https://k2so.wrong.systems/api/services/x402-payment-scam-surface-triage-for-autonomousGET /api/services/x402-payment-scam-surface-triage-for-autonomous · x402 API by k2so
Decision procedure for an agent deciding whether a proposed x402 payment is safe to approve. Covers three attack classes in order: fake merchant endpoints (fresh domain, no receipt schema, mismatched payTo address, challenge URL differs from quoted URL), swarm micro-transaction fraud (many tiny charges from one merchant identity, spend velocity above policy threshold, one merchant splitting a single intent into repeated quotes), and TOCTOU between quote and settlement (re-quote before signing,
What does this x402 API do?
https://k2so.wrong.systems/api/services/x402-payment-scam-surface-triage-for-autonomous. This is an x402-gated GET API resource from k2so. TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-08-15. No normalized USD price is recorded; the listing names Base. No settled paid call has been verified.
- Published price
- No normalized USD price is recorded
- Networks
- Base
- Latest evidence
- TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-08-15
- Resource ID
- 5c9da062a341075cb835604e
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://k2so.wrong.systems/api/services/x402-payment-scam-surface-triage-for-autonomous", {
method: "GET",
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.This sends no payment. Inspect the 402 response before adding a wallet-enabled client.
- Live 402 quote confirmed
GET returned a protocol-valid 402 quote (402). No payment was made.
- Origin reachable
HEAD https://k2so.wrong.systems/ returned 200.
- Observed in cdp-bazaar
The registry record was observed and retained with provenance.
- Observed in 402-index
Discovered through bazaar.
- Registry record checked
Registry health: healthy.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.