
Agentic Endpoints
com.oliverkissv1.0.0Updated Sep 29, 2026
Pay-per-call tools for autonomous agents, settled in USDC on Base via x402.
Installation
In SourceWeft
- Open Agentic Endpoints in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"agentic-endpoints": {
"type": "http",
"url": "https://ai.oliverkiss.com/mcp"
}
}
}README
agentic-endpoints
x402-powered micro-SaaS utilities for autonomous AI agents. Pay-per-call with USDC micropayments on Base — no API keys, no accounts, no subscriptions.
Live at https://ai.oliverkiss.com
Endpoints
GET / content-negotiates: send Accept: application/json for the machine-readable
endpoint catalogue, anything else gets the HTML landing page.
How It Works
- An agent requests a paid endpoint
- The server replies
HTTP 402 Payment Requiredwith the price, network and receiving address - The agent signs a USDC transfer on Base and retries with an
X-PAYMENTheader - The facilitator verifies and settles the payment, then the handler runs
Try it — this returns a real 402 challenge, not an error:
Try It Free
Funding a wallet to find out whether a service is any good is the wrong order,
and it was the single largest barrier in front of every paid route here. So
POST /credits/trial hands out $0.10 of credit — about 20 calls — with no
wallet, no signature and no account:
The token is not issued and recorded; it is derived from the caller's address
by HMAC, so asking twice returns the same ledger with whatever is left on it —
never a refill. That needs no issuance table and no new Durable Object, and it
is safe to retry, which matters because the caller is an agent that will retry.
IPv6 addresses collapse to their /64 so a single machine cannot walk a
subnet for more. Every 402 advertises the trial in an X-Trial-Available
header, so an agent that hits the paywall learns the way around it in the same
response.
Over MCP the same trial is a tool. An MCP client controls a tool's arguments
but usually cannot set a per-call HTTP header, so credits_trial issues the
token and every paid tool accepts it as an optional credit_token argument —
meaning a client with no wallet can go from tools/list to real work without
ever setting a header. A refused tool call names that route explicitly rather
than only quoting x402 at a caller that cannot sign.
Agent-to-Agent (A2A)
The service speaks A2A v0.3 at https://ai.oliverkiss.com/a2a, with an Agent
Card at /.well-known/agent-card.json (and the legacy /.well-known/agent.json).
A2A has no payment step, which is why agents publishing x402 services usually declare their paid work out of scope for A2A and expose only the free parts. Credit here is a header rather than a protocol negotiation, so every paid skill is callable over A2A in a single round trip — all 21 of them — and the free trial means the caller needs no wallet to start:
Name the skill in message.metadata.skill, or send a DataPart shaped
{ skill, input }. A part that names a skill wins over one that only carries
input, so a caller that sends both is never billed for the wrong endpoint.
Skill ids are the route path with slashes as dots (/once-key/complete →
once-key.complete). A non-standard skills/list method returns the catalogue.
message/send always returns a Message, never a Task. The x402 resumption
flow expects the server to hold the original input against a returned taskId,
and this service stores nothing between calls — so a Task it could not resume
would fail on the second leg. tasks/get therefore answers -32001 honestly
and streaming is refused with -32004, rather than advertising operations that
would break. An unpaid call still returns the x402 challenge under the
a2a-x402 extension's metadata key, so a payment-aware client can sign and
retry in one step.
Calls arriving over /a2a re-enter the same route in-process, so they pass the
identical pricing, payment, validation and body-cap path as direct HTTP.
MCP Server
Every paid endpoint is also exposed as an MCP tool over Streamable HTTP at
https://ai.oliverkiss.com/mcp, implementing revision 2026-07-28 (stateless:
no initialize handshake, no session header) with a fallback for clients still
sending the 2025-06-18 handshake.
tools/list is free so clients can discover the catalogue. tools/call
re-enters the corresponding paid route in-process, so it passes the same x402
gate, body cap and validation as a direct HTTP call. Without a valid
X-PAYMENT header the tool returns isError: true and a machine-readable
payment demand (price, payTo, asset, network) rather than performing work.
Two Ways To Pay
Per-call x402 caps revenue at whatever a buyer will tolerate signing: $1,000 at $0.005 a call is 200,000 signatures. Prepaid credits sell the same work once, in an amount worth the transaction, and let callers whose wallets cannot sign per request use the service at all.
Both paths run side by side and neither is privileged:
Omitting X-Credit-Token produces exactly the 402 challenge it always did, so
the Bazaar listing and every existing integration are unaffected.
Credits are integer micro-dollars, never floats: $0.001 has no exact binary representation, and a ledger that drifts is worse than no ledger. Each account is its own Durable Object addressed by the hash of its token, so the balance check and its debit are atomic and one account cannot queue behind another. Calls are debited before the work and refunded if it 5xxs, because an outage must not bill a customer for nothing.
The token is shown once and is not recoverable — only its hash is stored.
Discovery
An endpoint nobody can find earns nothing, so the service is registered wherever agents actually look. Every catalog below was chosen because it verifies ownership by domain or wallet rather than by a financial account — the Coinbase CDP Bazaar is skipped for exactly that reason.
Aggregators such as PulseMCP ingest from the official registry, so publishing there covers several directories at once. The repository is public, so directories that crawl source repos can now see it too.
Machine-readable descriptions are generated from the same pricing table that
gates payment, so they cannot drift from what is actually charged: /llms.txt
for a model handed a bare URL, /openapi.json for tooling, the A2A Agent Card
at /.well-known/agent-card.json, plus /robots.txt and /sitemap.xml. Tests
assert the prices agree across all of them, and that the card advertises exactly
the skills /a2a can actually run.
Policies
A buyer — or the underwriter behind one — checks for these before sending money
or data, and their absence is itself a reason to pass. /terms, /privacy,
/refunds, /acceptable-use and /compliance are served as HTML, and
/.well-known/compliance.json serves the same content machine-readably. Both
render from one source, so they cannot disagree.
They are written to be true of the code rather than boilerplate, and two tests
exist purely to stop them quietly becoming lies: one asserts no client IP is
recorded anywhere in /stats, and one asserts the free trial the refund policy
points at still works.
The support address is set with wrangler secret put SUPPORT_EMAIL rather than
committed. It is printed on public pages either way, so this is not secrecy —
it keeps the address out of a public repository's permanent history, which
harvesters scrape far harder than they crawl a site. A malformed value falls
back to the issue tracker instead of publishing a mailto: link that silently
goes nowhere.
Revenue Monitoring
The service could demand payment for months with no way to tell whether a
payment ever arrived — including the failure mode where payments verify but
never settle. A cron trigger sweeps Base every 5 minutes for USDC Transfer
logs into the receiving address and folds them into a running ledger in KV.
Revenue is read from the chain, not from our own logs or the facilitator's
word, so it cannot be inflated by a bug on either side. GET /revenue publishes
the ledger for free — it costs nothing and gives a prospective caller evidence
the service actually transacts.
Set ALERT_WEBHOOK_URL to a Discord webhook to be notified when money lands:
The first scan starts the watermark at the current chain head rather than genesis; scanning millions of blocks through a public RPC node would fail repeatedly and never establish a watermark at all. The watermark advances only on a successful scan, so a transient RPC failure is retried on the next tick with nothing missed.
Buyer signals
Revenue monitoring only sees money that arrived. The service takes thousands of requests a day and, so far, no revenue — and reviewing the callers, almost all of it is liveness probes, trust scanners and directory crawlers, which are indistinguishable from a customer in an access log. The gap that leaves is a genuine buyer being refused for a fixable reason and leaving without ever appearing as a distinguishable line.
src/lib/tripwire.ts emits one structured line per notable request, and the
same signals are persisted (see below), so the durable answer is:
To watch them arrive live, or to search the raw log lines:
Searching Workers Logs after the fact needs a full-text needle, not a
$metadata.message filter: the line is a JSON blob, and the message filter
does not match inside it — it silently returns zero rather than erroring, which
reads exactly like "no buyer has ever appeared".
It keys on behaviour, not identity. A monitor never carries a payment
authorization, so anything that does is trying to buy — and that holds even
when the User-Agent claims to be a bot. User-Agent only suppresses known
noise and grants nothing, because it is forged for free.
Note that the SDK inherits Node's User-Agent, which is exactly what an
anonymous script sends, so no string positively identifies a customer.
Anything unrecognised stays unclassified rather than being written off; the
tests pin this, since misfiling it would suppress the one signal worth having.
prospect_402 is a guess and is marked low confidence for that reason — it
should never be read as a sale.
The check runs ahead of the credit and x402 gates, both of which answer without
reaching application code, because a refusal is precisely the event worth
recording. Payment and credit headers are recorded only as present or absent, never
their values. The caller IP is dropped in favour of the country and network
name Cloudflare already derived, and the Referer is cut to origin and path, so
the query strings where emails and session tokens ride are never stored or
published on /stats.
Signals are also persisted in the stats Durable Object and served on /stats,
because a log line is only readable while something is tailing it — a first
customer arriving overnight would otherwise leave a line nobody read, which
would then age out. The event ring is bounded by count rather than age: the
first payment attempt could be the only one for months.
Note that buyer_signals.payment_attempt starts at 1 from a deployment
verification probe on 2026-09-09 (ua: persistence-verify/1.0). It could not
be removed without exposing a mutation endpoint. The first genuine buyer is
entry two.
Published SLOs
An agent choosing between two paid services has no way to tell which one works.
GET /status is free and answers that from recorded behaviour, not a promise:
Getting the number honest mattered more than getting it published. It first
shipped reporting an 11.39% error rate; every one of those was a 404 on a path
that never existed — my own probes and passing crawlers — plus tokens that were
correctly rejected. An agent reading that would have taken its money elsewhere
and been right to. So client errors (4xx) are counted separately from failures
(5xx), and requests to unknown paths are excluded from the rate entirely and
surfaced as a raw count instead. Otherwise any stranger could degrade our
published reliability just by scanning for /wp-admin.
Latency comes from histogram buckets, so the figures are reported as
p95_at_most — a bound, which is what a bucket can honestly support, rather
than a precise percentile it cannot. Uptime credits only the window actually
observed, so day one does not claim 24 hours from an hour of heartbeats. The
heartbeat is written before the revenue scan, so an outage at a public RPC
node is not reported as ours.
GET /stats publishes the demand funnel — challenged, paid, free, per route —
which is the only thing that distinguishes "nobody has found us" from "agents
arrive and decline to pay".
Client SDK
sdk/ is a dependency-free TypeScript client. It deliberately does
not sign payments — it takes a credit token, or your own x402-aware
fetch, so it never needs a private key.
Its reason to exist is exactlyOnce, which collapses the claim/complete/release
protocol into one call: it handles all four claim outcomes, records the result
so later callers can replay it, releases the claim if your work throws, and
rethrows your error untouched.
Stack
- Runtime: Cloudflare Workers + Durable Objects
- Payments: x402 protocol (USDC on Base mainnet,
exactscheme) - State: Durable Object SQLite (OnceKey, Vault, Credits, MeetingMemory, Stats, EndpointRegistry) and KV for the revenue ledger
- AI: Workers AI, for
/meetings/summarize - Framework: Hono
Setup
Prerequisites
- Node.js 20+
- Cloudflare account (Workers Paid plan — $5/mo, required for Durable Objects)
- A wallet address on Base to receive USDC
- Wrangler CLI (use
npx wranglerif not installed globally)
Install
Configure Secrets
Do not set
FACILITATOR_URLunless you mean to override the default. It must be a valid URL. If it is set to anything else, every paid endpoint returns 500 instead of a 402, and the failure is only visible innpx wrangler tail— this silently broke all payments once already.
The default facilitator is https://facilitator.xpay.sh: free, no signup, and it
supports Base mainnet.
Develop and deploy
Proving settlement without spending
Settlement is the one step that cannot be tested by inspection, and on
mainnet every attempt costs real USDC. [env.testnet] deploys the same code
to a workers.dev URL priced in Base Sepolia USDC, which
faucet.circle.com gives away with no account.
Only the exact string eip155:84532 selects Sepolia; anything unrecognised
falls back to mainnet. That asymmetry is deliberate — a Worker that wrongly
demanded testnet tokens would hand out real work for money anyone can mint.
Announcing to the Bazaar
Lists every utility route in the PayAI Bazaar without spending anything.
Cataloguing runs on the facilitator's /verify as well as /settle, and
verification moves no funds. A first listing of a POST resource seen only
through /verify is normally deferred until it settles, but the catalog
worker admits it anyway when its own read-only probe (HEAD, then GET)
answers 402 — which every paid route here does. So the signing wallet only
has to hold the price of each route, because verification checks the
balance; it never moves it. Three cents covers all 16 routes.
Verified against the live facilitator on Base Sepolia: 16/16 routes went from
having no catalog row at all to lastWrite: { status: "listed", source: "verify" }, with the signer's balance unchanged to the last micro-dollar
afterwards.
Check any route's status, and the reason if it is missing, with:
API Examples
OnceKey (exactly-once execution)
A claim on its own is only half an idempotency key. The agent that loses the race needs to know what happened, or it has to either block forever or repeat the side effect anyway — which is the failure this endpoint exists to prevent. So the lifecycle is three calls, and only the first one costs money.
Every later claim of that key returns duplicate with that result.
duplicate always means completed. A claim that was started but never
completed reports held instead, precisely so a caller cannot mistake work
that is still in flight — or that died half way through — for work that
succeeded. The SDK raises HeldError rather than returning a result of
undefined.
If the work fails, POST /once-key/release (free) frees the key immediately.
lease_ttl is opt-in, deliberately. Without it a claim is held for its
full ttl and nothing can ever run your side effect twice. With it, a
claimant that crashes is presumed dead once the lease lapses and the next
caller takes over with recovered: true. Leases on by default would have
made every key claimed by the original claim-only API silently reclaimable —
a duplicated charge is a far worse failure than a key that needs a retry
under a fresh name.
The agentic-endpoints npm package wraps all of this in one call:
Web scraper
PDF parser
Inflates FlateDecode content streams, expands PDF 1.5+ object streams, and maps
character codes through each font's /ToUnicode CMap, so subset and composite
fonts come back as real text rather than glyph indices. Encrypted PDFs and
image-only scans return 422 rather than filler content, so callers are not
billed for a result that is known to be useless.
Token compressor
Meeting memory (agent-queryable transcripts)
Meeting notetakers keep transcripts inside their own app, where the only reader is a human scrolling a sidebar. This puts them somewhere your agents can ask questions of them.
You choose, per meeting, whether this service can read it. The choice is required, and the wrong field for the mode is refused rather than guessed.
Sending plaintext as private is an error rather than a quiet indexing, and
sending ciphertext as queryable is an error rather than a meeting that can
never match a search. Both refusals exist because the failure they prevent is
silent and only discovered long after it matters.
Search returns ranked excerpts plus searched_meetings and
private_meetings_skipped. Read them. If searched_meetings is 0, an empty
result means nothing was searched, not that the topic was never discussed —
and an agent that conflates those will confidently tell a user something never
happened.
Via MCP the same thing is meetings_search, meetings_import, meetings_get
and meetings_list.
Asking a question instead of reading excerpts
/meetings/search hands back ranked excerpts and leaves the reasoning to you.
/meetings/summarize takes a plain-language question, retrieves the relevant
transcripts, and answers from them with a citation per claim:
The question is not FTS5 syntax — the terms are derived from it and returned
as terms, so a bad answer can be traced to bad retrieval rather than
guessed at. consulted is what the answer was actually built from; a
truncated entry means only part of that transcript was read, so its silence
on a point is not evidence.
The negative cases matter more than the positive one. A summarizer's dangerous failure is not a wrong answer but a confident one assembled from nothing, because the caller cannot tell the difference afterwards. So:
Private meetings can never contribute to an answer; private_meetings_skipped
says how many were excluded. Answers are generated by
@cf/meta/llama-4-scout-17b-16e-instruct on Workers AI, pinned rather than
floating — a silently swapped model would change every answer this endpoint
has ever given.
Via MCP this is meetings_summarize.
Importing a raw export
transcript accepts a WebVTT or SRT file exactly as Zoom, Teams, Meet or a
notetaker emits it — header, cue numbers, timestamps and <v Speaker> spans
included. You do not have to write a parser first.
The format is detected from the content, not from source; that field is a
hint and is ignored when it disagrees with the file. Timestamps and cue
numbering are stripped before indexing, and consecutive cues from the same
speaker are merged, because exports split on timing rather than grammar:
Indexed cue-by-cue, a search for "redesign before the security audit" matches
nothing — the phrase exists in the meeting but not in any one cue. Merged, it
matches. Speakers found in the file are added to participants alongside any
you declared, so attendees who never spoke are not lost.
A parsed import reports what happened:
The absence of that field means the text was stored verbatim. Plain text is
unchanged, and private meetings are never parsed — the body is ciphertext
this service cannot read.
Checking an endpoint before paying it
An agent that pays automatically cannot notice that the money started going somewhere else. Every response still returns 200, the price still looks right, and by the time a human looks it has happened a thousand times.
It fetches the endpoint's live payment challenge and compares it against every observation made by every previous caller. That comparison is the part an agent cannot do for itself — it can remember what it saw, not what everyone else saw.
A pay_to, network or asset that this endpoint has never offered before
is critical — those determine where the money goes. A price change is a
warning at worst.
The comparison is over the whole accepts list, not just the first entry.
A real client pays through the option matching a chain and token it holds,
which need not be index 0, so an endpoint could otherwise list an honest
option first and an attacker's payee second and pass a check that only reads
the first. Reordering the list is reported as a warning, not a critical,
because the same destinations remain on offer.
Addresses are compared case-insensitively. EIP-55 checksumming is presentation, not meaning, and reporting a re-cased address as a changed payee would fire the most severe alarm this tool has at an endpoint where nothing moved.
History is kept per method and URL, not per URL. method is caller-supplied,
and plenty of x402 services price GET and POST differently — a read tier and
a compute tier. Sharing one history between them would let anyone spend $0.003
to make an honest endpoint appear to the next caller to have swapped its
payee, and alternating the two would flap that baseline indefinitely. The URL
is canonicalised first (host lowercased, default port dropped, fragment
removed) so that different spellings of one endpoint still share one history
rather than fragmenting it.
What it does not tell you
Network identifiers are normalised before comparison, so an endpoint moving
from x402 v1's "base" to v2's "eip155:8453" is correctly read as the same
chain rather than as a critical chain change.
Failures are reported coarsely (timeout or unreachable) and a redirect
target is never echoed back. Reflecting the real error or the Location header
would turn a $0.003 call into a network-probe oracle for any host a caller
names.
A critical is recorded permanently, not just reported to whoever happened to
call first. Comparing against the previous observation alone would mean an
attacker's challenge becomes the baseline after one call, and every caller
afterwards sees an empty drift beside a growing times_seen — a record that
reads as stability because the change was absorbed, not because nothing
happened. prior_criticals and last_critical do not expire when a later look
is clean, and the advice says so first.
The word "safe" never appears in a response, deliberately. This reports what an endpoint declares about itself; it cannot certify an operator.
Vault
Storage is free; retrieval is paid. The server only ever sees ciphertext — encrypt client-side before calling.
Namespaces are caller-chosen strings, so they are claimed on first write. That
first store returns a namespace_token once; every later operation on the
namespace must present it.
Writes are last-write-wins unless you say otherwise, so two agents rotating
the same secret would clobber each other silently. Pass if_match with the
item's current updated_at for a compare-and-swap, or if_absent to create
only; either answers status: "precondition_failed" instead of overwriting.
POST /vault/list ($0.001) returns the keys and their versions but never any
ciphertext — that is what the $0.02 retrieve is for.
Rotate a token you think has leaked, with POST /vault/rotate-token. It
is free: putting a price on the correct response to a suspected leak is how
you get callers who never rotate. It requires the current token, and there
is no recovery if that is lost — any path that could restore access without
it would be a second way in, and would serve an attacker just as readily as
the owner. Lose it and the namespace is gone by design; there is no account
to reset it against.
Limits
Paid requests are throttled far more loosely than anonymous ones, because a caller who is paying per call already has a spend ceiling. They are not unlimited.
Concurrent paid calls
Paid calls issued concurrently from the same wallet are refused a
noticeable fraction of the time — measured at 2 in 10 up to 8 in 15 on Base
Sepolia, independent of our rate limits, and reproducible with as few as 5 in
flight. The refusal is an ordinary 402, and it originates at the facilitator,
which will not verify overlapping authorizations from one payer.
Nothing is charged for a refused call. Measured directly: 10 concurrent calls at $0.005, 8 settled, 2 refused, and the payer's balance moved by exactly $0.040. Any status at or above 400 cancels x402 settlement, and that holds here.
So a 402 on a paid request means the payment did not happen and it is safe to
retry with a fresh signature. If you need throughput, issue paid calls
sequentially, or retry on 402 with a short backoff. Do not treat a 402 as a
charge you need to reconcile.
Since 0.4.0 the SDK does this for you: post() replays a 402 twice by
default, with jittered backoff, and maxPaymentRetries tunes it. Jitter is not
decoration — the colliding requests belong to a single payer, so a fixed delay
would realign them on the next attempt. Retries only happen when you supplied
an x402-aware fetch; the SDK never signs payments itself, so without one a
402 is terminal and is surfaced immediately rather than stalling.
Security Notes
- URL-taking endpoints are SSRF-guarded (
src/lib/url-guard.ts): scheme allowlist, private/reserved IPv4 and IPv6 ranges blocked, hostnames resolved over DNS-over-HTTPS and private answers rejected, every redirect hop re-validated, and response bodies bounded. It fails closed. It does not defeat DNS rebinding, and does not claim to: the DoH probe and the fetch are two independent resolutions, so a hostile low-TTL nameserver can answer them differently. Pinning the fetch to the vetted address is not expressible on Workers —cf.resolveOverrideonly accepts hostnames inside your own zone, and an IP literal breaks TLS SNI. What bounds the risk is the egress path: Workers reach the internet through Cloudflare's network, which has no route to RFC1918 or loopback and exposes no metadata endpoint. Do not place anything sensitive where this Worker's egress can reach it on the assumption that this guard stops it. - Vault and OnceKey namespaces are ownership-gated. The first request to a
namespace is issued a one-time
namespace_token; tokens are stored only as SHA-256 hashes and compared in constant time. - New namespaces must be unguessable (16+ characters, mixed character
classes). Ownership is first-writer-wins over a global, account-less string
and there is deliberately no recovery path, so a short name like
invoicesorbillingcould be claimed by anyone for $0.001 and would lock out the rightful owner permanently. Making real namespaces unguessable means there is nothing worth squatting. Usemyapp-<uuid>. Names claimed before this rule keep working. - The free lifecycle endpoints do not reveal whether a namespace exists.
/once-key/completeand/once-key/releasereturn an identical 404 whether the namespace was never claimed or your token is wrong, because a free existence oracle is the reconnaissance step before squatting. The paid/once-keyand/vault/*routes answer200withstatus: "forbidden"instead of403, so that each probe actually settles a payment — a 4xx would cancel settlement and leave the payment header replayable, making the oracle free after all. Branch onstatus, not on the HTTP code. namespace_tokenis a bearer credential with no recovery path. Anyone holding it is the owner. Worse than a normal leak:/vault/rotate-tokenis free and needs only the current token, so whoever steals it can rotate first and lock you out irreversibly. OnceKey has no rotation at all, so a leaked OnceKey token is permanent. There are no accounts, no email, and no support channel that can restore access — treat these tokens like a private key, and store them before you make the call that returns one.- The vault cannot read your values, but it does see their names. No key
held here can decrypt anything, and plaintext is never received. But the
item key, the namespace, the
alglabel and the size are all stored in the clear, so the service can tell which named secrets you hold and how large they are.algis an advisory label: nothing here can verify that what you sent was in fact encrypted. Use high-entropy namespace names — ownership is first-writer-wins, so a guessable namespace can be squatted (now enforced; see above). - Paid routes answer completed work with 200 and a
statusfield, never a 4xx. The x402 middleware cancels settlement above 399, so a 4xx returned after the work is done gives the answer away free and leaves the payment header replayable. - Receipts are HMAC-signed with
RECEIPT_SECRET. Note that only/once-keyand the vault endpoints return areceipt— the stateless utilities (/pdf-parse,/scrape,/compress) do not. - The operator can suspend or delete any vault, meeting or OnceKey
namespace through
POST /admin/takedown, to act on abuse reports (see Acting on an abuse report). It cannot read vault values, which are encrypted before they arrive, but it can make them unavailable. The route is disabled unlessADMIN_TOKENis set, and answers404to anyone without it. - Every 402 challenge links
/terms, because paying is what accepts them. - The wallet is the trust anchor. Nothing in this codebase protects the seed
phrase behind
X402_PAY_TO. If it leaks, the money is gone.
Acting on an abuse report
The acceptable use policy commits to acknowledging a report within 2 business days and removing unlawful stored content. Namespace tokens belong to customers, so the operator acts through an admin route instead:
service:vault,meetingsoronce-key.suspendblocks every request to the namespace with410and keeps the data. Do this first. For suspected child sexual abuse material, Canadian law requires reporting to Cybertip.ca and can require the data to be preserved, so do not purge until any duty to preserve has passed.purgedeletes everything in the namespace. It stays refused, so the same person cannot claim it again.liftundoes a suspension made in error. A purge cannot be lifted.
Each action writes a TAKEDOWN line to the Worker logs, but those expire.
Keep your own record of each report and what you did about it.
Money Flow
Canadian-friendly off-ramps: Kraken, Newton, Shakepay, Coinbase. US-only services such as Mercury and Sphere Pay are not an option.
Known Gaps
- No payment has settled on mainnet. Revenue is $0.00. Settlement itself is no longer unproven: on 2026-09-04 the full pipeline ran on Base Sepolia and 0.001 USDC moved on chain, confirmed by reading the transfer log rather than trusting the facilitator. What is untested on mainnet is only that the same code paths work against a chain where the money is real.
- Not in the PayAI Bazaar on mainnet, though the mechanism is now proven
rather than assumed. Listing needs a settled payment per route — reaching
/verifydoes nothing, which is why the catalogue held 0 of 28,095 of our routes. On testnet all 9 appeared within seconds. Announcing the mainnet catalogue costs $0.068, not the ~$1 assumed for months. /x402/verifyhas no observation history yet. Every endpoint it is pointed at will come back"first_observation": trueuntil someone checks the same URL twice, and drift detection is worth nothing until then. The comparison logic is covered by tests, and the parser has been run against this service's own live challenges — which is how the CAIP-2 mismatch was caught: x402 v2 declareseip155:8453where v1 saidbase, and comparing those literally would have fired a critical "the settlement chain changed" alarm at any endpoint that merely upgraded protocol version. Network identifiers are now normalised before comparison. What remains untested is the handler against a third-party endpoint, since every x402 service reachable for free is one of ours./meetings/summarizehas never run behind a real payment. The parts have been verified separately rather than end to end: the model, the grounding prompt and its negative controls were exercised against Workers AI directly (it declines when the transcript does not answer, cites both sides when two meetings disagree, and will not conclude from a truncated transcript), andenv.AI.runwas proven to work from inside a deployed Durable Object using a throwaway Worker running the same model and message shape. Retrieval, bounds and every no-answer path are covered by tests. What has not been observed is one paid call traversing the whole chain, because that needs USDC. Note the vitest pool cannot reach Workers AI at all — inference there fails with an upstream internal error regardless ofremote = true, so a summarisation failure under test is the harness, not the service.- No evidence of demand.
/statsrecords the funnel precisely so that "nobody has found us" and "agents arrive and refuse to pay" stop looking identical. So far the answer is the first one. - The A2A card targets v0.3, not v1.0. v1.0 is a breaking release
(PascalCase methods,
kinddiscriminators dropped,supportedInterfaces[]), and deployed clients still speak v0.3, so that is what is served. The earlier objection to publishing a card at all — that v1.0 makes a declared interface owe all 11 operations — is handled by declaring only what is implemented:tasks/getreturns-32001and streaming-32004rather than pretending. A v1.0 card will be a second document, not an edit to this one. - No A2A skill has been invoked by a stranger. The transport is verified end to end against production, including a paid skill run on trial credit, but every caller so far has been us.
/scrape,/pdf-parseand/compresscompete with free libraries. The defensible endpoints are/once-keyand/vault: coordination primitives a single agent cannot self-host, because they answer questions about what other agents have done.- OnceKey namespace tokens cannot be rotated (vault's now can).
- The
extractivecompression strategy is heuristic and unvalidated against real agent workloads.
License
MIT — see LICENSE.
Source: README.md at commit 18bcef9
Tools
0Version history
1- v1.0.0LatestSep 16, 2026
