUiOnsicmVzb2x2ZWQiOnsiY2lrIjoiMDAwMDMyMDE5MyIsImNpa0ludCI6MzIwMTkzLCJ0aWNrZXIiOiJBQVBMIiwiY29tcGFueU5hbWUiOiJBcHBsZSBJbmMuIiwiZW50aXR5VHlwZSI6Im9wZXJhdGluZyIsInNpYyI6IjM1NzEiLCJ0aWNrZXJTbmFwc2hvdERhdGUiOiIyMDI2LTA1LTMwIiwibWFwcGluZ0FnZVNlY29uZHMiOjE4NDJ9LCJmb3JtIjoiMTAtSyIsImFwcGxpZWRTaW5jZSI6bnVsbCwiY291bnQiOjEsIml0ZW1zIjpbeyJjaWsiOiIwMDAwMzIwMTkzIiwiYWNjZXNzaW9uTnVtYmVyIjoiMDAwMDMyMDE5My0yNC0wMDAxMjMiLCJmb3JtIjoiMTAtSyIsImZpbGluZ0RhdGUiOiIyMDI0LTExLTAxIiwicmVwb3J0RGF0ZSI6IjIwMjQtMDktMjgiLCJwcmltYXJ5RG9jdW1lbnQiOiJhYXBsLTIwMjQwOTI4Lmh0bSIsImZpbGluZ1VybCI6Imh0dHBzOi8vd3d3LnNlYy5nb3YvQXJjaGl2ZXMvZWRnYXIvZGF0YS8zMjAxOTMvMDAwMDMyMDE5MzI0MDAwMTIzL2FhcGwtMjAyNDA5MjguaHRtIiwiaW1tdXRhYmxlIjp0cnVlfV0sInRydW5jYXRpb24iOm51bGwsInNvdXJjZSI6eyJuYW1lIjoiZGF0YS5zZWMuZ292IiwiZmV0Y2hlZEF0IjoiMjAyNi0wNS0zMFQxNDoyMjowMVoiLCJzZXJ2ZWRGcm9tQ2FjaGUiOnRydWUsInNvdXJjZUxhc3RGZXRjaGVkQXQiOiIyMDI2LTA1LTMwVDE0OjExOjQzWiJ9LCJtZXRhIjp7InJlbGF0ZWRFbmRwb2ludHMiOltdfX19fSwic2NoZW1hIjp7IiRzY2hlbWEiOiJodHRwczovL2pzb24tc2NoZW1hLm9yZy9kcmFmdC8yMDIwLTEyL3NjaGVtYSIsInR5cGUiOiJvYmplY3QiLCJwcm9wZXJ0aWVzIjp7ImlucHV0Ijp7InR5cGUiOiJvYmplY3QiLCJwcm9wZXJ0aWVzIjp7InR5cGUiOnsidHlwZSI6InN0cmluZyIsImNvbnN0IjoiaHR0cCJ9LCJtZXRob2QiOnsidHlwZSI6InN0cmluZyIsImVudW0iOlsiR0VUIl19LCJxdWVyeVBhcmFtcyI6eyJ0eXBlIjoib2JqZWN0IiwicHJvcGVydGllcyI6eyJjaWsiOnsidHlwZSI6InN0cmluZyIsInBhdHRlcm4iOiJeXFxkezEsMTB9JCIsImRlc2NyaXB0aW9uIjoiU0VDIENJSyAoMS0xMCBkaWdpdHMpLiBYT1Igd2l0aCB0aWNrZXIuIn0sInRpY2tlciI6eyJ0eXBlIjoic3RyaW5nIiwicGF0dGVybiI6Il5bQS1aYS16LlxcLV17MSwxMH0kIiwiZGVzY3JpcHRpb24iOiJTdG9jayB0aWNrZXIsIGNhc2UtaW5zZW5zaXRpdmUuIFhPUiB3aXRoIGNpay4ifSwiZm9ybSI6eyJ0eXBlIjoic3RyaW5nIiwiZW51bSI6WyIxMC1LIiwiMTAtUSIsIjgtSyJdLCJkZXNjcmlwdGlvbiI6IlNFQyBmb3JtIGZvciAvZmlsaW5nczogMTAtSywgMTAtUSwgOC1LLiBBbGlhc2VzIGFjY2VwdGVkICgxMGssIDEwLXEsIDhrLCBhbm51YWwsIHF1YXJ0ZXJseSwgY3VycmVudC1yZXBvcnQsIG1hdGVyaWFsLWV2ZW50KS4gRm9ybSA0IGFuZCAxM0YtSFIgaGF2ZSB0aGVpciBvd24gcm91dGVzIOKAlCBHRVQgL3YxL2VkZ2FyL2luc2lkZXIgYW5kIEdFVCAvdjEvZWRnYXIvaG9sZGluZ3MuIn0sInNpbmNlIjp7InR5cGUiOiJzdHJpbmciLCJwYXR0ZXJuIjoiXlxcZHs0fS1cXGR7Mn0tXFxkezJ9JCIsImRlc2NyaXB0aW9uIjoiSW5jbHVzaXZlIGxvd2VyIGJvdW5kIG9uIGZpbGluZ0RhdGUgKFlZWVktTU0tREQpLCB3aXRoaW4gdGhlIGxhc3QgNSB5ZWFycy4ifSwibGltaXQiOnsidHlwZSI6ImludGVnZXIiLCJtaW5pbXVtIjoxLCJtYXhpbXVtIjo1MCwiZGVzY3JpcHRpb24iOiJQZXItZm9ybSBjZWlsaW5nOiAxMC1LLzEwLVEvOC1LPTUwLiJ9LCJpbmNsdWRlQW1lbmRtZW50cyI6eyJ0eXBlIjoiYm9vbGVhbiIsImRlc2NyaXB0aW9uIjoiV2hlbiB0cnVlIChkZWZhdWx0KSwgYW1lbmRtZW50IHN1ZmZpeGVzICgxMC1LL0EpIHN1cmZhY2UgYWxvbmdzaWRlIHRoZSBiYXNlIGZvcm0uIn19LCJyZXF1aXJlZCI6WyJmb3JtIl19fSwicmVxdWlyZWQiOlsidHlwZSIsIm1ldGhvZCJdLCJhZGRpdGlvbmFsUHJvcGVydGllcyI6ZmFsc2V9LCJvdXRwdXQiOnsidHlwZSI6Im9iamVjdCIsInByb3BlcnRpZXMiOnsidHlwZSI6eyJ0eXBlIjoic3RyaW5nIn0sImV4YW1wbGUiOnsidHlwZSI6Im9iamVjdCIsInByb3BlcnRpZXMiOnsicmVzb2x2ZWQiOnsidHlwZSI6Im9iamVjdCJ9LCJmb3JtIjp7InR5cGUiOiJzdHJpbmciLCJlbnVtIjpbIjEwLUsiLCIxMC1RIiwiOC1LIl19LCJhcHBsaWVkU2luY2UiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl0sImZvcm1hdCI6ImRhdGUifSwiY291bnQiOnsidHlwZSI6ImludGVnZXIifSwiaXRlbXMiOnsidHlwZSI6ImFycmF5IiwiaXRlbXMiOnsidHlwZSI6Im9iamVjdCJ9fSwidHJ1bmNhdGlvbiI6eyJ0eXBlIjpbIm9iamVjdCIsIm51bGwiXX0sInNvdXJjZSI6eyJ0eXBlIjoib2JqZWN0In0sIm1ldGEiOnsidHlwZSI6Im9iamVjdCJ9fX19LCJyZXF1aXJlZCI6WyJ0eXBlIl19fSwicmVxdWlyZWQiOlsiaW5wdXQiXX19fX0=
SHA-256 of the canonicalized challenge: c21f6a12671c3a6c628096a2a3512f511d36aa28c2386f379c70497ec3c380d7
Raw signals
The exact input the scoring function was given. A signal we could not determine has
observed: false and contributes nothing to the score — it is never counted as a failure.
[
{
"id": "probe_ok",
"value": true,
"observed": true,
"detail": null
},
{
"id": "challenge_served",
"value": true,
"observed": true,
"detail": null
},
{
"id": "challenge_decodes",
"value": true,
"observed": true,
"detail": null
},
{
"id": "wire_form",
"value": "v2-header",
"observed": true,
"detail": null
},
{
"id": "x402_version",
"value": 2,
"observed": true,
"detail": null
},
{
"id": "tls_ok",
"value": true,
"observed": true,
"detail": null
},
{
"id": "tls_protocol",
"value": null,
"observed": false,
"detail": "The negotiated TLS version is not exposed to the probe."
},
{
"id": "redirect_count",
"value": 0,
"observed": true,
"detail": null
},
{
"id": "redirect_scheme_downgrade",
"value": false,
"observed": true,
"detail": "Cross-scheme redirects are refused."
},
{
"id": "resource_origin_match",
"value": true,
"observed": true,
"detail": null
},
{
"id": "network_recognized",
"value": true,
"observed": true,
"detail": "Recognized means present in the tx402 signed release manifest."
},
{
"id": "asset_recognized",
"value": true,
"observed": true,
"detail": "Recognized means present in the tx402 signed release manifest."
},
{
"id": "facilitator_known",
"value": null,
"observed": false,
"detail": "The challenge named no facilitator."
},
{
"id": "amount_canonical",
"value": true,
"observed": true,
"detail": null
},
{
"id": "amount_magnitude_band",
"value": "micro",
"observed": true,
"detail": null
},
{
"id": "pay_to_wellformed",
"value": true,
"observed": true,
"detail": null
},
{
"id": "pay_to_declared_dynamic",
"value": false,
"observed": true,
"detail": null
},
{
"id": "timeout_sane",
"value": false,
"observed": true,
"detail": "Authorization window 300s exceeds the tx402 maximum of 60s."
},
{
"id": "scheme_known",
"value": true,
"observed": true,
"detail": null
},
{
"id": "requirement_count",
"value": 2,
"observed": true,
"detail": null
},
{
"id": "challenge_size_bytes",
"value": 217,
"observed": true,
"detail": null
},
{
"id": "first_seen_age_days",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "scan_count",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "availability_30d",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "latency_p50_ms",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "price_changes_90d",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "recipient_changes_90d",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "recipient_unstable_undeclared",
"value": null,
"observed": false,
"detail": "No history yet."
},
{
"id": "terms_changed_within_24h",
"value": null,
"observed": false,
"detail": "No history yet."
}
]