How TOLL·402 verifies x402 services
How the directory checks exact routes, keeps unsafe probes out, and gives buyers useful, dated service information.
DIRECT ANSWER
TOLL·402 starts with source documentation, then probes public endpoints for unpaid payment requirements. A discovered route enters curated results only after its exact safe method and URL return a current, version-valid x402 requirement. Paid-call verification is awarded separately, only after a bounded real payment settles and the documented output is confirmed. Failed and stale checks remain visible.
Key takeaways
- Truthful absence is better than an invented endpoint, price or tool name.
- Probe evidence overrides documentation-derived detail when they conflict.
- Mutating tools are excluded from unattended dry-call and paid-call tests.
How verification progresses
A discovered candidate needs a real source URL and identifiable service. Documentation can support names, descriptions and explicit prices. A strict exact-route quote check can promote a safe route into curated results. A human-controlled paid call is a separate, stronger step because money movement and output evaluation require tighter judgment.
Safety boundaries
The probe avoids mutating operations, caps the number of dry calls and records failures instead of hiding them. Unknown prices stay unknown. A documentation pass cannot set the listing-level sort price unless the live probe confirms it. These rules reduce the chance that plausible marketing copy becomes false machine-readable data.
- Never publish a private key, payment signature or sensitive output.
- Use dedicated wallets with small balances for verification.
- Retain source, date and failure reason for review.
What verification does not promise
A verified badge is evidence of one successful, reviewed transaction. It is not an endorsement of every tool, a security audit, a guarantee of future uptime or a promise that a price will not change. Buyers must still apply their own permissions and spend policy.
From public lead to a resource a buyer can evaluate
Discovery begins with public registries, provider documentation and submissions. Each lead is normalized into an exact method-and-URL resource while the original sources remain attached. Provider and product grouping keeps thousands of related routes browsable, but the evidence stays on the resource that was actually observed.
The next steps answer different buyer questions. Source review establishes what the provider says the route does. A safe origin check shows whether the public host responds. An exact quote check shows whether a non-mutating route currently offers a valid x402 requirement. Editorial curation adds enough context to compare the result without replacing those direct observations.
What earns a resource a place in curated results?
Bulk ingestion alone does not. A safely testable discovered route can enter curated search after its exact method and URL return a current, version-valid x402 requirement. Separately, an editor may include an exact resource with strong provider documentation and useful context. The route keeps its actual verification state either way; editorial selection does not manufacture a live quote.
This rule converts a large raw inventory into a smaller set that is more useful for buyers while preserving the long tail for research. It also prevents a healthy homepage from promoting every path on the same domain. The user sees the service context, but the dated check belongs to the route.
The exact-route checker and its safety limits
Before connecting, TOLL·402 resolves the host, rejects private or reserved IPv4 and IPv6 addresses and pins a validated public address into the request. Redirects do not inherit trust automatically. These controls reduce the risk that an attacker uses a submitted URL to reach internal services or changes DNS after validation.
The checker invokes only GET and HEAD resources without unresolved path values. It does not guess an account ID, submit a form or call mutating methods to chase a badge. A route outside those limits receives a visible not-safely-testable outcome and can be reviewed through a controlled process when justified.
- Validate and pin public dual-stack DNS answers.
- Use the exact advertised safe method and URL.
- Reject malformed or version-mixed payment requirements.
- Record skips and failures instead of dropping the route.
How conflicts and stale evidence are handled
Direct observations take priority for fields they actually measure. If documentation says a route costs one cent and the current 402 requires two cents, the live quote is the relevant offer and the discrepancy should be visible. That does not mean a probe can rewrite the provider name or describe output it never purchased.
Every check carries a date. A later failure changes the current status but does not delete the historical success, source or failure reason. This lets a provider diagnose a regression and lets a buyer decide whether old evidence is still useful. Unknown values remain unknown rather than being filled from a similar route.
What buyers gain beyond a verification label
The directory combines exact routes with provider grouping, tool descriptions, price evidence, network filters, source links and comparable failure states. A buyer can move from a capability question to a shortlist, inspect the route's current offer and understand why an alternative was not promoted. That is more useful than a flat list of URLs or a badge without a method.
Downloadable data also makes the conclusions auditable. Researchers can recompute counts, providers can find stale routes, and agent builders can apply their own policy to method, network, price and verification date. The directory's job is to shorten evaluation while leaving the purchasing decision with the buyer.
How providers can improve or correct a listing
Publish one canonical documentation URL, keep the exact protected route and method current, and provide valid discovery metadata with a safe example. If a check reports an invalid 402, compare the response with the current protocol version rather than changing the homepage. If a route moved, retire or redirect the old path and update its registry records.
A correction should include the exact resource and evidence, not a request to mark an entire brand verified. That precision lets the directory recheck the failing layer and keeps unrelated routes from inheriting a result they did not earn.
Related directory entries
Sources and methodology
TOLL·402 distinguishes public claims, registry discovery, unpaid quote checks and settled paid-call verification. Sources below support the visible claims; presence in a registry is not treated as verification.
- TOLL·402 quote-check definitions — Public definitions and limits for each verification signal.
- TOLL·402 discovery methodology — Public rules separating bulk discovery from curated verification.
- x402 buyer quickstart — Current client-side payment mechanics.