X402 ENDPOINT TRUST INDEX · UPDATED 2026-08-05

x402 Endpoint Trust Index: July 2026

A reproducible monthly view of x402 trust by network, provider, exact-route quote validity, evidence freshness and paid-call status.

TARGET QUESTION · x402 endpoint health

DIRECT ANSWER

The July 2026 TOLL·402 Endpoint Trust Index measures what the directory can verify across 78,315 resources: normalized network coverage, provider concentration, exact-route quote outcomes, evidence freshness and paid-call status. Of 69,864 quote-testable routes, 15,121 returned valid requirements. Untested routes are not counted as failures, and discovery or origin reachability is not treated as proof that a paid service works.

Key takeaways

  • Only about one quarter of the crawled resources were labeled healthy by the source registry.
  • A high raw count can be driven by many routes from a small number of providers.
  • Health, payment validity, response usefulness and provider ownership are separate trust questions.
  • No route in this snapshot has settled, reviewed paid-call evidence, so the index reports quote validity without promoting it to paid verification.

The headline numbers

The crawl fetched every page of the independent 402 Index x402 feed, normalized URL hosts and query ordering, paired each URL with its HTTP method, and removed exact duplicates. Five duplicates were removed and no URL failed parsing. The source snapshot remains downloadable so other researchers can audit the health count.

Registry labelResourcesWhat it means
Healthy19,594Source health checks currently pass
Degraded41,261Endpoint responds with material problems
Down11,773Source could not reach a usable endpoint
Unknown2,364Insufficient or missing health evidence

Why endpoint count is not provider count

One provider can publish hundreds or thousands of routes. The secondary registry reports 74,992 unique method-and-URL resources and 2,319 of its own grouped services. Coinbase CDP Bazaar yielded 25,841 current service-resource entries. After cross-source and template deduplication plus curated endpoint migration, TOLL·402 presents 78,315 canonical resources across 2,421 provider/product groups; none of those counts represents 78,315 distinct businesses.

How TOLL·402 uses the crawl

Every bulk record now enters the canonical resource index. Provider/product grouping keeps high-volume gateways usable, while discovery, registry health, safe origin reachability, quote checks, editorial curation and paid-call verification remain separate evidence fields. Unreachable resources stay visible with their failed check instead of silently disappearing.

How to read a 55% degraded rate

Of the 74,992 unique method-and-URL resources in the 402 Index snapshot, 26.1% carried the source's healthy label, 55.0% degraded, 15.7% down and 3.2% unknown. The largest bucket is therefore not a clean pass or a total outage. It is the middle state where the registry saw a material problem. That distinction matters: degraded inventory may include recoverable configuration errors, intermittent responses or payment behavior that no longer matches the expected route.

The percentages describe the source snapshot, not an uptime study conducted at fixed intervals by TOLL·402. They should guide investigation, not become a service-level guarantee. A buyer choosing one endpoint still needs the exact route's recent quote result and, for important work, a controlled call of its own.

A route can be reachable and still be unusable

Health is layered. DNS can resolve while TLS fails. The origin can answer while the advertised path returns 404. The path can return HTTP 402 while its payment requirement is malformed. A valid requirement can settle while the paid response is empty or unrelated to the documentation. Treating all of those cases as a single live/down flag removes the information an operator needs to fix the service.

TOLL·402 therefore stores origin reachability, registry health, exact-route quote outcome and paid-call evidence separately. A responsive origin is useful because it rules out one class of failure, but it does not promote every route on that host. Curated status comes from evidence attached to the exact resource.

LayerQuestion answeredWhat it cannot prove
Origin reachabilityDid the public host answer safely?That a particular route exists
Registry healthWhat did the source observe?A current independent quote
Exact quoteDid this route return valid requirements?That paid output is useful
Paid callDid one bounded transaction work?Future uptime or quality

Why route-heavy providers distort ecosystem totals

Imagine one gateway publishing 5,000 model-and-operation combinations while fifty independent providers publish one route each. A route count would make the gateway look like nearly the entire market, even though a buyer is choosing among fifty-one provider relationships. Route counts are still useful for measuring callable surface area, but they should not be used as a synonym for companies, products or independently operated services.

TOLL·402 groups canonical resources by provider and product so a user can browse capabilities without scrolling through thousands of near-identical paths. The original method, URL and source associations remain available underneath that grouping. This preserves auditability while making the inventory legible.

What buyers should do with this report

Use the report to set expectations for discovery. A registry result is a lead, not a production dependency. Shortlist routes that match the required capability, then favor a recent exact quote, clear documentation, a supported network and a safe sample input. For a business-critical workflow, keep an alternate provider or a non-paid fallback rather than assuming every discovered route will stay healthy.

When a check fails, preserve the failure class and timestamp. A non-402 response after a provider update calls for a different response than a DNS timeout. Rechecking the same failing route without a backoff wastes capacity and can make a temporary incident worse.

What providers can learn from the crawl

A provider should test from outside its own network, publish one canonical protected URL and keep discovery metadata synchronized with deployment. Old demo routes are especially damaging because they remain discoverable long after the working service moves. A stable public status page or health endpoint helps operators diagnose transport without charging a buyer merely to learn whether the host is alive.

After a repair, verify the exact advertised method and URL, not only the homepage. Confirm that the 402 response uses the current protocol shape and that a bounded payment returns the documented media type. Finally, remove or redirect retired routes so registries can converge on the service that actually exists.

Why this edition's totals were revised

This edition originally reported against a snapshot built on 22 July 2026. The July snapshot was subsequently rebuilt with an as-of date of 31 July, which moved its resource total to 78,315, and the figures here now match the snapshot the page renders rather than the earlier build.

The source input counts quoted elsewhere in this report were captured on 10 July 2026 and are left at their captured values, because changing them would misdate the observation. The August edition covers 89,057 resources and reports the month-over-month comparison directly.

July 2026 Endpoint Trust Index data

AS OF 2026-07-31

This is a transparent evidence index, not a single composite score. Network counts overlap when one resource advertises multiple networks. A valid quote is not a settled paid call, and zero paid-call records does not mean zero services can settle.

The largest provider group accounts for 51.8% of quote-testable routes; the ten largest account for 80.2%. Read the network and provider rates with that concentration in mind.

Canonical resources
78,315
Provider groups
2,406
Quote-testable routes
69,886
Valid / quote-testable
13,928 · 19.9%
Success among attempts
20.4%
Evidence within 7 days
100%
Settled paid calls
0 · 0%
Paid outputs reviewed
0 · 0%

Evidence by normalized network

DimensionResourcesQuote-testableValid / testableEvidence ≤7dPaid call
Base73,25065,31215.4%100%0%
Solana12,53710,35780.9%100%0%
Polygon2,4982,14456.6%100%0%
Arbitrum2,3222,03954.6%100%0%
eip155:4801,05697499.9%100%0%
Base Sepolia92766644.3%100%0%
eip155:143902861100%100%0%
eip155:196845808100%100%0%
Algorand780772100%100%0%
xrpl:0768765100%100%0%

Evidence for the 15 largest provider groups

DimensionResourcesQuote-testableValid / testableEvidence ≤7dPaid call
orbisapi37,30636,1710%100%0%
lowpaymentfee10,66210,6620%100%0%
api.deepnets.ai3,5823,57199.9%100%0%
Agent4021,7741,4186.5%100%0%
tcgapi1,2301,230100%100%0%
clonecho.builda.company9939930%100%0%
GoCreative AI67965798.8%100%0%
x402node54753998%100%0%
proxy4752147.6%100%0%
2s.io46946998.7%100%0%
llm402.ai45500%100%0%
api-dev39124658.9%100%0%
stratalize366185100%100%0%
x4023403270%100%0%
strale33429694.6%100%0%

EXACT-ROUTE OUTCOMES

non 402
52,973 · 67.6%
confirmed
13,928 · 17.8%
not safely testable
8,429 · 10.8%
skipped origin unreachable
1,713 · 2.2%
http 402 invalid
1,072 · 1.4%
http 402 unparsed
168 · 0.2%
unreachable
32 · 0%

EVIDENCE AGE

Within 7 days
78,315 · 100%
8 to 30 days
0 · 0%
Over 30 days
0 · 0%
No recorded date
0 · 0%

Source dataset generated 2026-07-31T06:50:36.541Z; it was 0.7 days old at this report's cutoff. SHA-256 bf66ead9f067Download the monthly snapshot history →

Related directory entries

Sources and methodology

TOLL·402 distinguishes public claims, registry discovery, unpaid quote checks and settled paid-call verification. Sources below support the visible claims; presence in a registry is not treated as verification.

  1. TOLL·402 discovery corpusThe normalized downloadable crawl output.
  2. 402 Index APIIndependent public registry and health fields used as the crawl source.
  3. x402 Bazaar documentationExplains how routes enter a facilitator discovery catalog.

Continue reading