TrustAgent
Is this x402 endpoint safe to pay? Reads the endpoint's own payment challenge under BOTH protocol versions — v1 body and v2 PAYMENT-REQUIRED header, so a live v2-only service is not reported as dead — extracts the payout wallet it advertises, and screens that wallet: OFAC sanctions, sybil-filtered ERC-8004 reputation, on-chain behaviour. Flags an endpoint that names different recipients under the two versions. Scores the wallet, not the service behind it, and says so.
The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.
Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.
Live 402 challenge
Captured by the enrichment pass, not read just now. Prices can change — always read the 402 the endpoint answers with.
{
"error": "X-PAYMENT header is required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x6121654D3Fd4C8B42a90d30472E4D40927C3e6BB",
"trial": {
"note": "3 free calls of THIS endpoint per wallet per 24h — not a lesser one. Sign `message` below with any wallet, substituting your own address on the wallet line (either casing), and send the two headers in `send`. No funds, no signup, no settlement — a signature proves the wallet is yours and costs nothing. Contract wallets are verified via ERC-1271. Prefer one signature total: POST the same wallet and signature to /v1/trial/claim and send the returned token as `X-Trial-Token` instead.",
"send": {
"X-Trial-Wallet": "the wallet that signed, 0x-prefixed",
"X-Trial-Signature": "the 0x-prefixed signature over `message`"
},
"claim": {
"use": "X-Trial-Token: the token it returns",
"body": {
"wallet": "the wallet that signed, 0x-prefixed",
"signature": "the 0x-prefixed signature over `message`"
},
"endpoint": "POST /v1/trial/claim"
},
"howTo": "https://trust-agent.io/v1/trial",
"price": "$0.00",
"message": "TrustAgent Free Trial v1\nwallet: 0xYourWalletAddress\ngrant: free-tier access to paid TrustAgent endpoints",
"signWith": "personal_sign (EIP-191)",
"windowHours": 24,
"callsPerWallet": 3
},
"scheme": "exact",
"network": "base",
"mimeType": "application/json",
"resource": "https://trust-agent.io/v1/endpoint/screen",
"description": "Is this x402 endpoint safe to pay? Reads the endpoint's own payment challenge under BOTH protocol versions — v1 body and v2 PAYMENT-REQUIRED header, so a live v2-only service is not reported as dead — extracts the payout wallet it advertises, and screens that wallet: OFAC sanctions, sybil-filtered ERC-8004 reputation, on-chain behaviour. Flags an endpoint that names different recipients under the two versions. Scores the wallet, not the service behind it, and says so.",
"inputSchema": {
"type": "http",
"method": "GET",
"queryParams": {
"url": "REQUIRED. The x402 endpoint to screen, e.g. https://example.com/v1/thing.",
"chain": "OPTIONAL. Only \"base\" is served; any other value is refused rather than answered from the wrong chain."
}
},
"discoverable": true,
"outputSchema": {
"flags": "array of {code, severity, title, detail}",
"offers": "every advertised offer: payTo, network, asset, amount, version",
"paywalled": "whether the endpoint answered 402 with a parseable payment offer",
"components": "per-rule scoring breakdown",
"trustScore": "0-100 for the payout wallet; null when no rule could be evaluated",
"payoutWallet": "the address scored",
"x402Versions": "which protocol generations answered — [1], [2] or [1,2]",
"recommendation": "proceed | proceed_with_caution | hold | block | insufficient_data",
"additionalPayoutWallets": "present only when the offers disagree about the recipient"
},
"freeAlternative": {
"url": "https://trust-agent.io/v1/endpoint?url=https://...",
"note": "No payment required. Resolves the endpoint to the wallet it actually pays and screens that wallet — enough on its own to refuse a sanctioned recipient. This paid route adds the numeric score, the itemised flags and the reasoning behind them.",
"price": "$0.00",
"returns": "the advertised payout wallet, OFAC verdict, risk band and flag counts",
"endpoint": "GET /v1/endpoint"
},
"maxAmountRequired": "5000",
"maxTimeoutSeconds": 60
}
],
"x402Version": 1
}Accepts
The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.
Pay 0.005 USDC on Base to 0x6121…3e6BB. The signed payment is good for 1 minute.
- Paid to
- 0x6121…3e6BB
- USD Coin contract
- 0x8335…02913
- Payment window
- 1 minute
- As published
- 5000 smallest units
The catalog’s raw entry
[
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x6121654D3Fd4C8B42a90d30472E4D40927C3e6BB",
"amount": "5000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 60
}
]Extensions
{
"bazaar": {
"info": {
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"url": "https://trust-agent.io/v1/verify/quick",
"chain": "base"
}
},
"output": {
"type": "json",
"example": {
"flags": "array of {code, severity, title, detail}",
"offers": "every advertised offer: payTo, network, asset, amount, version",
"paywalled": "whether the endpoint answered 402 with a parseable payment offer",
"components": "per-rule scoring breakdown",
"trustScore": "0-100 for the payout wallet; null when no rule could be evaluated",
"payoutWallet": "the address scored",
"x402Versions": "which protocol generations answered — [1], [2] or [1,2]",
"recommendation": "proceed | proceed_with_caution | hold | block | insufficient_data",
"additionalPayoutWallets": "present only when the offers disagree about the recipient"
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method"
],
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"type": "object",
"required": [
"url"
],
"properties": {
"url": {
"type": "string",
"description": "REQUIRED. The x402 endpoint to screen, e.g. https://example.com/v1/thing."
},
"chain": {
"type": "string",
"description": "OPTIONAL. Only \"base\" is served; any other value is refused rather than answered from the wrong chain."
}
}
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"flags": {
"description": "array of {code, severity, title, detail}"
},
"offers": {
"description": "every advertised offer: payTo, network, asset, amount, version"
},
"paywalled": {
"description": "whether the endpoint answered 402 with a parseable payment offer"
},
"components": {
"description": "per-rule scoring breakdown"
},
"trustScore": {
"description": "0-100 for the payout wallet; null when no rule could be evaluated"
},
"payoutWallet": {
"description": "the address scored"
},
"x402Versions": {
"description": "which protocol generations answered — [1], [2] or [1,2]"
},
"recommendation": {
"description": "proceed | proceed_with_caution | hold | block | insufficient_data"
},
"additionalPayoutWallets": {
"description": "present only when the offers disagree about the recipient"
}
}
}
}
}
}
}
}
}Provenance
- Seen in the source catalog
- 2026-09-03 21:34Z
- Last indexed by Roundhouse
- 2026-09-24 08:10Z
- Last enriched (probe, favicon, geo)
- 2026-09-12 14:15Z
- x402 version
- 2
- Max timeout
- 60s
- Liveness probe
- HTTP 402
Hand this page to an agent
Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.
GET api.roundhouseai.io/v0/endpoints
This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 20 snapshots so far. Verified volume counts only settlements with an on-chain EIP-3009 marker.
Show the promptHide the prompt
Using Roundhouse, look up the x402 service TrustAgent and tell me whether it is worth paying: what a call costs, whether the endpoint answered when last probed, and what its payment record actually shows. curl -s 'https://api.roundhouseai.io/v0/endpoints?q=TrustAgent' curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>' Then call it: read the price from the live 402 at https://trust-agent.io/v1/endpoint/screen, never from a cached figure, and pay with an x402 client. The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except /v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402, or use an organization key from https://roundhouseai.io/dashboard/team. If you do not have Roundhouse tools or skills installed, read https://roundhouseai.io/skill.md first — it is the whole procedure.