$1
per call · USD Coin on Base
Audits another x402 service for the exact failure modes that cause aggregators (agent-tools.cloud, x402scan, Bazaar) to mark it 'down' or make its 402 challenge unreadable: missing/invalid /.well-known/x402 descriptor, an unpaid request returning 500/404 instead of a clean 402, a malformed or missing payment-required challenge, and drift between the descriptor's advertised terms and the live challenge. Returns a concrete diagnosis and fix for each failing check, not just pass/fail.
Endpoint
GET https://x402-api-catalog.onrender.com/api/x402-doctor1
Calls / 30d
1
Unique payers / 30d
Sep 7
Last called
exact
Payment scheme
Call this service
import { wrapFetchWithPayment } from "@x402/fetch";
import { privateKeyToAccount } from "viem/accounts";
const account = privateKeyToAccount(process.env.PRIVATE_KEY);
const fetchWithPay = wrapFetchWithPayment(fetch, account);
const res = await fetchWithPay("https://x402-api-catalog.onrender.com/api/x402-doctor", {
method: "GET",
});
const data = await res.json();curl -X GET \
"https://x402-api-catalog.onrender.com/api/x402-doctor?path=%2Fapi%2Fsome-paid-endpoint&url=https%3A%2F%2Fexample-service.onrender.com" \
-H "X-PAYMENT: <signed x402 payment>"Example response
{
"checks": [],
"fixes": [],
"score": 40,
"url": "https://example-service.onrender.com",
"verdict": "broken: aggregators will show this as down"
}Payment details
0x9041f8a43d0b43209b9227de2c7fb25c9fe3847eUSD Coin · 0x833589fcd6edb6e08f4c7c32d4f71b54bda02913Is this your API?
Pin it to the top of Developer Tools and the homepage with a featured placement.
More from PreFlight Checker & similar services
PreFlight Checker · Trust Check
x402-api-catalog.onrender.com
npm package trust check / risk score / security audit: registry age, weekly downloads, GitHub org/stars, OSV.dev vulnerabilities, typosquat detection.
PreFlight Checker · MCP Audit
x402-api-catalog.onrender.com
MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+credential access). If a GitHub repo is supplied, folds in a real software-supply-chain signal too.
PreFlight Checker · Contract Check
x402-api-catalog.onrender.com
EVM token contract safety check: honeypot detection, mint/blacklist/pausable/self-destruct capability, ownership renouncement, transfer tax, and a real token-impersonation check (does the symbol claim to be USDC/WETH/DAI/cbBTC at the wrong address — the token equivalent of npm typosquatting).